Part 3: NIST PQC standardization

NIST PQC standardization activities

NIST started the standardization activities to specify PQC algorithms in 2016, followed by a series of evaluation rounds. In 2022, after 3 rounds of evaluation, NIST published IR 8413 (2022-07)1, which specified 1 key encapsulation mechanism (KEM) and 3 digital signature algorithms. The former is to confidentially transmit a secret key by encapsulating (encrypting) it, and the latter is the signature algorithms that are expected to replace RSA and the elliptic curve digital signature algorithm (ECDSA).

Selected algorithms (IR 8413)
KEM
Original nameOfficial standard nameAlgorithm type
CRYSTALS-KyberML-KEM2 (FIPS 203)Lattice-based
Table 1: KEM algorithm
Signature algorithms
Original nameOfficial standard nameAlgorithm type
CRYSTALS-DilithiumML-DSA3 (FIPS 204)4Lattice-based
FalconFN-DSA5 (FIPS 206)6Lattice-based
SPHINCS+SLH-DSA7 (FIPS 205)8Hash-based
Table 2: Signature algorithms
Additional signature algorithms

After the publication of IR 8413 (i.e., at the end of the round 3 evaluation), no other signature candidate remained. To expand the signature algorithm portfolio, NIST announced a call for additional signature algorithms.9 A part of the motivation for this call was to diversify the algorithm types beyond lattice-based (except for SPHINCS+ which is hash-based). Furthermore, this call specifically mentioned algorithms that have “short signatures and fast verification.” At the time of writing, IR 8610 (2026-05) 10 announced 9 candidates, advancing to the next round of evaluation.

Algorithm nameAlgorithm type
FAESTMPC-in-the-Head
MQOM11MPC-in-the-Head
SDitH12MPC-in-the-Head
HAWKLattice-based
MAYOMultivariate
UOV13Multivariate-based
QR-UOV14Multivariate
SNOVA15Multivariate
SQIsignIsogeny-based
Table 3: Additional signature algorithms in evaluation
Next step of additional signature algorithms

With the publication of IR 8610, the evaluation process proceeds to the 3rd round. NIST plans to hold a conference in the first half of 2027, when the update status of the above 9 candidate algorithms are discussed toward the conclusion of the 3rd round evaluation. As the standardization selection was announced after the 3rd round in the original cycle (IR 8413), it is possible that the current 3rd round may conclude with an announcement for standardization selection of one or more additional signature algorithm(s).

Quantum-resistant math problems

As mentioned in the preceding tables, several mathematical problems are considered to be quantum computer-resistant. and resulting signature algorithms named after these mathematical problems: (1) lattice-based, (2) code-based, (3) multivariate, (4) hash-based, (5) MPC-in-the-head, and (6) isogeny-based. Each of these algorithms is distinct in its mathematical nature. We will discuss each of these mathematical problems in our future blog.

In our next blog,,,

In our next blog, we are going to talk about the characteristics of the standardized signature algorithms and some of the algorithms currently in evaluation.

  1. NIST, “Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process” (https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8413-upd1.pdf)
  2. ML-KEM: Module-Lattice-Based Key-Encapsulation Mechanism
  3. ML-DSA: Module-Lattice-Based Digital Signature Algorithm
  4. https://csrc.nist.gov/pubs/fips/204/final
  5. FN-DSA: FFT-over NTRU-Lattice-Based Digital Signature Algorithm
  6. https://csrc.nist.gov/pubs/fips/205/final
  7. SLH-DSA: Stateless Hash-Based Digital Signature Algorithm
  8. https://csrc.nist.gov/pubs/fips/205/final
  9. https://csrc.nist.gov/projects/pqc-dig-sig
  10. NIST Internal Report NIST IR 8610, Status Report on the Second Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process, https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8610.pdf
  11. MQOM: MQ on my Mind
  12. SDitH: Syndrome Decoding in the Head
  13. UOV: Unbalanced Oil and Vinegar
  14. QR-UOV: Quotient Ring UOV
  15. SNOVA: Simple NOVA
takahitoyoshizawa Avatar

Leave a Reply

Discover more from TCR (Taurus Cybersecurity Research)

Subscribe now to keep reading and get access to the full archive.

Continue reading