FIPS 203 and FIPS 204 Do Not Specify the Silicon: the 9 September 2026 NTT Patent Screening, and the Two Portfolios NIST's Royalty-Free Licenses Cover

Board-ready intelligence on quantum innovation · Biomedical discovery · Post-quantum transition
Three documents dated 9 September 2026 — a Chinese patent-landscape screening of post-quantum hardware, a US analysis of NIST's CRYSTALS-KYBER licenses, and an OpenSSL pre-release — all describe the layer the standards leave open.

IP & Competition

Three documents dated 9 September 2026 — a Chinese patent-landscape screening of post-quantum hardware, a US analysis of NIST's CRYSTALS-KYBER licenses, and an OpenSSL pre-release — all describe the layer the standards leave open.

Published by Quentir Systems LLC · September 10, 2026 · 8 min read

In April 1965 James Cooley and John Tukey published five pages in Mathematics of Computation setting out how to compute a Fourier transform in n log n operations rather than n squared. The algorithm was never patented, and six decades of signal processing were built on that fact. Its arithmetic cousin, the number-theoretic transform, now sits inside the high-performance implementations that will carry banking, defense and telecommunications traffic through the post-quantum migration. Patent filings have gathered around it, and they are not on the transform. They are on how you build one.

Three documents carry the date 9 September 2026. A patent-landscape screening published by the Suzhou Institute of Information Security Law on the Chinese security-research site Anquan Neican works through the hardware layer of ML-KEM and ML-DSA. An analysis in the National Law Review sets out the limits of the royalty-free patent licenses NIST secured for CRYSTALS-KYBER. And OpenSSL published a pre-release carrying new optimizations for exactly the operations the first document is about. Read together they describe a part of the migration that has an owner problem, and that appears in none of the migration budgets now being written.

Practical takeaway. NIST's royalty-free licenses reach hardware, and they reach two named patent portfolios and one algorithm. Everything outside that — other holders, other patents, and ML-DSA — is ordinary patent risk sitting on the optimizations that make a post-quantum part shippable. That question is cheap to answer while an architecture is still being chosen and expensive once a design is in silicon.

What FIPS 203 and FIPS 204 Specify, and Where the Text Stops

FIPS 203 standardizes ML-KEM and FIPS 204 standardizes ML-DSA. Both rest on multiplication in a polynomial ring, and both specify the transform in mathematical terms: the modulus, the constants, the order the coefficients are read in. Neither describes how a circuit performs the work. The butterfly datapath, the modular reduction technique, the memory banking, the pipeline depth, the masking a certification laboratory will expect to see — the standards are silent on all of it.

Direct polynomial multiplication costs order n squared operations; the transform brings it to order n log n. For any product with a throughput, power or latency budget, the screening treats the transform as the route that has to be taken rather than one option among several. The standards are therefore silent in the place where the engineering is hardest and the commercial value concentrates.

The Five Areas Where the Screening Reports the Filings Clustered

Every claim in this section is the screening's, and its authors state at the foot of the piece that the work is an incomplete preliminary screening based on public information, that it does not constitute an infringement determination or a legal opinion, and that precise analysis requires obtaining each claim set and doing an equivalents analysis. On that basis, the document groups the activity into five areas. Butterfly units and their pipelines, covering Cooley-Tukey and Gentleman-Sande forms and dual-butterfly multi-path delay commutator designs. Modular multipliers, which it calls the fine-grained chokepoint inside the transform. Unified architectures that share one transform unit between ML-KEM and ML-DSA. Side-channel and fault-injection protection — shuffled transforms, masked modular multiplication — which the authors describe as a practical necessity for FIPS 140-3 or Common Criteria evaluation. And instruction-set and coprocessor integration, including RISC-V extensions. The screening dates the filing surge to 2024 and describes 2026 as still dense. On the international side it reads Intel's incomplete-transform approach and LG's incompleteness optimizations as a dual track, calls Samsung, LG and Inha University systematic in Korea, and characterizes Europe through industrial validation at Siemens and homomorphic-encryption work at ZAMA. It publishes no patent numbers in its public text, which is the main thing a reader should hold against it.

What can be checked independently is that these are real and contested engineering categories rather than invented ones. PQShield's paper for the 2024 hardware-security workshop ASHES, High-Performance NTT Hardware Accelerator to Support ML-KEM and ML-DSA, describes precisely that design space: a single butterfly configuration unit serving both the forward and inverse transform to cut resource use and shorten the critical path, with a multi-path delay commutator strategy for fully pipelined parallel processing of multiple coefficients. That corroborates where the engineering competition sits. It does not corroborate where the filings sit, and nobody should read it as doing so.

