Chapter 6ML-DSA

Chapter 6: ML-DSA

August 25, 20263 min readbeginner

Chapter 5 built the scheme that protects secrecy. This chapter builds the one that protects authenticity.

01.What this chapter is for

Chapter 5 built the scheme that protects secrecy. This chapter builds the one that protects authenticity.

ML-DSA is FIPS 204, the post-quantum digital signature standard. It runs on the same ring, the same transform and the same module lattices as ML-KEM, and yet the construction looks almost nothing like it. Encryption hides a message from everyone but one person. A signature proves to everyone that one particular person produced something. Those are different problems and they need different machinery.

The central difficulty is one that does not arise in the KEM at all. A signature is computed using the secret key and then published. Every signature is therefore a piece of evidence about the key, released voluntarily, in unlimited quantity. Getting that to leak nothing is the whole design problem, and the technique that solves it, rejection sampling, is what gives this chapter its shape.

By the end you should be able to explain why the obvious construction leaks the key outright, what "Fiat-Shamir with aborts" does about it, and how a verifier reconstructs a value it was never sent.

02.Who this is written for

The same reader as before. Chapter 5 is assumed, chiefly for the shape of a Module-LWE key pair and for comfort with the notation As+eA\mathbf{s} + \mathbf{e}. Nothing about ML-KEM's internals is needed.

Two things in this chapter have no counterpart earlier in the book and are built from scratch here: the idea of a proof of knowledge, which is where signatures come from historically, and a family of small rounding routines that let a verifier work with an approximation of a value it does not hold.

03.Reading order

  1. What a Signature Is. The contract, and the attacker model that makes it hard.
  2. Schnorr and Fiat-Shamir. Where the construction comes from: an interactive proof of knowledge, made non-interactive by hashing.
  3. Why the Naive Version Leaks. The obvious lattice translation, and a simulation showing it hands over the secret key.
  4. Rejection Sampling, or Fiat-Shamir With Aborts. The fix, and what it costs.
  5. The Parameter Sets. Seven new symbols, and where each of them comes from.
  6. Key Generation. Including why the public key is deliberately truncated.
  7. Signing. The full loop, the rounding gadgets, and the hint vector.
  8. Verification. Reconstructing a commitment from a response, and the algebra proving it works.
  9. Security, and the Chapter Summary. The two lattice problems involved, and the chapter summary.

04.The shape of the answer, in advance

It helps to know where this is going, because the pieces only make sense together.

A signature is going to be a value z\mathbf{z} that satisfies an equation involving the public key and a challenge derived by hashing the message. Producing such a z\mathbf{z} requires the secret key. Checking one does not.

Everything else, the rejection loop, the high and low bit decomposition, the hint vector, exists to solve two secondary problems: making z\mathbf{z} carry no information about the secret, and making the signature small enough to be worth sending. Neither is optional, and both add machinery that can look arbitrary until you see which problem it answers.

FeedbackBook mode
post-quantum-cryptographycryptographymathematics