All About Circuits

Lattice Brings Post-Quantum Cryptography to Low-Power FPGAs

The new low-power FPGAs include CNSA-2.0 compliance and hardware root of trust for post-quantum cryptographic security.


News October 21, 2025 by Duane Benson

Lattice Semiconductor recently announced the new MachXO5-NX TDQ low-power, cryptographic-targeted field programmable gate array (FPGA) family. The TDQ variants of the security-focused FPGA group are the first in the industry to be fully compliant with the Commercial National Security Algorithm (CNSA) 2.0 post quantum cryptography (PQC) standard. It includes advanced cryptography capabilities and hardware root of trust (RoT). 

 

MachXO5-NX TDQ

The new MachXO5-NX TDQ is designed to deliver post quantum security now. 
 

The new series is built on the existing MachXO5-NX security-focused FPGA. The platform is a reconfigurable SRAM FPGA fabric with on-chip flash for UFI and multi-boot capability. The TDQ products start with NX family security and operational functionality and adds CNSA 2.0 compliance. Varieties range from 14K to 53K logic cells.

 

Key Security Features of the New FPGAs

The new family includes hardware root-of-trust (RoT) capabilities. RoT turns each chip into a known and trusted starting point for security. Compromise attacks often seek to hijack connected devices by inserting code into the boot chain. RoT prevents these attacks by creating an immutable starting point against which all downstream security can verify.

The TDQ family includes expanded RoT over prior family members, including trusted single-chip boot with integrated flash, unique device secret (UDS) individual device identity, and partitioning and secure locking of non-volatile configuration and user flash memory (UFM). It also includes SPI and JTAG locking control and side-channel attack (SCA) resiliency. The devices are compliant to NIST Cryptographic Algorithm Validation Program (CAVP) algorithms (LMS, XMSS, ML-DSA, ML-KEM, AES256-GCM, SHA2, SHA3, and SHAKE). 

 

Embedded security function block (ESFB) block diagram

Embedded security function block (ESFB) block diagram. 
 

The devices complete CNSA 2.0 compliance and include bitstream authentication and encryption to ML-DSA, LMS, XMSS, and AES256. They offer in-field crypto algorithm update capability with anti-rollback version protection. Secure bitstream management includes key hierarchy and revokable root keys for both classic and PQC keys. 

Bitstream and user data protection cover symmetric and classical asymmetric cryptographic algorithms (AES-CBC/GCM 256 bit, ECDSA-384/521, SHA-384/512, and RSA 3072/4096 bit). The devices also support a device identifier composition engine (DICE), security protocol and data model (SPDM), and proprietary Lattice SupplyGuard capability. 

 

A Safeguard Against "Harvest Now, Decrypt Later"

FPGAs are used in settings that require large amounts of custom logic. By implanting functionality in logic, processes that benefit from parallel operations or require complex logic operations can be sent through programmable logic quickly. The MachXO5-NX TDQ family's broad security features, along with its low-power operation, enable deployment in a wide variety of settings. Lattice claims the MachXO5-NX TDQ devices can support standalone IoT devices, connected commercial and industrial equipment, and data center control hardware.

 

MachXO5-55TDQ evaluation board

The MachXO5-55TDQ evaluation board comes with the FPGA, 2-GB of LPDDR4, and interface hardware. 
 

Data centers and data center-related infrastructure are especially vulnerable to cyber attacks. Servers and data stores need robust security as do power entry, power distribution, cooling, and switching equipment. The new parts combine the flexibility of programmable logic with advanced hard-instance, PQC-level security.

Even without quantum decryption available today, bad actors are seeking to break into data centers, steal non-time-sensitive data now, and hold onto it for quantum cracking later. This “harvest now, decrypt later” (HNDL) risk means that PQC security is needed now.

 

Getting Ahead of Security in the Quantum Age

The rise of quantum computing has stoked fears that even the most secure encryption may become easy to crack. While quantum computer-based decryption is still more theoretical than a genuine threat, once quantum computers are widely available, illicit decryption will be a significant challenge for data security. This is referred to as the post-quantum cryptography (PQC) era. 

Fortunately, those in the cryptography industry are not sitting still. While quantum computers promise to factor prime numbers easily and quickly—a key component of breaking encryption keys—some algorithms don’t lend themselves to quantum computer operation. CNSA covers the integration of these quantum-difficult algorithms into today’s security so that by the time quantum computers are available, the world’s computing infrastructure will remain secure.

 


 

All images used courtesy of Lattice Semiconductor.