Why the FRAND Discipline May Not Reach an Implementation Patent

Two things have to line up before a FRAND obligation exists. A patent is essential when compliance with the standard necessarily practices one of its claims, and the FRAND commitment itself comes from an undertaking the holder gives under the intellectual-property policy of the body that publishes the standard. Both are weak here. FIPS 203 and FIPS 204 describe no butterfly datapath and no modular multiplier, so an essentiality claim over one has little in the standard text to attach to. The second limb reaches further than it first appears and still stops short of this layer. NIST's 2016 call for proposals required a signed statement from every patent owner behind a submission, offering a license either without compensation or on reasonable and nondiscriminatory terms. Those assurances attach to patents identified as necessary to implement the submitted scheme. They do not reach unrelated patents, and they do not reach circuit implementation patents filed years afterward by parties who submitted nothing. The screening's conclusion follows from that gap: on its reading, the holder of such a patent sets its own price and chooses whom to license.

The authors add a variable worth keeping in view. If NIST later issues implementation guidance, or an industry de facto standard absorbs one particular design, some of these patents could become essential to a revised standard or essential in practice. In the second case no declaration procedure has been run at all, so on their reading a FRAND obligation does not automatically follow. A patent can become unavoidable without becoming constrained.

The exposure they describe is set out under Chinese patent law, where a method-plus-apparatus claim bundle is asserted against manufacture, offer for sale, sale, import and use; their further position that this reaches upstream into the design stage is the authors' own and is not established by the listed statutory rights alone. Their concern is royalty stacking: chip IP is commonly licensed per unit shipped, and several holders sitting at several chokepoints turn that into what they call a tollbooth, where each one charges separately or declines to let a design through. Whether US and European claim construction reaches as far is a separate question, and the sources reviewed here identify no reported decision on it for a post-quantum accelerator.

What NIST's Two Royalty-Free Licenses Actually Cover

The obvious answer to all of this is that NIST already cleared the ground, and it is worth being exact about how far. NIST entered two patent license agreements to support adoption of CRYSTALS-KYBER, covering a portfolio privately owned by a US entity and a portfolio controlled by French institutions. The licensors agreed on a royalty-free basis to place into abeyance any right of enforcement against any implementer or end user of the algorithm. Hardware is inside that grant. The US agreement defines licensed products as "any apparatus or composition encompassed within the scope of a claim in the LICENSED PATENT and implementing the PQC ALGORITHM", extended to products made by a licensed process. The French agreement uses the same apparatus-or-composition language without the algorithm-implementing qualifier attached to the product itself. Both define an implementer to include one acting for commercial manufacture, distribution or the provision of products and services for a fee.

The limits are the portfolios and the algorithm. Two portfolios are named, the field of use is implementing CRYSTALS-KYBER as published by NIST, and no equivalent agreement exists for ML-DSA. An analysis published in the National Law Review on 9 September 2026 puts the boundary in one sentence: the agreements "neutralize the risks associated with the licensed patent portfolios, but they are not a blanket freedom-to-operate for every ML-KEM product." Other patents may still require consideration, the authors write, "particularly where an implementation departs from the standardized algorithm or incorporates additional proprietary technology."

Set that beside the engineering. An accelerator that earns its place in a product departs from the reference implementation on every axis that matters commercially: the reduction technique, the pipeline organization, the shared datapath, the masking. The licenses neutralize two portfolios across implementations governed by ML-KEM migration profiles. The freedom to operate question lives with every other holder, across the optimizations that many commercial performance budgets require.

OpenSSL Shipped Transform Optimizations Into a Pre-Release on 9 September

On 9 September 2026 the OpenSSL project published 4.1.0-alpha1, labeled a pre-release. Its changelog records "optimized ML-DSA and ML-KEM NTT operations on ppc64le; optimized ML-DSA operations on s390x, and x86_64" together with "AVX-512-optimized SHAKE x4 operations for ML-DSA on x86_64", alongside support for DTLS 1.3. The optimization layer the screening is describing is being written into a widely deployed cryptographic library, in public, while the licensing question sits open.

