Be the first to know.
Get our Semiconductors weekly email digest.

Post-quantum secure boot reaches low-cost and mid-range FPGAs

Altera has extended quantum-resistant bitstream authentication to its mid-range Agilex 5 FPGAs and the low-cost Agilex 3 family, running in the on-chip block that loads the device. Shipping now.

author avatar

23 Sep, 2026. 3 minutes read

Altera Agilex Chip

Altera Agilex Chip

What is the announcement

Altera announced that post-quantum cryptography support now covers its Agilex 3 and Agilex 5 FPGAs, the company's low-cost and mid-range families. PQC-enabled secure boot runs in the Secure Device Manager, the on-chip block that authenticates the configuration bitstream before the fabric loads, and which also provides bitstream encryption, physical anti-tamper support, key management, physically unclonable function keys and platform attestation. 

Version 26.1.1 of Quartus Prime Pro Edition, Altera's FPGA design software, supplies the supporting flow, and PQC-enabled devices are shipping.[1]

Why does it matter

Where the post-quantum step sits matters a lot. On Agilex it is in the Secure Device Manager, which runs first. The nearest alternatives place it higher up the chain. 

The Microchip PolarFire SoC system controller authenticates its boot image using elliptic curve cryptography.[6] The AMD Zynq UltraScale+ immutable BootROM authenticates the first-stage bootloader with RSA-4096.[7] However, wolfSSL, which supplies such a bootloader, states plainly that post-quantum verification through a bootloader layered above a classical first stage this does not make the BootROM quantum-safe.[7] 

PQC secure boot is not new to the family. Altera introduced it in September 2025 on Agilex 5 D-Series devices, the higher-density tier of that mid-range family.[2] What arrives now is coverage of Agilex 3 and the wider Agilex 5 line, plus a supporting design-software flow. That matters most at the lower-cost end, where security features usually appear last.

Which algorithm it uses decides whether it can satisfy a compliance mandate. CNSA 2.0 requires LMS or XMSS, the stateful hash-based schemes standardised in NIST SP 800-208, for firmware and software signing, and ML-DSA-87 under FIPS 204 for general-purpose signatures.[4][5]  However, the algorithm and parameter set used are not named in the announcement or in the public Agilex configuration and security documentation.[1][3] 

Technical specifications

ItemValueSource
DevicesAgilex 3 and Agilex 5 FPGAs and SoCsAltera[1]
FeaturePQC-enabled secure boot in the Secure Device ManagerAltera[1]
Other SDM security featuresBitstream encryption, physical anti-tamper, key management, PUF keys, embedded cryptographic cores, platform attestationAltera[1]
Tool supportQuartus Prime Pro Edition 26.1.1Altera[1]
AvailabilityShippingAltera[1]
First appearance of PQC secure boot in the familyAgilex 5 D-Series, September 2025, with Quartus Prime 25.3Altera[2]
Classical bitstream authentication schemeFirst-level signature chain (.qky), root key SHA-256 or SHA-384 hash stored in eFusesQuartus Prime Pro Programmer User Guide[3]
PQC algorithm and parameter setNot stated-
Hybrid classical plus PQC, or PQC onlyNot stated-

Source: [1][2][3]

Secure boot authenticates the configuration bitstream. It does not by itself protect data in transit or at rest, which still needs key establishment, and the new capability covers signature verification only. Post-quantum signatures are substantially larger than ECDSA signatures, so configuration time and flash budget are worth measuring on a real bitstream before a board layout is committed. 

Recommended reading: On choosing between CPLDs and FPGAs; where Agilex 3 and Agilex 5 sit in the device landscape.

References

  1. Altera Corporation, "Altera Adds Post-Quantum Security to Agilex 3 and Agilex 5 FPGAs", Business Wire, 8 September 2026. (link)
  2. Altera Corporation, "Altera Expands Agilex FPGA Portfolio and Streamlines Developer Experience", Business Wire, 30 September 2025. (link)
  3. Quartus Prime Pro Edition User Guide: Programmer, "Enabling Bitstream Authentication". (link)
  4. postquantum.com, "NSA Updates CNSA 2.0 After NIST Finalizes PQC Standards", on the CNSA 2.0 FAQ v2.1. (link)
  5. QCecuring, "CNSA 2.0 Compliance Guide", June 2026. (link)
  6. Microchip Technology, "Boot With Trust: How PolarFire SoC FPGAs Provide Secure Startup". (link)
  7. wolfSSL, "wolfBoot for CNSA 2.0 Secure Boot on Zynq UltraScale+ MPSoC", June 2026. (link)
  8. wolfSSL, "Announcing wolfBoot Support for Microchip PolarFire SoC", December 2025. (link)
  9. iWave Global, "Post-Quantum Cryptography on Agilex 5 System on Module", with Xiphera xQlave ML-KEM and ML-DSA cores. (link)

24,000+ Subscribers

Stay Cutting Edge

Join thousands of innovators, engineers, and tech enthusiasts who rely on our newsletter for the latest breakthroughs in the Engineering Community.

By subscribing, you agree to ourPrivacy Policy.You can unsubscribe at any time.