[CFRG] Re: Silithium - A Compact, Efficient and Non-separable Hybrid Signature
Simon Josefsson <simon@josefsson.org> Thu, 16 July 2026 06:57 UTC
Return-Path: <simon@josefsson.org>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 70D76117A19FF; Wed, 15 Jul 2026 23:57:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784185055; bh=lxaPTTXTbTRwUABhEN8OwCT0mNwuYLc/ru+RB72ISVY=; h=From:To:Cc:Subject:In-Reply-To:References:Date; b=ckiC5SVgrZgitbtSM69HlKHboPGtb/zWogNRQhNnfa/6t8Evt0Bjz4dkqvAckq6S2 Kd3ExM2iGojXExwGxqoYcdmSMVVL+tcxHGoeyEVc2khlwXRA/P0YlICQCUVgZYi9KT 3yPXwSiTqluxxsxOAEG8eH9LNxLKBzdGisme0Ynw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level:
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=josefsson.org header.b="2iByL+zQ"; dkim=pass (2736-bit key) header.d=josefsson.org header.b="YVGYj5aq"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4K__Jd8zfS3H; Wed, 15 Jul 2026 23:57:34 -0700 (PDT)
Received: from uggla.sjd.se (uggla.sjd.se [178.174.241.107]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 70266117A19F7; Wed, 15 Jul 2026 23:57:31 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=ed2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=cvxaIJ9GDv79b7PVakXEQQRBWqJqx5Xi6lnxADiX1gY=; t=1784185050; x=1785394650; b=2iByL+zQ9+VzmBLRSHjxLen3+dPgnMox/e599rPKdFM5p42SYh+rPh9W8Mwk7AJRVnlv0DCQH7a fX2Af7R/mAQ==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=rsa2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=cvxaIJ9GDv79b7PVakXEQQRBWqJqx5Xi6lnxADiX1gY=; t=1784185050; x=1785394650; b=YVGYj5aqvui5JSB5B1DHF0DjGtsH9B0ee1x/AyDA+sKx3lRhAl/zlgL8mYg51e6+RgZdvhuguF8 MQuYn8GJF5/0NtLjkUNj3+oO54+hb5Kndf/WnIBDWMCXqB/wo/QvjZUf4QU/EbzZzAehZDTuwfqZh A9UvwZ02zL4vnpFDZQ6rlCjogY9VrS0EywjYmx49ZYEN03Tjp9LXePDceONGhEIcN6U4tXzjGQ5+I sRI63gT4wcry5eEpE7qwIE/Kds346uo4ZCZjwHoRVxZ8s9J8svBIwkCil3yigB9oySHANat07W3rl DkVBMm7DRo1mNKH8DmL3coOmFEv3PvLKMVB8OWO60pZaNpWi60ZhYlmTmG5e7KlHG2g0XJVYl4tMq PXtt4heeEEwmNBoZPk4JtnmLIeHglf1bLlOtFHbwGz72g5u+J6IDSFME+j9jKeJxOiUSpiWBA;
Received: from h-178-174-130-130.a498.priv.bahnhof.se ([178.174.130.130]:39324 helo=frallan) by uggla.sjd.se with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <simon@josefsson.org>) id 1wkG27-000wtg-3q; Thu, 16 Jul 2026 06:57:23 +0000
From: Simon Josefsson <simon@josefsson.org>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
In-Reply-To: <AS4PR07MB8825C2A9CDB6152278B064E789C72@AS4PR07MB8825.eurprd07.prod.outlook.com> (John Mattsson's message of "Thu, 16 Jul 2026 06:26:19 +0000")
References: <47c7ed21f0e041f5a20c9736606b0777@ssi.gouv.fr> <20260716051125.906425.qmail@cr.yp.to> <AS4PR07MB8825C2A9CDB6152278B064E789C72@AS4PR07MB8825.eurprd07.prod.outlook.com>
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt
X-Hashcash: 1:23:260716:john.mattsson=40ericsson.com@dmarc.ietf.org::bpH385zl2LtB+3Lo:4zc7
X-Hashcash: 1:23:260716:djb@cr.yp.to::ojFiSRP8UjRrvYdR:KCXj
X-Hashcash: 1:23:260716:cfrg@irtf.org::rIJHGaRivzKfV4sL:IxcH
Date: Thu, 16 Jul 2026 08:57:25 +0200
Message-ID: <87cxwnctgq.fsf@josefsson.org>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: HEJABC27R6YXHWI6S4DHYG2A3JQRB25D
X-Message-ID-Hash: HEJABC27R6YXHWI6S4DHYG2A3JQRB25D
X-MailFrom: simon@josefsson.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "D. J. Bernstein" <djb@cr.yp.to>, "cfrg@irtf.org" <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Silithium - A Compact, Efficient and Non-separable Hybrid Signature
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/y5PIvSt8A0UtoLZmvv48Auo2H2M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org> writes: > One difference is that Mothma-Ed25519-ML-DSA-65 requires retaining > SHA-2, whereas Silithium (which I assume can be used with > edwards25519) can be implemented using only SHA-3. That's only because Ed25519 uses SHA-512 internally, right? Sillithium doesn't use Ed25519 as a black-box, if I understand correctly (which seems like a implementation challenge). Would a Ed25519 variant using SHAKE256 be relevant? There is already Ed448 that do not use SHA2. I'm not convinced any of the SHA2 weaknesses even apply to Ed25519. > If people plan to use hybrids long-term, that is an advantage for > Silithium. I believe the point of using hybrids is to continue using old crypto as a black-box in parallel with new crypto, in a safe way. A hybrid that doesn't re-use traditional crypto as a black box seems esoteric to me. /Simon
- [CFRG] Silithium - A Compact, Efficient and Non-s… DEVEVEY Julien
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… Ilari Liusvaara
- [CFRG] Re: Silithium - A Compact, Efficient and N… Morgane Guerreau
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… D. J. Bernstein
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… Simon Josefsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… D. J. Bernstein
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… D. J. Bernstein
- [CFRG] Re: Silithium - A Compact, Efficient and N… D. J. Bernstein
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… Simon Josefsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… Neil Madden
- [CFRG] Re: Silithium - A Compact, Efficient and N… John Mattsson
- [CFRG] Re: Silithium - A Compact, Efficient and N… D. J. Bernstein
- [CFRG] Re: Silithium - A Compact, Efficient and N… Ilari Liusvaara
- [CFRG] Re: Silithium - A Compact, Efficient and N… Sophie Schmieg
- [CFRG] Re: Silithium - A Compact, Efficient and N… Ilari Liusvaara
- [CFRG] Re: Silithium - A Compact, Efficient and N… Wang Guilin