1
Introduction
With the surge in data breaches and the increasing sophistication of attackers, the rise of quantum computing has brought new urgency—it enables attackers to exploit stolen encrypted data and decrypt it in the future, threatening the long-term trustworthiness of all digital systems. In response, governments and industries are accelerating the formulation of regulations and adopting post-quantum cryptography (PQC) standards such as the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) and the NIST’s FIPS 203/204 to protect critical infrastructure and ensure compliance. Today, digital systems rely on cryptographic agility and hardware-based trusted roots to counter evolving threats, and their trustworthiness depends on this.
This white paper will discuss why adopting PQC is urgent, how countries and industries are responding, and how Lattice Semiconductor‘s RoT (Root of Trust) FPGA supporting PQC can help organizations secure their future in the era of quantum computing.
2
The Urgency of Adopting Post-Quantum Cryptography (PQC)
The foundation of post-quantum security must be built on trusted hardware, and Lattice’s RoT FPGA provides such a secure foundation. With its unique design, Lattice’s RoT FPGA can execute post-quantum algorithms and has the industry’s most comprehensive CNSA 2.0 algorithm coverage, supporting all mandatory standards including ML-KEM, ML-DSA, LMS, and XMSS. This not only equips customers with the capability to ensure future security but also allows them to meet compliance deadlines set by agencies such as the NSA.
Unlike traditional microcontrollers or general-purpose hardware security modules, Lattice’s RoT FPGA combines the following features:
Comprehensive compliance with CNSA 2.0: Supports all approved post-quantum cryptography (PQC) algorithms
Hardware-enforced RoT mechanisms: Ensures secure boot chain, protects firmware, and eliminates denial-of-service risks
Cryptographic agility: Supports seamless migration between classical, hybrid, and PQC algorithms
Efficient performance: Secure boot speeds improved by up to 10 times, with power consumption reduced by 50%-75% compared to competitors
This makes Lattice’s RoT FPGA a practical foundational platform for deploying PQC technology today.
3
The Real Reasons for Urgency
The debate over when large-scale quantum computers will arrive continues, but there is no dispute about the imminent risk of “harvest now, decrypt later” (HNDL) attacks. Attackers are continuously collecting encrypted communications, financial records, medical data, and confidential information, planning to decrypt them once quantum technology matures.
This is the real reason why governments are accelerating action. The NSA’s CNSA 2.0 mandates the adoption of PQC technology in software and firmware signatures by 2025, with full deployment by 2027. The EU and other regions have set similarly urgent timelines. The window for transformation is closing, and companies that delay will face the risk of sensitive data being compromised in the future.
Clearly, PQC is no longer a future issue but a current priority. By building a secure foundation with Lattice’s RoT FPGA, companies can deploy CNSA 2.0-compliant solutions to create a protective wall against tomorrow’s quantum threats for the data generated today.
4
Understanding “Harvest Now, Decrypt Later” Attacks
While symmetric encryption schemes are generally considered resistant to quantum attacks, protocols used for exchanging or establishing shared keys often rely on asymmetric encryption techniques that are vulnerable to quantum threats. The “harvest now, decrypt later” (HNDL) attack refers to attackers (often state actors or advanced cybercriminals) intercepting and storing current encrypted data, waiting until quantum computing capabilities mature to decrypt it.
The danger of this attack method lies in its targeting of sensitive data with long-term strategic or personal value, such as medical records, financial agreements, intellectual property, and confidential communications, which often have decades of retention value. Unlike traditional attacks that pose immediate threats, HNDL creates long-term threats. The stolen data remains encrypted, appearing secure on the surface, giving companies a false sense of security.
To mitigate this risk, organizations must begin planning the transition to quantum-resistant key exchange mechanisms (such as ML-KEM (FIPS 203)), especially for the most sensitive communications. Early adoption of PQC standards is crucial for ensuring the future security of currently encrypted data.
5
Advancements in Quantum Computing
By 2025, significant breakthroughs in quantum computing are expected in both hardware and software. Google’s 105-qubit Willow chip has reduced error rates by several orders of magnitude, completing benchmark tasks that would take classical supercomputers trillions of years in just minutes; Microsoft has launched the first topological qubit-based quantum processor, Majorana 1, paving the way for building fault-tolerant quantum systems; NVIDIA and Quantum Circuits are advancing hybrid quantum-classical computing technology by integrating CUDA-Q into Aqumen; and Amazon and NVIDIA have jointly launched DGX Quantum, a platform that combines AI superchips with quantum control systems, supporting real-time error correction and scalable quantum workloads.
Based on current progress, the first practical post-quantum computer (capable of breaking mainstream encryption systems like RSA-2048) is expected to emerge between 2030 and 2035, depending on technological advancements and implementation conditions. By then, any length of classical public key encryption will be at risk.
