Mpg.De GlobalPlatform Launches Pavona for Post-Quantum Security in Silicon
Article Content
- •Pavona is the first open-source silicon platform integrating post-quantum cryptography.
- •The initiative aims to enhance hardware security against quantum computing threats.
- •Performance gains for PQC algorithms on embedded silicon were reported, achieving significant improvements.
GlobalPlatform has launched Pavona, an open-source silicon distribution aimed at enhancing hardware security with integrated post-quantum cryptography (PQC) capabilities. The initiative addresses vulnerabilities in specialized hardware against quantum computing threats. Pavona includes production-grade IP components and reference designs for secure semiconductor systems, featuring a modular framework for customized silicon subsystems. The platform's initial release includes two reference designs: a standalone chip root of trust and an integrated version for chiplet architectures, both successfully developed using TSMC’s 3nm process. The project is supported by twelve founding members, including semiconductor firms and research institutions. Performance improvements for PQC algorithms ML-KEM and ML-DSA were demonstrated, achieving gains of six to nine times on embedded hardware. Pavona aligns with certification standards like FIPS 140-3, emphasizing the importance of secure silicon as critical infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…