ML-DSA (FIPS 204)
O que é ML-DSA (FIPS 204)?
ML-DSA (FIPS 204)NIST's standardized post-quantum digital signature algorithm, derived from CRYSTALS-Dilithium and published as FIPS 204 in August 2024 — the default lattice-based PQ signature for code signing, X.509, and DNSSEC over time.
ML-DSA (Module-Lattice-Based Digital Signature Algorithm), standardized as FIPS 204 on 13 August 2024, is NIST's primary lattice-based post-quantum signature scheme, derived from CRYSTALS-Dilithium. It defines three parameter sets — ML-DSA-44, ML-DSA-65, and ML-DSA-87 — providing security comparable to AES-128/192/256 under standard lattice assumptions. Signatures are roughly 2.4 to 4.6 KB and public keys 1.3 to 2.6 KB, which is substantially larger than Ed25519 or ECDSA but small enough to fit comfortably in X.509 certificates, code-signing manifests, and DNSSEC records. ML-DSA is the default lattice-based PQ signature for use cases that cannot tolerate the much larger but more conservative SLH-DSA (FIPS 205, hash-based). Implementations are appearing in the BoringSSL/OpenSSL family, in Linux distributions' code-signing pipelines, and in hardware tokens. Migration strategies include hybrid certificates (classical ECDSA + ML-DSA, both signatures verified) and gradual rollouts on long-lived signing keys (root CAs, firmware update keys) where quantum resilience matters most.
● Exemplos
- 01
A code-signing CA issues hybrid ECDSA + ML-DSA-65 certificates so that signatures verify on both classical and post-quantum verifiers during the migration window.
- 02
A firmware-update key for a 15-year-lifetime IoT device is rotated to ML-DSA-87 to ensure quantum-resilience across the device's deployed life.
● Perguntas frequentes
O que é ML-DSA (FIPS 204)?
NIST's standardized post-quantum digital signature algorithm, derived from CRYSTALS-Dilithium and published as FIPS 204 in August 2024 — the default lattice-based PQ signature for code signing, X.509, and DNSSEC over time. Pertence à categoria Criptografia da cibersegurança.
O que significa ML-DSA (FIPS 204)?
NIST's standardized post-quantum digital signature algorithm, derived from CRYSTALS-Dilithium and published as FIPS 204 in August 2024 — the default lattice-based PQ signature for code signing, X.509, and DNSSEC over time.
Como funciona ML-DSA (FIPS 204)?
ML-DSA (Module-Lattice-Based Digital Signature Algorithm), standardized as FIPS 204 on 13 August 2024, is NIST's primary lattice-based post-quantum signature scheme, derived from CRYSTALS-Dilithium. It defines three parameter sets — ML-DSA-44, ML-DSA-65, and ML-DSA-87 — providing security comparable to AES-128/192/256 under standard lattice assumptions. Signatures are roughly 2.4 to 4.6 KB and public keys 1.3 to 2.6 KB, which is substantially larger than Ed25519 or ECDSA but small enough to fit comfortably in X.509 certificates, code-signing manifests, and DNSSEC records. ML-DSA is the default lattice-based PQ signature for use cases that cannot tolerate the much larger but more conservative SLH-DSA (FIPS 205, hash-based). Implementations are appearing in the BoringSSL/OpenSSL family, in Linux distributions' code-signing pipelines, and in hardware tokens. Migration strategies include hybrid certificates (classical ECDSA + ML-DSA, both signatures verified) and gradual rollouts on long-lived signing keys (root CAs, firmware update keys) where quantum resilience matters most.
Como se defender contra ML-DSA (FIPS 204)?
As defesas contra ML-DSA (FIPS 204) costumam combinar controles técnicos e práticas operacionais, conforme detalhado na definição acima.
Quais são outros nomes para ML-DSA (FIPS 204)?
Nomes alternativos comuns: FIPS 204, Dilithium (standardized), Module-Lattice DSA.
● Termos relacionados
- cryptography№ 278
CRYSTALS-Dilithium
Esquema de assinatura digital baseado em reticulados, padronizado pelo NIST como FIPS 204 (ML-DSA) em agosto de 2024 e destinado a substituir, num mundo pós-quântico, as assinaturas RSA, DSA e ECDSA.
- cryptography№ 947
Criptografia pós-quântica
Algoritmos criptográficos clássicos concebidos para se manterem seguros contra ataques de computadores clássicos e computadores quânticos de grande escala.
- cryptography№ 768
ML-KEM (FIPS 203)
NIST's standardized post-quantum key encapsulation mechanism, based on the CRYSTALS-Kyber design and published as FIPS 203 in August 2024 — now the default PQ KEM for TLS, IPsec, and hybrid key exchange.
- cryptography№ 1166
SLH-DSA (FIPS 205)
NIST's standardized stateless hash-based post-quantum signature scheme, derived from SPHINCS+ and published as FIPS 205 in August 2024 — the conservative PQ signature option, relying only on hash-function security.
- cryptography№ 678
Criptografia baseada em reticulados
Família de esquemas criptográficos pós-quânticos cuja segurança se reduz à dificuldade de encontrar vetores curtos ou resolver equações lineares ruidosas sobre reticulados de dimensão elevada.
- cryptography№ 820
Padronização PQC do NIST
Processo plurianual do NIST que seleciona e padroniza algoritmos criptográficos pós-quânticos; as três primeiras normas, FIPS 203, 204 e 205, foram publicadas em agosto de 2024.