{"catalogVersion":"signature-dossier-v3-atomic-contributions","constructions":[{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"factoring","assumption_id":"SIG-ASSUMPTION-RSA-INVERSION","assumption_name":"RSA inversion","authors":["Ronald L. Rivest","Adi Shamir","Leonard M. Adleman"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","message-recovery-encoding"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"rsa","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-1978-RSA","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"none","nonce_requirement":null,"nonce_size":null,"normative_status":"historical foundation; not a secure encoding by itself","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","paper_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"pre-modern heuristic security","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"deterministic algebraic relation","security_notion":"not EUF-CMA as written","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"one private RSA exponentiation","signing_rounds":null,"sizes":{"public_key":"RSA modulus and exponent","secret_key":"RSA trapdoor","signature":"one RSA group element"},"statefulness":"stateless","summary":"This card records the algebraic root. Secure deployed RSA signatures require an encoding such as PSS.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"one public RSA exponentiation","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-1978-RSA","year":1978},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"trapdoor_permutation","assumption_id":"SIG-ASSUMPTION-CLAW-FREE-TRAPDOOR-PERMUTATIONS","assumption_name":"claw-free trapdoor permutations","authors":["Shafi Goldwasser","Silvio Micali","Ronald L. Rivest"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","adaptive-chosen-message-security"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"foundations","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-1988-GMR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"not applicable","nonce_requirement":null,"nonce_size":null,"normative_status":"theoretical foundation","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"A Digital Signature Scheme Secure Against Adaptive Chosen-Message Attacks","paper_url":"https://doi.org/10.1137/0217017","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"standard model","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard","security_notion":"existential unforgeability under adaptive chosen-message attack","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"theoretical polynomial-time signer","signing_rounds":null,"sizes":{"public_key":"asymptotic construction parameters","secret_key":"evolving signer state","signature":"polynomial-size historical construction"},"statefulness":"stateful tree traversal","summary":"The canonical security-definition anchor, rather than a modern deployment profile.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"theoretical polynomial-time verifier","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-1988-GMR","year":1988},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"SIG-ASSUMPTION-DISCRETE-LOGARITHM","assumption_name":"discrete logarithm","authors":["Claus-Peter Schnorr"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","compact-signature","linear-key-relation"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"schnorr","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-1991-SCHNORR","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"fresh secret nonce per signature","nonce_requirement":null,"nonce_size":null,"normative_status":"deployed family","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Efficient Signature Generation by Smart Cards","paper_url":"https://doi.org/10.1007/BF00196725","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"random-oracle lineage","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random oracle in later analyses","security_notion":"EUF-CMA lineage","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"one scalar multiplication plus hashing","signing_rounds":null,"sizes":{"public_key":"one group element","secret_key":"one scalar","signature":"two scalars or equivalent encoding"},"statefulness":"stateless with nonce-safety requirement","summary":"Nonce reuse or bias can reveal the signing key; deterministic and hedged nonce derivation are separate profile choices.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"multi-scalar multiplication plus hashing","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-1991-SCHNORR","year":1991},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"factoring","assumption_id":"SIG-ASSUMPTION-RSA-INVERSION","assumption_name":"RSA inversion","authors":["Mihir Bellare","Phillip Rogaway"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","probabilistic-encoding","standards-profile"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"rsa_pss","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-1996-PSS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"randomized salt","nonce_requirement":null,"nonce_size":null,"normative_status":"standardized in FIPS 186-5","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Optimal Asymmetric Encryption and Signature","paper_url":"https://doi.org/10.1007/3-540-68339-9_34","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"random oracle","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random oracle with RSA-PSS reduction","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"one private RSA operation plus hashing","signing_rounds":null,"sizes":{"public_key":"RSA modulus and exponent","secret_key":"RSA trapdoor","signature":"one RSA modulus element"},"statefulness":"stateless","summary":"PSS is the security-oriented encoding layer missing from textbook RSA.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"one public RSA operation plus hashing","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-1996-PSS","year":1996},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"factoring","assumption_id":"SIG-ASSUMPTION-STRONG-RSA-ASSUMPTION","assumption_name":"strong RSA assumption","authors":["Ronald Cramer","Victor Shoup"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","standard-model-proof"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"strong_rsa","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-1999-CS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"randomized signing","nonce_requirement":null,"nonce_size":null,"normative_status":"research construction","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Signature Schemes Based on the Strong RSA Assumption","paper_url":"https://crypto.ethz.ch/publications/CraSho99.html","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"standard model","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"modular exponentiations and prime generation/search","signing_rounds":null,"sizes":{"public_key":"RSA-group parameters","secret_key":"factorization-derived trapdoor","signature":"constant number of group and integer values"},"statefulness":"stateless","summary":"An important standard-model branch distinct from the random-oracle encodings used by deployed RSA profiles.