Skip to content

Conversation

@emanjon
Copy link
Collaborator

@emanjon emanjon commented Feb 2, 2026

For FN-DSA-512 the difference per certificate compared to ECDSA with P-256 is (897+666-32-64)

For ML-DSA-44 the difference per certificate compared to ECDSA with P-256 is (1312+2420-32-64)

The absolute savings stay the same but the relative savings in percentage decreases.

In the future NIST may standardize isogeny-based signatures (SQISign) with 64 bytes PK and 177 byte SIG.

The numbers in the table only considers the raw numbers in the algorithms. Encoding might change the numbers with a few bytes..

For FN-DSA-512 the difference per certificate compared to ECDSA with P-256 is (897+666-32-64)

For ML-DSA-44 the difference per certificate compared to ECDSA with P-256 is (1312+2420-32-64)

The absolute savings stay the same but the relative savings in percentage decreases.

In the future NIST may standardize isogeny-based signatures (SQISign) with 64 bytes PK and 177 byte SIG.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants