logo

A look at the latest post-quantum signature standardization candidates

ID: c73883ad-b48e-5aa4-913d-33c5091fadcf

STIX ID: report--c73883ad-b48e-5aa4-913d-33c5091fadcf

Feed Name: Cloudflare Blog

Date Published: 2024-11-07

Date Updated: 2026-04-27

Author: Bas Westerbaan

...
...

This report reviews NIST’s advancement of 14 post-quantum signature schemes and evaluates their suitability for TLS by comparing size, performance, and implementation risks of standardized options (ML-DSA, SLH-DSA, Falcon) against newer candidates (e.g., HAWK, FAEST, UOV, SNOVA, MAYO, QR-UOV, SQISign). Using Cloudflare telemetry, it shows that certificates already account for a large share of bytes on many QUIC connections and that adding ≥9kB can cause ~15% handshake slowdowns, with client failures increasing beyond ~10kB. While none rival classical ECC, some approaches (e.g., HAWK; combining UOV with another scheme; parameter-flexible SNOVA/MAYO; FAEST’s VOLE-in-the-head) could reduce overhead versus ML-DSA/Falcon, though several rely on newer assumptions or need further scrutiny. The authors propose complementing algorithm selection with ecosystem changes—fewer transmitted signatures, KEM-based handshake authentication, and WebPKI redesign—while planning to support ML-DSA certificates as CAs enable them (estimated around 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.