TCitH signatures enable faster smaller secure chips than SLH DSA

Efficient TCitH-Based Alternatives to SLH-DSA: Cross-Layer ASIC Design of Mirath

Cryptography and SecurityHardware Architecture

Summary

Quantum computers threaten current digital signatures, so new kinds of signatures are needed. The authors focus on TCitH-based signatures, which have small keys but are usually slow and large. They designed and built the first ASIC chip implementation of Mirath, a TCitH signature scheme, on a RISC-V platform. Their chip signs data much faster and uses less silicon area than a comparable SLH-DSA chip, showing these signatures could be a good alternative for secure computing.

What this means in practice

  • For embedded system designers: Build secure embedded devices with faster and smaller TCitH-based signature hardware to protect against quantum attacks.
  • For smart card manufacturers: Integrate the proposed Mirath ASIC design to offer compact, energy-efficient quantum-resistant signature capabilities in payment or ID cards.$Commercial implications: This ASIC design makes it possible to produce smaller, faster secure smart cards resistant to quantum attacks, creating marketable hardware products.

Authors

Hiandra Tomasi, Maximilian Schöffel, Johannes Feldmann, Norbert Wehn

Abstract

To address the security risks posed by quantum computers, the U.S. National Institute of Standards and Technology (NIST) has standardized the post-quantum signature schemes ML-DSA, FN-DSA, and SLH-DSA. While ML-DSA and FN-DSA are lattice-based, SLH-DSA relies on hash-based assumptions. To support cryptographic agility against future vulnerabilities, NIST is evaluating non-lattice candidates as alternatives to SLH-DSA. Among these, TCitH-based schemes are particularly promising due to their compact keys and small signatures. However, their high computational complexity and memory footprint pose significant challenges for efficient implementations on resource-constrained embedded platforms. They remain largely unexplored in this context, particularly in ASIC implementations. To address this gap, we use a cross-layer methodology combining algorithmic and hardware layers to present, to the best of our knowledge, the first ASIC implementation of Mirath, a TCitH-based signature scheme, in a RISC-V-based system. The design is implemented in a 22nm FD-SOI technology node. Compared with an SLH-DSA ASIC implemented in the same technology node, the proposed architecture achieves 17.8x lower signing latency while requiring 58% less total cell area, showing the potential of TCitH-based signatures as efficient non-lattice alternatives from an implementation perspective.