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"modular exponentiations","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-1999-CS","year":1999},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"pairing","assumption_id":"SIG-ASSUMPTION-COMPUTATIONAL-DIFFIE-HELLMAN-IN-PAIRING-GROUPS","assumption_name":"computational Diffie-Hellman in pairing groups","authors":["Dan Boneh","Ben Lynn","Hovav Shacham"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","short-signature","aggregation-friendly"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"pairing","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2001-BLS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"none beyond hash-to-curve","nonce_requirement":null,"nonce_size":null,"normative_status":"deployed ecosystem profile","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Short Signatures from the Weil Pairing","paper_url":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"random oracle","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random oracle","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"hash-to-curve and one scalar multiplication","signing_rounds":null,"sizes":{"public_key":"one group element","secret_key":"one scalar","signature":"one group element"},"statefulness":"stateless","summary":"This dossier records ordinary BLS signing; multisignature and aggregate protocols remain out of scope unless needed as lineage context.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"pairing equation","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2001-BLS","year":2001},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"pairing","assumption_id":"SIG-ASSUMPTION-Q-STRONG-DIFFIE-HELLMAN","assumption_name":"q-strong Diffie-Hellman","authors":["Dan Boneh","Xavier Boyen"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","short-signature","standard-model-proof"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"pairing","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2004-BB","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"randomized signing in the full construction","nonce_requirement":null,"nonce_size":null,"normative_status":"research construction","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Short Signatures Without Random Oracles","paper_url":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"standard model for the full construction","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"pairing-group exponentiation","signing_rounds":null,"sizes":{"public_key":"pairing-group elements","secret_key":"scalar","signature":"constant-size pairing-group encoding"},"statefulness":"stateless","summary":"This card distinguishes the full standard-model signature from the weak-message variant discussed in the same work.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"pairing equation","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2004-BB","year":2004},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"SIG-ASSUMPTION-SIS-AND-WORST-CASE-LATTICE-PROBLEMS","assumption_name":"SIS and worst-case lattice problems","authors":["Craig Gentry","Chris Peikert","Vinod Vaikuntanathan"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","trapdoor-preimage-sampling","post-quantum"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"lattice_hash_and_sign","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2008-GPV","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"randomized preimage sampling","nonce_requirement":null,"nonce_size":null,"normative_status":"foundational research framework","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Trapdoors for Hard Lattices and New Cryptographic Constructions","paper_url":"https://doi.org/10.1145/1374376.1374407","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"random oracle for signatures","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random oracle","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"discrete Gaussian preimage sampling","signing_rounds":null,"sizes":{"public_key":"lattice matrix","secret_key":"short trapdoor basis","signature":"short lattice preimage"},"statefulness":"stateless","summary":"The hash-and-sign lattice root later optimized by compact trapdoors and fast Fourier sampling.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"matrix-vector relation and norm check","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2008-GPV","year":2008},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"SIG-ASSUMPTION-SIS-FAMILY-LATTICE-ASSUMPTIONS","assumption_name":"SIS-family lattice assumptions","authors":["Vadim Lyubashevsky"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","rejection-sampling","post-quantum"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"lattice_fswa","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2009-LYU","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"short random mask plus rejection sampling","nonce_requirement":null,"nonce_size":null,"normative_status":"foundational research framework","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Fiat-Shamir with Aborts: Applications to Lattice and Factoring-Based Signatures","paper_url":"https://doi.org/10.1007/978-3-642-10366-7_35","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"random oracle","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random oracle","security_notion":"EUF-CMA lineage","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"repeated masking and rejection sampling","signing_rounds":null,"sizes":{"public_key":"lattice relation","secret_key":"short vector","signature":"masked short vector and challenge"},"statefulness":"stateless with fresh signing randomness","summary":"Exact theorem and parameter locators remain queued for a local full-text audit.