[CFRG] Re: Silithium - A Compact, Efficient and Non-separable Hybrid Signature

Ilari Liusvaara <ilariliusvaara@welho.com> Wed, 15 July 2026 19:33 UTC

Return-Path: <ilariliusvaara@welho.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7071F117610D6 for <cfrg@mail2.ietf.org>; Wed, 15 Jul 2026 12:33:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784144004; bh=Bi2XR7xvZNykwEx+fRiqF0/ibm/jNfSmt1lspepJB3Q=; h=Date:From:To:Subject:References:In-Reply-To; b=PfwZqwJFe0IlcEwvLTqngZnOO+jHBmgweO6z6kCxAOikgF3fu08Jq1d87/Uc0aaDU xt1th07GjOXSk7vLCQOIzyzyjtzkuq0nrNHePkF8Gr+Sc72vp8+rpyd8KELOUz+7Ky jetkci7Fate6cpXMbierSAz/Tyg5NzLkblfBBVEc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=welho.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0felk3yR7mGs for <cfrg@mail2.ietf.org>; Wed, 15 Jul 2026 12:33:23 -0700 (PDT)
Received: from smtp.dnamail.fi (sender103.dnamail.fi [83.102.40.157]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 932EE117610D1 for <cfrg@irtf.org>; Wed, 15 Jul 2026 12:33:23 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.dnamail.fi (Postfix) with ESMTP id 23A854098E8A for <cfrg@irtf.org>; Wed, 15 Jul 2026 22:33:16 +0300 (EEST)
X-Virus-Scanned: X-Virus-Scanned: amavis at smtp.dnamail.fi
Received: from smtp.dnamail.fi ([83.102.40.157]) by localhost (dmail-psmtp02.s.dnaip.fi [127.0.0.1]) (amavis, port 10024) with ESMTP id h6KHxPVvGITw for <cfrg@irtf.org>; Wed, 15 Jul 2026 22:33:15 +0300 (EEST)
Received: from LK-Perkele-VII2 (87-92-117-27.bb.dnainternet.fi [87.92.117.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: hliusvaa@dnamail.internal) by smtp.dnamail.fi (Postfix) with ESMTPSA id 8C0F84098E80 for <cfrg@irtf.org>; Wed, 15 Jul 2026 22:33:15 +0300 (EEST)
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp.dnamail.fi 8C0F84098E80
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=welho.com; s=2025-03; t=1784143995; bh=g5q4BKaS1+UDcHUTJceV46g1yX38R63TBiJHUF812S4=; h=Date:From:To:Subject:References:In-Reply-To:From; b=O9Q0WD+LRSqnRKpVEpyO7t+7/OGbIzKuHMFMpR9Rx0JnobtmwRDO7ROUc1DTybPX1 8Z7kZ0m5GcOpulXA0U0hWJJsr/NJgFlr9lDvIY93mVgbcSgl72S6ug5va9pmIPhwRY isRZMLB+3XdUZsUMjprLXXGcs2OQxqC7A6hhrn15tgFVERXELlBAtO6sjLpJwlDmJ7 0tmoEY8Sdf5u3xWIH0azGnzYv/4PM9K3P3uUNnEKlE+WdlSRNbrGXcmA2tdceWrkx2 i64z2KsWvp7hlMNaBcPUVe9dpisNZB2ygevNDK+0ViSe8ZDqyW4XRbtx+8sqcau1V/ jbgM8lFHI16mw==
Date: Wed, 15 Jul 2026 22:33:10 +0300
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: "cfrg@irtf.org" <cfrg@irtf.org>
Message-ID: <alfgdl50G-gzxgen@LK-Perkele-VII2.locald>
References: <47c7ed21f0e041f5a20c9736606b0777@ssi.gouv.fr> <AS4PR07MB8825FD0BE6744C9C6623072789F82@AS4PR07MB8825.eurprd07.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <AS4PR07MB8825FD0BE6744C9C6623072789F82@AS4PR07MB8825.eurprd07.prod.outlook.com>
Sender: ilariliusvaara@welho.com
Message-ID-Hash: INN4GRZZMJAAZODO2APB3EZHQT2PCFSB
X-Message-ID-Hash: INN4GRZZMJAAZODO2APB3EZHQT2PCFSB
X-MailFrom: ilariliusvaara@welho.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Silithium - A Compact, Efficient and Non-separable Hybrid Signature
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/PkIkfBH_oLRxk74GxL3HsS_zwak>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

On Wed, Jul 15, 2026 at 04:27:16PM +0000, John Mattsson wrote:
> Hi Julien,
> 
> I think it is valuable to see continued work on improving the
> practical deployment options for post-quantum signatures.
> Designing new composite signature algorithms is something that should
> have been done in CFRG to begin with.
> 
> >Silithium is strongly unforgeable as long as ML-DSA is.
> 
> I think this should be considered a minimum requirement for all PQ/T
> composites. While the T component was the most important part during
> what ANSSI calls Phase 1, we are now in Phase 2, where the PQ
> component is the most important. In Phase 3, the PQ component will be
> the only component that matters.

This gave me the following idea for ECC+ML-DSA hybrid that is strongly
unforgeable as long as either is:

muprime <- H(A|tr|M, 64)
r <-$ ]0,L[
R <- rG
sq <- ML-DSA(sk, alg_id, R|muprime)
s <- r + H(sq, len) * a (mod L)
sig <- R | sq | s

When verifying, check that:

- R and A are canonical encodings for point.
- R and A have high order.
- 0 < s < L.
- sq is valid ML-DSA signature.
- sG = R + H(sq, len)*A.


The idea is that both components essentially sign one another (with s
indirectly signed), and ML-DSA also signs the input.

For security, len needs to be big enough. What is big enough depends on
L, but is Omega(log L).

This does not support pass-through context, but adding that is
trivial.

This construction does not depend on the elliptic curve. However, it
depends on the internal structure of ML-DSA.




-Ilari