Software holds the cheaper position here. A library can change a variant in a point release and ship it the same quarter. Hardware cannot. Once an architecture is selected and the IP is frozen, the cost of moving is a redesign, which is why the screening puts design-around at architecture selection and treats anything later as expensive. Quentir has followed that side of the migration as it reached the parts themselves, in the read on SEALSQ's QVault TPM putting ML-DSA and ML-KEM into a certified device. Security parts of that kind stay in service for years, sometimes for the life of the equipment they sit in. The screening also leaves one exit open: routes that avoid the transform altogether exist, their performance cost should be measured rather than assumed, and for a device with a low throughput requirement — its example is slow industrial and consumer connectivity — that route may be clean.

How Quentir Reads It

The migration is being ordered from the supervisory side against fixed dates. FINMA recommends that Swiss institutions have a roadmap by the middle of 2027, and its own survey found 8 percent of the 60 institutions it asked already had one, as this site read in detail on 9 September. US agency migration plans under OMB memorandum M-26-15 are due on 22 October 2026. Those instruments set destinations and dates. None of them says anything about what the implementation layer will cost to license, and the ML-DSA half of the migration has no NIST license behind it at all.

The place this lands first is contractual. Supply agreements for security silicon and firmware allocate third-party IP risk through indemnities and warranties that are point-in-time representations with short claim windows. A royalty demand arriving in 2029 against parts bought in 2026, under a mandate issued by a supervisor in 2027, falls into a gap between three documents none of which anticipated it. Whether the vendor, the buyer or the public body that ordered the migration absorbs it is a drafting question with a cheap answer now.

The defensive position is stronger than the screening's framing suggests. Prior art in this field is deep and public: Cooley and Tukey in 1965, the lattice work of the 1990s, and the pq-crystals reference implementations open since 2016. That is real material for novelty and inventive-step challenges, and it is the reason a freedom-to-operate exercise on this layer is worth running before an architecture is chosen. Quentir's September Signature Brief, October 19 Comes Before 2030, sits next to this question on the calendar side: it carries the six dated events of the post-quantum calendar with the primary source for each and the questions to put before 22 October, in a fixed scope with an internal-use license, which is what a public post on this site does not attempt.

Two dates now run against each other. Agency plans are due on 22 October 2026 and Swiss roadmaps by mid-2027, while the sources reviewed here identify no reported decision anywhere on an implementation patent asserted against a post-quantum accelerator. The buying decisions come first, and the licensing question will arrive at whoever signed for the hardware.

Sources. Suzhou Institute of Information Security Law, “Patent landscape and infringement-risk analysis of NTT polynomial multiplication in quantum-resistant cryptography”, published on Anquan Neican, page date 9 September 2026 — the five technical areas, the 2024 filing surge, the SEP and FRAND analysis, the tollbooth and royalty-stacking argument, the design-around timing and the prior-art list. The article states that it is an incomplete preliminary screening based on public information, that it does not constitute an infringement determination or legal opinion, and that precise analysis requires claim-by-claim review. NIST, summary and excerpts of the two CRYSTALS-KYBER patent license agreements — the US and French portfolios, the abeyance of enforcement, and the quoted definitions of “implementer” and “licensed products”. “Navigating the Legal Safety Net of NIST’s Post-Quantum Cryptography Patent Licenses”, National Law Review, 9 September 2026 — both quoted sentences on portfolio scope and freedom to operate. NIST, FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA), August 2024 — algorithm and parameter specifications. OpenSSL, release 4.1.0-alpha1, 9 September 2026, pre-release — the quoted changelog entries and DTLS 1.3 support. PQShield, “High-Performance NTT Hardware Accelerator to Support ML-KEM and ML-DSA”, ASHES 2024 — single butterfly configuration unit and multi-path delay commutator pipelining. NIST, intellectual-property statements, agreements and disclosures required of post-quantum submitters — the process described in the FRAND section. FINMA, “FINMA guidance on quantum computing”, 9 July 2026 — the mid-2027 roadmap recommendation and the survey of 60 institutions. Office of Management and Budget, memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography — the 22 October 2026 date for agency migration plans. J. W. Cooley and J. W. Tukey, “An Algorithm for the Machine Calculation of Complex Fourier Series”, Mathematics of Computation 19 (1965), 297–301. Sources checked 10 September 2026.

Published intelligence, built to inform your own decisions. Published: September 10, 2026.

© 2026 Quentir Systems LLC
Previous
Previous

ECDSA.Fail Cut Its secp256k1 Point-Addition Benchmark Score 86 Percent on 9 September 2026; a Day Later Scripps Found 32 US States Without a Confirmed Post-Quantum Plan

Next
Next

FINMA Guidance 05/2026 Recommends a Post-Quantum Roadmap by Mid-2027, and Only 8 Percent of the 60 Swiss Institutions It Surveyed Had One