Sitemap
Press enter or click to view image in full size

Member-only story

Get Ready for FN-DSA: Slower Than Dilithium But Smaller Keys/Ciphertext

7 min readMar 28, 2025

--

Currently, we have two main digital signature standards for PQC. These are FIPS 204 (Dilithium — ML-DSA) and FIPS 205 (SPHINCS+ — SLH-DSA). Now, NIST are defining a third standard: FIPS 206 and based on the FALCON method. It will be given the name of FN-DSA — FFT (fast-Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm). The baseline is that FALCON is slower in performance than Dilithium, but the key sizes and ciphertext are much smaller.

As you may know, most of our public key methods are at threat from quantum computers. This includes ECC, RSA and discrete log methods. And so, over the next decade, we are likely to see a migration of these methods to ones which are quantum robust — and see the rise of PQC (Post Quantum Cryptography).

Performance and key sizes

With Falcon-512 (which has an equivalent security to RSA-2048), we generate a public key of 897 bytes, a private key of 1,281 bytes, and a signature size of 690 bytes, while FALCON-1024 gives a public key of 1,793 bytes, a private key of 2,305 bytes, and a signature size of 1,313 bytes [here]:

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.