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"lattice linear relation and norm check","verification_status":"bibliographic_reviewed","work_id":"SIG-PAPER-2009-LYU","year":2009},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"SIG-ASSUMPTION-DISCRETE-LOGARITHM-IN-THE-EDWARDS-CURVE-GROUP","assumption_name":"discrete logarithm in the Edwards-curve group","authors":["Daniel J. Bernstein","Niels Duif","Tanja Lange","Peter Schwabe","Bo-Yin Yang"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","deterministic-signing","high-speed-software"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"eddsa","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2011-ED25519","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"deterministic secret-prefix-and-message hash","nonce_requirement":null,"nonce_size":null,"normative_status":"EdDSA standardized in FIPS 186-5","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"High-Speed High-Security Signatures","paper_url":"https://eprint.iacr.org/2011/368","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"Schnorr-derived design","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"hash-function idealization in analyses","security_notion":"public-key unforgeability lineage","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"fixed-base and variable-base scalar arithmetic plus hashing","signing_rounds":null,"sizes":{"public_key":"32 bytes","secret_key":"32-byte seed in the reference format","signature":"64 bytes"},"statefulness":"stateless","summary":"The size fields describe Ed25519's reference encoding, not every EdDSA parameterization.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"double-scalar multiplication plus hashing","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2011-ED25519","year":2011},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS","assumption_name":"Module-LWE and Module-SIS","authors":["Léo Ducas","Eike Kiltz","Tancrède Lepoint","Vadim Lyubashevsky","Peter Schwabe","Gregor Seiler","Damien Stehlé"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","post-quantum","gaussian-free-design"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"module_lattice_fswa","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2018-DILITHIUM","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"deterministic or randomized seed expansion depending profile","nonce_requirement":null,"nonce_size":null,"normative_status":"design lineage standardized as ML-DSA","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme","paper_url":"https://eprint.iacr.org/2017/633","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"quantum random oracle lineage","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random-oracle lineage","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"polynomial arithmetic with rejection sampling","signing_rounds":null,"sizes":{"public_key":"module-lattice vectors","secret_key":"short module-lattice vectors","signature":"masked vector challenge and hint"},"statefulness":"stateless","summary":"Algorithmic family card; exact FIPS encodings and parameter sets belong to the ML-DSA card.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"polynomial arithmetic and norm checks","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2018-DILITHIUM","year":2018},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"hash","assumption_id":"SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-CRYPTOGRAPHIC-HASH-FUNCTIONS","assumption_name":"security properties of cryptographic hash functions","authors":["Andreas Hülsing","Stefan Kölbl","Daniel J. Bernstein","Ruben Niederhagen","Joost Rijneveld","Peter Schwabe"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","post-quantum","stateless-signing"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"stateless_hash_based","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"randomized or deterministic message randomization by profile","nonce_requirement":null,"nonce_size":null,"normative_status":"design lineage standardized as SLH-DSA","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"The SPHINCS+ Signature Framework","paper_url":"https://eprint.iacr.org/2019/1086","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"hash-based reduction","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"hash-function assumptions","security_notion":"EUF-CMA and stronger multi-target analyses by profile","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"many hash computations","signing_rounds":null,"sizes":{"public_key":"compact hash roots","secret_key":"compact seeds and root","signature":"many hash outputs across FORS and hypertree paths"},"statefulness":"stateless","summary":"The conservative-assumption branch trades comparatively large signatures and hashing work for stateless operation.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"many hash computations","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2019-SPHINCSPLUS","year":2019},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"SIG-ASSUMPTION-NTRU-LATTICE-SIS-LINEAGE","assumption_name":"NTRU-lattice SIS lineage","authors":["Pierre-Alain Fouque","Jeffrey Hoffstein","Paul Kirchner","Vadim Lyubashevsky","Thomas Pornin","Thomas Prest","Thomas Ricosset","Gregor Seiler","William Whyte","Zhenfei Zhang"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","post-quantum","compact-signature"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"ntru_lattice_hash_and_sign","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2020-FALCON","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"randomized hash-to-point and Gaussian preimage sampling","nonce_requirement":null,"nonce_size":null,"normative_status":"selected by NIST; FN-DSA standard in development at cutoff","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Falcon: Fast-Fourier Lattice-Based Compact Signatures over NTRU","paper_url":"https://falcon-sign.info/falcon.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"random oracle lineage","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random-oracle lineage","security_notion":"EUF-CMA","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"fast Fourier Gaussian sampling","signing_rounds":null,"sizes":{"public_key":"compressed NTRU polynomial","secret_key":"compressed NTRU trapdoor","signature":"salt and compressed short vector"},"statefulness":"stateless","summary":"Implementation assurance centers on the correctness and side-channel behavior of the sampler as well as the algebraic core.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"NTRU polynomial arithmetic and norm check","verification_status":"primary_source_reviewed","work_id":"SIG-PAPER-2020-FALCON","year":2020},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS-LINEAGE","assumption_name":"Module-LWE and Module-SIS lineage","authors":["National Institute of Standards and Technology"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","post-quantum","federal-standard"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"module_lattice_fswa","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2024-MLDSA","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"deterministic signing with an optional randomness input in the standard","nonce_requirement":null,"nonce_size":null,"normative_status":"NIST FIPS 204 final","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"FIPS 204: Module-Lattice-Based Digital Signature Standard","paper_url":"https://csrc.nist.gov/pubs/fips/204/final","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"standardized Dilithium-derived profile","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"FIPS 204 specification","security_notion":"standardized digital-signature security profile","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"parameter-set-defined NTT polynomial arithmetic and rejection sampling","signing_rounds":null,"sizes":{"public_key":"parameter-set-defined byte string","secret_key":"parameter-set-defined byte string","signature":"parameter-set-defined byte string"},"statefulness":"stateless","summary":"Use the three named FIPS parameter sets for concrete byte counts; this cross-family card deliberately avoids mixing them.