The Parameter Sets
August 25, 20266 min readbeginner
ML-DSA introduces more symbols than any other chapter of this book. This note lists them, gives the three parameter sets, and explains where each number comes from.
ML-DSA introduces more symbols than any other chapter of this book. This note lists them, gives the three parameter sets, and explains where each number comes from.
01.The table
| ML-DSA-44 | ML-DSA-65 | ML-DSA-87 | |
|---|---|---|---|
| NIST level | 2 | 3 | 5 |
| 2 | 4 | 2 | |
| 39 | 49 | 60 | |
| 78 | 196 | 120 | |
| 80 | 55 | 75 | |
| signature | 2420 B | 3309 B | 4627 B |
Shared by all three: , , and a rounding parameter .
02.What each symbol is
and . The module matrix is , the secret is , and the error is .
Note that this is rectangular, where ML-KEM's was square. The two dimensions do different jobs: sets the size of the response , which dominates the signature, while sets the size of the commitment. They are tuned separately because the signature size and the security level pull on them differently.
. The centred binomial width for and , so their coefficients lie in .
. The challenge is a polynomial with exactly non-zero coefficients, each , and all the rest zero. That peculiar shape is deliberate and is explained below.
. The commitment randomness has coefficients uniform on . This is the of Rejection Sampling, or Fiat-Shamir With Aborts.
. The bucket width used by the high and low bit decomposition in Signing.
. A bound on how large and can get. This is the of the rejection rule.
. A cap on how many bits may be set in the hint vector, which Signing introduces.
03.Where comes from
The one relationship worth deriving, because it explains why the challenge has its odd shape.
The challenge has non-zero coefficients, each . The secret has coefficients bounded by . When they are multiplied in , each output coefficient is a sum of at most terms, each of size at most . So
Check it against the table:
ML-DSA-44: .
ML-DSA-65: .
ML-DSA-87: .
Exact in all three cases. is not an independent parameter at all, it is defined by the other two.
That derivation is also the reason is sparse with unit coefficients. From Rejection Sampling, or Fiat-Shamir With Aborts, the acceptance rate is , so keeping small is what keeps signing from restarting endlessly. A dense challenge with large coefficients would make enormous and the rejection rate catastrophic. A sparse challenge keeps in the low hundreds against a of or more, so stays under one percent per coordinate.
Meanwhile the challenge still has to be unguessable. With positions chosen among 256 and each carrying a sign, the number of possible challenges is around , which is far beyond search.
So the sparse-and-small shape serves two constraints at once: enough entropy to be a real challenge, small enough norm to keep the rejection loop viable.
Why is so much larger than the KEM's
ML-KEM used , twelve bits. ML-DSA uses , twenty-three bits. Same ring degree, same lattice family, a modulus two thousand times larger.
The reason is dynamic range. In the KEM, every quantity is small: secrets, errors and messages all fit in a narrow band, and the modulus only has to be big enough that the noise does not wrap around.
In the signature, alone has coefficients up to , which is already larger than the whole of ML-KEM's . The commitment is wider still. The algebra must not wrap during honest operation, so has to accommodate all of it.
There is a second reason, and it is the one from Chapter 4. Because
there are thirteen factors of two available, and the transform needs only nine. So ML-DSA gets the complete length-256 negacyclic NTT that ML-KEM cannot have. The larger modulus that dynamic range forced turns out to also solve the transform problem.
05.Signature sizes
At 2420 to 4627 bytes, ML-DSA signatures are large. An Ed25519 signature is 64 bytes, so the increase is a factor of thirty-eight to seventy-two.
Most of it is , which is ring elements with coefficients up to , so roughly bits. The hint is small by design, under a hundred bytes, which is what enforces. The third piece is the challenge hash, carried at bytes, so 32, 48 and 64 across the three sets.
That last field is worth pinning down, because it is where published tables disagree with each other. Round-three Dilithium and the FIPS 204 draft carried a 32-byte challenge hash at every security level, giving 3293 and 4595 for the two larger sets. The final standard widened it to , and and the hint did not move, so the whole difference between the two tables is that one field. A table quoting 3293 is reading the draft.
This is the cost that makes signatures the harder half of the post-quantum migration. A kilobyte added to a TLS handshake is tolerable. A certificate chain contains several signatures plus several public keys, and inflating all of them at once is what makes the transition genuinely awkward for constrained protocols. It is also why SLH-DSA, whose signatures are larger still, is positioned as a conservative backup rather than a default.