Chapter 6ML-DSA

The Parameter Sets

August 25, 20266 min readbeginner

ML-DSA introduces more symbols than any other chapter of this book. This note lists them, gives the three parameter sets, and explains where each number comes from.

ML-DSA introduces more symbols than any other chapter of this book. This note lists them, gives the three parameter sets, and explains where each number comes from.

01.The table

ML-DSA-44ML-DSA-65ML-DSA-87
NIST level235
(k,ℓ)(k, \ell)(4,4)(4, 4)(6,5)(6, 5)(8,7)(8, 7)
η\eta242
τ\tau394960
γ1\gamma_12172^{17}2192^{19}2192^{19}
γ2\gamma_2(q−1)/88(q-1)/88(q−1)/32(q-1)/32(q−1)/32(q-1)/32
β\beta78196120
ω\omega805575
signature2420 B3309 B4627 B

Shared by all three: n=256n = 256, q=8380417=223−213+1q = 8380417 = 2^{23} - 2^{13} + 1, and a rounding parameter d=13d = 13.

02.What each symbol is

kk and ℓ\ell. The module matrix is A∈Rqk×ℓA \in R_q^{k \times \ell}, the secret is s1∈Rqℓ\mathbf{s}_1 \in R_q^{\ell}, and the error is s2∈Rqk\mathbf{s}_2 \in R_q^{k}.

Note that this is rectangular, where ML-KEM's was square. The two dimensions do different jobs: ℓ\ell sets the size of the response z\mathbf{z}, which dominates the signature, while kk sets the size of the commitment. They are tuned separately because the signature size and the security level pull on them differently.

η\eta. The centred binomial width for s1\mathbf{s}_1 and s2\mathbf{s}_2, so their coefficients lie in [−η,η][-\eta, \eta].

τ\tau. The challenge cc is a polynomial with exactly τ\tau non-zero coefficients, each ±1\pm 1, and all the rest zero. That peculiar shape is deliberate and is explained below.

γ1\gamma_1. The commitment randomness y\mathbf{y} has coefficients uniform on (−γ1,γ1](-\gamma_1, \gamma_1]. This is the γ\gamma of Rejection Sampling, or Fiat-Shamir With Aborts.

γ2\gamma_2. The bucket width used by the high and low bit decomposition in Signing.

β\beta. A bound on how large cs1c\mathbf{s}_1 and cs2c\mathbf{s}_2 can get. This is the β\beta of the rejection rule.

ω\omega. A cap on how many bits may be set in the hint vector, which Signing introduces.

03.Where β\beta comes from

The one relationship worth deriving, because it explains why the challenge has its odd shape.

The challenge cc has τ\tau non-zero coefficients, each ±1\pm 1. The secret s1\mathbf{s}_1 has coefficients bounded by η\eta. When they are multiplied in RqR_q, each output coefficient is a sum of at most τ\tau terms, each of size at most η\eta. So

∥c s1∥∞  ≤  τ⋅η  =  β.\|c\,\mathbf{s}_1\|_\infty \;\le\; \tau \cdot \eta \;=\; \beta .

Check it against the table:

ML-DSA-44: τη=39×2=78=β\tau \eta = 39 \times 2 = 78 = \beta.

ML-DSA-65: τη=49×4=196=β\tau \eta = 49 \times 4 = 196 = \beta.

ML-DSA-87: τη=60×2=120=β\tau \eta = 60 \times 2 = 120 = \beta.

Exact in all three cases. β\beta is not an independent parameter at all, it is defined by the other two.

That derivation is also the reason cc is sparse with unit coefficients. From Rejection Sampling, or Fiat-Shamir With Aborts, the acceptance rate is (1−β/γ1)N(1 - \beta/\gamma_1)^N, so keeping β\beta small is what keeps signing from restarting endlessly. A dense challenge with large coefficients would make β\beta enormous and the rejection rate catastrophic. A sparse ±1\pm 1 challenge keeps β\beta in the low hundreds against a γ1\gamma_1 of 2172^{17} or more, so β/γ1\beta/\gamma_1 stays under one percent per coordinate.

Meanwhile the challenge still has to be unguessable. With τ=39\tau = 39 positions chosen among 256 and each carrying a sign, the number of possible challenges is around 21922^{192}, which is far beyond search.

So the sparse-and-small shape serves two constraints at once: enough entropy to be a real challenge, small enough norm to keep the rejection loop viable.

Why qq is so much larger than the KEM's

ML-KEM used q=3329q = 3329, twelve bits. ML-DSA uses q=8380417q = 8380417, twenty-three bits. Same ring degree, same lattice family, a modulus two thousand times larger.

The reason is dynamic range. In the KEM, every quantity is small: secrets, errors and messages all fit in a narrow band, and the modulus only has to be big enough that the noise does not wrap around.

In the signature, y\mathbf{y} alone has coefficients up to γ1=219\gamma_1 = 2^{19}, which is already larger than the whole of ML-KEM's Zq\mathbb{Z}_q. The commitment w=Ay\mathbf{w} = A\mathbf{y} is wider still. The algebra must not wrap during honest operation, so qq has to accommodate all of it.

There is a second reason, and it is the one from Chapter 4. Because

q−1  =  223−213  =  213(210−1),q - 1 \;=\; 2^{23} - 2^{13} \;=\; 2^{13}\left(2^{10} - 1\right),

there are thirteen factors of two available, and the transform needs only nine. So ML-DSA gets the complete length-256 negacyclic NTT that ML-KEM cannot have. The larger modulus that dynamic range forced turns out to also solve the transform problem.

05.Signature sizes

At 2420 to 4627 bytes, ML-DSA signatures are large. An Ed25519 signature is 64 bytes, so the increase is a factor of thirty-eight to seventy-two.

Most of it is z\mathbf{z}, which is ℓ\ell ring elements with coefficients up to γ1\gamma_1, so roughly ℓ⋅256⋅18\ell \cdot 256 \cdot 18 bits. The hint is small by design, under a hundred bytes, which is what ω\omega enforces. The third piece is the challenge hash, carried at λ/4\lambda/4 bytes, so 32, 48 and 64 across the three sets.

That last field is worth pinning down, because it is where published tables disagree with each other. Round-three Dilithium and the FIPS 204 draft carried a 32-byte challenge hash at every security level, giving 3293 and 4595 for the two larger sets. The final standard widened it to λ/4\lambda/4, and z\mathbf{z} and the hint did not move, so the whole difference between the two tables is that one field. A table quoting 3293 is reading the draft.

This is the cost that makes signatures the harder half of the post-quantum migration. A kilobyte added to a TLS handshake is tolerable. A certificate chain contains several signatures plus several public keys, and inflating all of them at once is what makes the transition genuinely awkward for constrained protocols. It is also why SLH-DSA, whose signatures are larger still, is positioned as a conservative backup rather than a default.

FeedbackBook mode
post-quantum-cryptographycryptographymathematics