[CFRG] Silithium - A Compact, Efficient and Non-separable Hybrid Signature

DEVEVEY Julien <Julien.DEVEVEY@ssi.gouv.fr> Wed, 15 July 2026 14:24 UTC

Return-Path: <Julien.DEVEVEY@ssi.gouv.fr>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D9080117394AD for <cfrg@mail2.ietf.org>; Wed, 15 Jul 2026 07:24:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784125466; bh=fov6MLmMTIvBXgVq46C0bfdI1sYoTavHAA46puuDSB4=; h=From:To:CC:Subject:Date; b=mdqyMz86PWD8HoEoYUitVKyr4otRgpJo4kzQlilbALYWujwYBqtZNXlXjzsciiBzA a4vJr2zGFED7wm9iuD5LwPFlBYryiZTnaVnKK555xGWBgoblIPWX55DB3wy1ohwpdN cQMyiLog7xW04My6wrTQLeOGJMfWzn8EJhW0+CsM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ssi.gouv.fr
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mT1zKE6s5xpJ for <cfrg@mail2.ietf.org>; Wed, 15 Jul 2026 07:24:26 -0700 (PDT)
Received: from smtp-out-1a.sgdsn.gouv.fr (smtp-out-1b.sgdsn.gouv.fr [143.126.255.31]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 02211117394A3 for <cfrg@irtf.org>; Wed, 15 Jul 2026 07:24:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ssi.gouv.fr; s=20240601; t=1784125459; bh=fov6MLmMTIvBXgVq46C0bfdI1sYoTavHAA46puuDSB4=; h=From:To:CC:Subject:Date:From:Subject; b=MT4spVdes1oEfLXLXc9RyV0KQoDN0iQdpYkmkAf1AzGzyR1oUNXJmSvVNeVhqAVgI YxGsuSJ21WBVsLFSfMXSogyheLPJPxTc5UZ/GvRxCluHoFdNMxY89+ZDIbechy8m7g rbkHCH8PqAf/akacAem5+cXzsFIByM0PH4QOcByi91lTxoKrOXYMAVOruW+9KCVPdQ TCmoD53vVS3lRnqa6Uo/iMqiWzkrjoUKmSw5iE+NvWd+eub3IWos1xFXWO7/p2uGds 05S3xgXCOkxoQPQeUqQtidjP1O2Bi9x+FxjfTJveZHfAUAZeu5g4NISi28k9Io/pGK W+5TuixVRQtVg==
From: DEVEVEY Julien <Julien.DEVEVEY@ssi.gouv.fr>
To: "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: Silithium - A Compact, Efficient and Non-separable Hybrid Signature
Thread-Index: Ad0UXsr4sPrZzPrLQnmC268oLzBhFQ==
Date: Wed, 15 Jul 2026 14:24:19 +0000
Message-ID: <47c7ed21f0e041f5a20c9736606b0777@ssi.gouv.fr>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
Content-Type: multipart/related; boundary="_004_47c7ed21f0e041f5a20c9736606b0777ssigouvfr_"; type="multipart/alternative"
MIME-Version: 1.0
Message-ID-Hash: NRLU2GHUQNSKSV2R327YGILTIQXMDCK4
X-Message-ID-Hash: NRLU2GHUQNSKSV2R327YGILTIQXMDCK4
X-MailFrom: Julien.DEVEVEY@ssi.gouv.fr
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: ROMEAS Maxime <Maxime.ROMEAS@ssi.gouv.fr>, Morgane Guerreau <morgane.guerreau@pqshield.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Silithium - A Compact, Efficient and Non-separable Hybrid Signature
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/0wWC_IcaFrNGj7ekKMkpqnwlNo8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

Hi everyone,
We wanted to share with you our first draft of a PQ/T hybrid signature scheme, called Silithium.

Very roughly, Silithium can be seen as ML-DSA sandwiched between elliptic curve operation. Conversely it could be seen as an instance of Schnorr's signatures with "ML-DSA as the hash function".
Silithium can be easily implemented, assuming elliptic curve operations and any kind of ML-DSA implementation are available. As we expect both to be available during the PQ transition period, this lessens the burden on developers to deploy PQ/T hybrid cryptography.
Performance-wise, Silithium has (marginally) faster signing and verification time than composite ECDSA+ML-DSA. It also benefits from smaller signature sizes, only increasing it by 32 bytes with respect to ML-DSA.
Security-wise, we claim the following:

  *   Forging a Silithium signature implies breaking ML-DSA and breaking the discrete logarithm problem, which means that hybridization is successful.
  *   However, strong unforgeability is equivalent to that of ML-DSA: while we are not degrading ML-DSA's security, this is not totally hybridized.
  *   Silithium can safely be used in "backward compatibility mode", i.e., the T component of the signing key can be extracted and used to sign with ECDSA without decreasing the overall security of the scheme. Applications with a need for backward compatibility are thus not required to generate different keypairs for their legacy uses.
  *   This is unfortunately not the case when it comes to using the PQ component of the signing to key to sign with ML-DSA, as Silithium signatures are comprised of a ML-DSA signature, which could be reused in the PQ-only context. Note that Silithium calls ML-DSA with a different, unpredictable context every time it signs a message. If using Silithium in tandem with ML-DSA is required, then constraints could be put on user-submitted contexts to ML-DSA verification to avoid this issue.

Find the draft here: https://www.ietf.org/archive/id/draft-devevey-cfrg-silithium-00.html
Any kind of feedback would be greatly appreciated, as writing I-D is a novelty for the three of us. We are also suggesting a few variants at the end of the draft, with different trade-offs between "implementation easiness" and security. For instance, the original proposal in our research paper https://eprint.iacr.org/2025/2059 required to modify ML-DSA's signing key as well as an external-mu implementation of ML-DSA's verification to be easily implemented, but allowed Silithium's key to be used in ECDSA and ML-DSA without security issues. Feedback on which variant is the most suited is very useful.

We will also be attending IETF 126, where we will present the scheme Wednesday. See you there!

Best,
Julien Devevey
Expert en Cryptographie
Laboratoire de Cryptographie
Division Scientifique et Technique
Sous-direction Expertise

Agence nationale de la sécurité des systèmes d'information (ANSSI)
31, Quai Grenelle, 75015 Paris 15
Tel : 01 71 75 25 93  / 06 07 74 31 11
cyber.gouv.fr<https://cyber.gouv.fr/> | X<https://twitter.com/anssi_fr> | LinkedIn<https://www.linkedin.com/company/anssi-fr/mycompany/> | Dailymotion<https://www.dailymotion.com/ANSSI_FR> | GitHub<https://github.com/ANSSI-FR> | SoundCloud<https://soundcloud.com/anssi-fr>

[logo signature]<https://cyber.gouv.fr/>

Les données à caractère personnel recueillies et traitées dans le cadre de cet échange, le sont à seule fin d'exécution d'une relation professionnelle et s'opèrent dans cette seule finalité et pour la durée nécessaire à cette relation. Si vous souhaitez faire usage de vos droits de consultation, de rectification et de suppression de vos données, veuillez contacter contact.rgpd@sgdsn.gouv.fr. Si vous avez reçu ce message par erreur, nous vous remercions d'en informer l'expéditeur et de détruire le message. The personal data collected and processed during this exchange aims solely at completing a business relationship and is limited to the necessary duration of that relationship. If you wish to use your rights of consultation, rectification and deletion of your data, please contact: contact.rgpd@sgdsn.gouv.fr. If you have received this message in error, we thank you for informing the sender and destroying the message.