6
Industry and Regulatory Responses
The global cybersecurity industry is actively responding to the imminent threats posed by quantum computing. Governments and enterprises are accelerating the adoption of PQC to safeguard sensitive data against future quantum attacks. For example, NIST has released NIST SP 800-208, recommending two hash-based signature schemes: Xtended Merkle Signature Scheme (XMSS) and Leighton-Micali Signature (LMS). The agency has also formally established the first set of PQC standards, including FIPS 203 based on module-lattice key encapsulation mechanism (ML-KEM) and FIPS 204 based on module-lattice digital signature (ML-DSA) algorithm standards.
The European Union has initiated a coordinated roadmap to secure critical infrastructure with quantum-resistant encryption by 2030.
The NSA’s CNSA 2.0 is a comprehensive update to the National Security System (NSS) encryption standards. This standard mandates the transition to quantum-resistant algorithms, replacing vulnerable schemes like RSA and ECC with lattice and hash-based alternatives.
The document outlines a transformation timeline: by 2025, software and firmware signatures must begin adopting CNSA 2.0 algorithms, with full promotion in NSS systems by 2027. It is expected that by 2035, all NSS technologies will achieve full compliance, making early planning and implementation crucial for organizations handling sensitive or confidential data.
7
What Solutions Does Lattice Provide?
Lattice’s RoT FPGA offers features including secure boot, low-power operation, tamper protection, bitstream and data security, real-time firmware protection, and end-to-end IP protection—all based on immutable hardware security features. These foundational capabilities are already available, and PQC is built on this solid foundation to better withstand emerging threats.
Lattice’s PQC FPGA devices meet the evolving needs of PQC technology development by providing a wide range of supported algorithm suites, covering lattice-based encryption (ML-DSA and ML-KEM) and hash-based signatures (LMS/XMSS), adaptable to diverse market demands and application scenarios.
Given the dynamic nature of cryptographic technology development, these devices are designed with cryptographic agility as a core goal, allowing for rapid adaptation to emerging protocols and technological improvements.
To simplify the transition to post-quantum standards, Lattice devices support hybrid encryption models, enhancing security by enabling the coexistence of classical algorithms and quantum-resistant algorithms.
Additionally, these devices are carefully designed to integrate with emerging quantum technologies such as quantum random number generators (QRNG) to create more robust and up-to-date security solutions.
8
Classical + PQC Key Hierarchy
In public key signature schemes, the confidentiality of private keys is the foundation of security. However, repeated incidents of key leakage over the years indicate that key exposure is a real and persistent threat, necessitating the establishment of backup mechanisms.
To this end, devices must support multiple valid public keys to enable secure key rotation and rapid revocation of compromised credentials.
Lattice’s PQC devices achieve this functionality through a robust key hierarchy architecture that supports the coexistence of multiple valid public keys.
The configured keys can mix post-quantum schemes such as ML-DSA, XMSS, or LMS with classical algorithms, providing system designers with high flexibility.
Once configured, keys can be enabled, extended, or revoked upon request, supporting healthy key rotation and robust lifecycle management.
This architecture ensures scalable, secure, and adaptable cryptographic operations in environments where resilience and agility are prioritized.
9
Bitstream Authentication and User Data Signing with PQC Solutions
LMS and XMSS are hash-based digital signature algorithms proposed by the IETF, while the ML-DSA (FIPS 204) standardized by NIST is recognized as a valid PQC option by CNSA 2.0.
In Lattice’s PQC device series, CNSA 2.0 algorithms are already supported for bitstream authentication. This authentication feature is a core security characteristic of such devices.
Customers can use their LMS, XMSS, or ML-DSA private keys to sign bitstream images within the hardware security module (HSM) ecosystem. The image will be verified when programmed into the device using the pre-configured corresponding public key.
Customers can also use ML-DSA to sign user data on Lattice FPGA devices, ensuring that sensitive information receives post-quantum digital signature protection in addition to bitstream authentication.
10
Secure Channels Using ML-KEM: Preventing “Harvest Now, Decrypt Later” Attacks
As mentioned earlier, one of the greatest threats posed by quantum computing is the “harvest now, decrypt later” (HNDL) attack, which involves stealing and storing encrypted data for a long time, waiting until quantum computers can break classical encryption schemes.
Traditional Nexus devices support creating secure channels using RSA or ECDH, but these methods are vulnerable to HNDL attacks.
To address this, Lattice’s PQC devices implement quantum-resistant key encapsulation based on hardware ML-KEM.
These devices support the entire ML-KEM suite, enabling secure communication in two ways: by using third-party public key encapsulation to share keys or initiating key exchanges and unsealing keys generated by other trusted agents.
Once a shared key is established, a secure channel resistant to future quantum attacks can be created immediately using the onboard AES engine.
Furthermore, Lattice’s PQC devices support all ML-KEM security levels compliant with CNSA 2.0, including ML-KEM-512, ML-KEM-768, and ML-KEM-1024, allowing users to customize security levels and performance based on specific application needs.
