A look at the latest post-quantum signature standardization candidates
ID: 61e36a96-125e-5e29-9bc7-6d306d0b137e
STIX ID: report--61e36a96-125e-5e29-9bc7-6d306d0b137e
Feed Name: Cloudflare Blog
The report analyzes NIST’s second-round post-quantum signature candidates (“signatures on ramp”) for TLS, comparing sizes and performance of schemes like ML-DSA, SLH-DSA, Falcon, HAWK, SNOVA, MAYO, FAEST, SQISign, and UOV, and assessing their feasibility for handshake and certificate use. Drawing on QUIC telemetry and prior experiments, it finds that added certificate bytes notably impact handshake times and typical connections, and proposes mitigations such as mixing schemes, reducing certificate chain signatures, exploring KEM-based authentication, and broader WebPKI changes. It notes ongoing deployment of post-quantum key agreement and plans to offer ML-DSA certificates when CA support arrives, while continuing to evaluate performance and security trade-offs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
