CoreBridge-PQC – Research on Modular Post-Quantum IP Cores for Secure Communication through On-Demand Cryptographic Tunnels

Project description:

CoreBridge-PQC investigates the development of a family of modular post-quantum IP Cores designed to enable secure communications through on-demand cryptographic tunnels.

The project focuses on developing a set of IP cores that will act as a network infrastructure component. Their function will be to enable the establishment of a secure tunnel based on Post-Quantum Cryptography (PQC) between computers or other devices connected to the internet, without requiring specific configurations or modifications to the existing IT infrastructure.

The IP Cores will be developed for implementation on FPGAs, with the possibility of future adaptation to ASICs. They may also be used independently to complement cryptographic or networking functions in third-party projects.

The project includes two main families of cores: cryptographic cores, responsible for post-quantum and symmetric-key cryptographic operations, and TCP/IP stack cores, designed to operate and modify network protocols. The combination of these elements will enable the establishment of transparent post-quantum cryptographic tunnels, managed by the IP Cores themselves, facilitating secure internet connections between connected systems.

General objective:

The main objective of CoreBridge-PQC is the design and development of a family of post-quantum cryptographic IP Cores (PQC) for implementation on FPGAs and/or as part of the initial design of ASICs.

The development will be carried out using RTL in the VHDL language. The cores will be organised into two main groups: cryptographic Cores, which will perform post-quantum cryptographic operations using ML-KEM and ML-DSA, as well as symmetric-key cryptography using AES; and TCP/IP stack Cores, which will be used to operate and modify network protocols.

The project falls within the field of cybersecurity, with a modular design that will allow these cores to be used either together or independently as complementary components in third-party designs requiring these functionalities.

Specific objectives:

The specific objectives of the project are:

  1. Design post-quantum and classical cryptographic cores, combining PQC for key exchange and authentication with classical cryptography for data transmission. The project includes the use of ML-KEM for key exchange, ML-DSA for digital signatures or authentication, and AES-256 to encrypt and decrypt information sent or received through the tunnel.
  2. Design the TCP/IP stack for network integration, through IP Cores capable of managing the complexity of a network connection. Planned components include a packet demultiplexer, a MAC subsystem and a packet switch.
  3. Investigate the use of Physically Unclonable Functions (PUFs) together with True Random Number Generators (TRNGs) to generate seeds for the cryptographic cores. The aim is to strengthen system security and minimise risks associated with the generation and use of random numbers.
  4. Design and validate the device in a controlled environment, investigating a user-friendly, ergonomic and easy-to-integrate design for IT networks, as well as developing the PCB and enclosure.
  5. Develop a script for device configuration, allowing users to generate certificates from scratch and compile the project from its source code. According to the project documentation, this approach aims to ensure that sensitive data remains on the customer’s computer and that there is no need to trust third parties to maintain the security of the tunnel.

Project duration:

September 2025 – June 2026

Project leader:

Funded by:

The project has been funded through the PERTE CHIP call for proposals of the Ministry of Industry, Trade and Tourism.

CDTI
CDTI
MINCOTUR

Contact

Blanca Moral – blanca.moral@itcl.es