11
SPDM Supporting ML-DSA/ML-KEM
The Security Protocol and Data Model (SPDM) specification, developed by the Distributed Management Task Force (DMTF), is a standardized protocol designed to achieve secure communication, device authentication, and authorization across platforms and transport layers, thereby establishing a zero-trust security environment.
SPDM facilitates encrypted and verified communication between components, functioning similarly to TLS 1.3 but optimized for embedded and firmware-level environments.
This model supports mutual authentication, key exchange, and session confidentiality, making it ideal for chip-to-chip and device-to-host interactions.
The core functionality of SPDM is to verify the identity and integrity of hardware components through mechanisms such as firmware authentication, allowing devices to provide encrypted proof of their firmware status to verifiers.
With the release of SPDM 1.4, the protocol now supports PQC algorithms such as ML-KEM and ML-DSA, providing assurance against future quantum threats.
Lattice’s PQC devices fully support SPDM-compatible systems, providing the necessary cryptographic primitives (including ML-KEM, ML-DSA, AES-GCM) and MCTP transport support for secure integration of all platform components.
12
DICE in Lattice Devices
The Device Identifier Composition Engine (DICE) is a security specification developed by the Trusted Computing Group (TCG) to establish a strong cryptographic and tamper-proof identity for resource-constrained devices.
In Lattice devices, a unique identifier called the Composite Device Identifier (CDI) is generated by cryptographically combining the loaded bitstream, its configuration information, and inherent hardware keys. This CDI reflects the current state of the device and serves as the basis for generating a unique asymmetric key pair.
When this key pair is certified by Lattice’s certificate authority during manufacturing, a device-specific certificate can be generated. These DICE certificates can be used in conjunction with SPDM to establish secure communication between devices in a zero-trust environment. Devices can share configuration data through Lattice’s genuine traceability signature credentials.
Moreover, system designers can leverage the capabilities of Lattice’s PQC devices to elevate the security of the authentication infrastructure to new heights capable of resisting quantum attacks.
13
Lattice’s PQC Device Platform Firmware Resilience (PFR)
Platform Firmware Resilience (PFR) is a security framework designed to protect critical platform firmware (such as BIOS, bootloaders, and other low-level system components) against network threats, unauthorized modifications, and operational failures.
Lattice’s PQC devices are the first to implement a PFR solution based on NIST Special Publication 800-193 guidelines, incorporating advanced cryptographic techniques defined by CNSA 2.0.
As PQC algorithms continue to develop, hybrid solutions that integrate classical and quantum-resistant methods provide a practical security path for future development. This model enhances credibility and promotes the adoption of the technology by maintaining the reliability of mature algorithms while enabling practical application testing of PQC.
Lattice’s PQC devices are well-suited to support this hybrid PFR model. These devices can combine classical algorithms such as ECDSA with quantum-resistant algorithms like ML-DSA, LMS, and XMSS for firmware authentication, and integrate ML-DSA/ML-KEM with ECDSA and AES-GCM for authentication and secure channel services.
This layered encryption strategy ensures that when one algorithm fails due to quantum breakthroughs or unknown vulnerabilities, the remaining algorithms can continue to provide protection. This redundancy significantly enhances the overall system resilience.
14
Ensuring Manufacturing Security with PQC Technology
Most of the security features discussed in this document rely on sensitive data provisioned during the device manufacturing phase. This data may include cryptographic keys for authenticating runtime keys, configuration files, policy settings, or X.509 certificates.
However, the manufacturing process is often overlooked in security assessments, leaving this critical phase vulnerable to potential threats.
Lattice’s PQC devices initiate their lifecycle through a “last inch security” provisioning protocol in a protected testing facility. The hardware security modules (HSMs) used in their manufacturing process are fortified with post-quantum cryptographic technologies (such as the combination of ML-DSA and ML-KEM), creating a robust defense against quantum-level attacks for sensitive configuration data.
15
Conclusion
The threats posed by quantum computing are no longer theoretical projections but real and imminent challenges, particularly the “harvest now, decrypt later” attacks that exploit vulnerabilities in current encryption technologies.
In response to this threat, governments and organizations worldwide are actively promoting the transition from classical public key cryptography to post-quantum public key cryptography to secure digital infrastructure.
Lattice’s PQC devices provide timely and effective solutions that meet the evolving security demands. With support for a wide range of cryptographic algorithms and built-in cryptographic agility, these devices are well-positioned to adapt to the future development of PQC.
Furthermore, the inherent flexibility of FPGAs allows for the integration of advanced security services such as PFR and SPDM, thereby constructing resilient architectures capable of withstanding the threats of the quantum era using existing cryptographic primitives.
For More Information
-
To learn more about how Lattice’s low-power FPGA solutions are applied in industrial, automotive, communications, computing, and consumer markets, please visit www.latticesemi.com or contact us at www.latticesemi.com/contact or www.latticesemi.com/buy.
Technical Support
-
Submit technical support cases at www.latticesemi.com/techsupport.
-
For FAQs, please click “Read More” to visit the Lattice Answers database.