< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

NIST Publishes SLH‑DSA Post‑Quantum Signature Standard, Industry Ready

In August 2024, the U.S. National Institute of Standards and Technology (NIST) finalized the Stateless Hash‑Based Digital Signature Algorithm (SLH‑DSA) as FIPS 205. The standard, derived from the SPHINCS+ submission, relies solely on hash‑function security, making it the most conservative of NIST’s post‑quantum signature algorithms. It offers twelve parameter sets across SHA‑2 and SHAKE hash families and three security categories, with trade‑offs of large signatures (e.g., ~7,856 bytes for SLH‑DSA‑128s) and slower signing speed, positioning it as a high‑assurance backup for long‑lived firmware and root‑of‑trust use cases.

Industry participants are already planning deployment. Akamai, for example, aims to provide post‑quantum TLS certificates by 2029 and highlights ongoing work on alternative algorithms such as FN‑DSA (Falcon) and composite signatures that combine traditional and quantum‑resistant schemes. The IETF’s new PLANTS working group is developing Merkle Tree Certificates to mitigate the packet‑size overhead of large PQC signatures in TLS handshakes. These efforts reflect broader concerns about a potentially sooner‑than‑expected quantum computing timeline and the need for scalable, interoperable quantum‑resistant authentication.

Together, the standardization of SLH‑DSA and the industry’s preparatory measures mark a coordinated move toward securing digital communications against future quantum threats.

Sources

What Is FN-DSA (FALCON, FIPS 206)? [www.encryptionconsulting.com]
about 2 months ago