⚛️ On September 28, NIST’s FIPS 206 team published a new plan for FN-DSA, the standard built on Falcon. It is a proposal they want feedback on. It is the first plan that makes Falcon a function you can test.
Back in 2024, NIST finalized two post-quantum signatures.
- ML-DSA (FIPS 204, Dilithium) is lattice-based.
- SLH-DSA (FIPS 205, SPHINCS+) is hash-based
➤ Falcon was selected in 2022 and assigned FIPS 206. That document is still a draft.
ML-DSA is what most deployments are shipping. Hash-based signatures are more conservative but comes with many drawbacks. Ethereum and Bitcoin are leaning towards that way.
Falcon is the compact lattice scheme. A Falcon-512 signature is 666 bytes. That is why Algorand has chosen Falcon since 2022, for state proofs and now for accounts. And Solana is leaning towards Falcon for latency optimization.
The delay for the standardization comes from the sampler, not the lattice. Falcon samples a discrete Gaussian with arithmetic defined over the reals, implemented in floating point.
Floating Point Arithmetic (IEEE-754) does not give you one result once the computation leaves exact dyadic operations. The same key, message, and seed can produce two valid signatures. There is then no known-answer test an implementation can match, because there is no single answer.
A sampler that is slightly wrong still verifies. The proof requires the implemented distribution to stay close to an ideal discrete Gaussian. If it drifts, the signatures remain valid and the bias leaks the private key. End-to-end test vectors miss it.
⚠️ In short, Floating Point Arithmetic is a nightmare when it comes to sending rockets to the moon, it's even worse for cryptography.
A paper was recently published aiming at fixing these issues with fixed-point implementation.
Fixed-point stores each fractional value as an integer with a fixed number of bits, so every implementation rounds the same way.
NIST wants one signing procedure, specified tightly enough that two correct implementations produce the same signature. So they just announced they'd update their draft for standardization following this paper (
groups.google.com/a/list.nis…)
That publishes nothing yet. But it removes the reason FN-DSA could not be validated. ML-DSA remains the default where the standard is already final.
The discussion about Post Quantum migration for Crypto was not so simple, we might have a new option soon, which could trigger even more discussions...