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"parameter-set-defined NTT polynomial arithmetic and checks","verification_status":"standard_reviewed","work_id":"SIG-PAPER-2024-FIPS204","year":2024},{"adaptive_security":null,"api_style":null,"associated_data":null,"assumption_family":"hash","assumption_id":"SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-APPROVED-HASH-FUNCTIONS","assumption_name":"security properties of approved hash functions","authors":["National Institute of Standards and Technology"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-verification","post-quantum","federal-standard","conservative-assumption-profile"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"stateless_hash_based","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SIG-CONSTRUCTION-2024-SLHDSA","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":"deterministic or hedged randomized signing mode","nonce_requirement":null,"nonce_size":null,"normative_status":"NIST FIPS 205 final","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"FIPS 205: Stateless Hash-Based Digital Signature Standard","paper_url":"https://csrc.nist.gov/pubs/fips/205/final","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"digital_signature","privacy_model":null,"proof_model":"standardized SPHINCS+-derived profile","quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"FIPS 205 specification","security_notion":"standardized digital-signature security profile","server_model":null,"server_work":null,"setup_model":null,"signer_model":"single_signer","signing_cost":"parameter-set-defined hash computation","signing_rounds":null,"sizes":{"public_key":"parameter-set-defined byte string","secret_key":"parameter-set-defined byte string","signature":"parameter-set-defined large hash-based byte string"},"statefulness":"stateless","summary":"The SHA2 and SHAKE parameter families expose different speed/size/security tradeoffs and should be compared at parameter-set granularity.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":null,"update_model":null,"verification_cost":"parameter-set-defined hash computation","verification_status":"standard_reviewed","work_id":"SIG-PAPER-2024-FIPS205","year":2024}],"edges":[{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-01C6007217036E","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2008-GPV","target":"SIG-ASSUMPTION-SIS-AND-WORST-CASE-LATTICE-PROBLEMS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-01E1DD8F2F2494","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2011-ED25519","target":"SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-01F59DCB5048CA","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2020-FALCON","target":"SIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-0700D53A41A1E3","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1986-FS","target":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-0C7A7866702008","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-OP-001","target":"SIG-PAPER-2024-FIPS204","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-0E8575A443CC3C","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-1999-CS","target":"SIG-ASSUMPTION-STRONG-RSA-ASSUMPTION","type":"RELIES_ON"},{"evidenceLocator":"Falcon specification, design-rationale and key/sign algorithms","evidenceUrl":"https://falcon-sign.info/falcon.pdf","id":"SIG-REL-0EB3037416B93E","note":"Falcon instantiates the GPV hash-and-sign paradigm over NTRU lattices and uses fast Fourier sampling to obtain compact concrete keys and signatures.","resultId":"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","reviewStatus":"primary_source_checked","source":"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","target":"SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING","type":"ENGINEERS"},{"evidenceLocator":"FIPS 186-5, Introduction and Section 7","evidenceUrl":"https://csrc.nist.gov/pubs/fips/186-5/final","id":"SIG-REL-0F605DF6D41342","note":"FIPS 186-5 approves EdDSA, a deterministic Schnorr-family design, alongside RSA and ECDSA under fixed federal profiles.","resultId":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","target":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES","type":"STANDARDIZES_FAMILY"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-10EB8807FA971E","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2024-FIPS205","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"FIPS 205, Introduction and parameter-set sections","evidenceUrl":"https://csrc.nist.gov/pubs/fips/205/final","id":"SIG-REL-130F62075225F2","note":"FIPS 205 standardizes a SPHINCS+-derived stateless hash-based signature as SLH-DSA with named SHA2 and SHAKE parameter sets.","resultId":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","reviewStatus":"primary_source_checked","source":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","target":"SIG-RESULT-2024-FIPS205-SLH-DSA-STANDARDIZATION","type":"STANDARDIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-166713CEFB2BAE","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2020-FALCON","target":"SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING","type":"HAS_RESULT"},{"evidenceLocator":"Dilithium paper, abstract and Sections 1-3","evidenceUrl":"https://eprint.iacr.org/2017/633","id":"SIG-REL-178AB21E6B42F2","note":"Dilithium develops the Fiat-Shamir-with-aborts lattice line using module lattices, decomposition hints, and a Gaussian-free implementation design.","resultId":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","reviewStatus":"primary_source_checked","source":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","target":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","type":"ENGINEERS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-1926B8CDDA138A","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2020-FALCON","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-1AA7627B6E7B1F","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-OP-001","target":"SIG-PAPER-2020-FALCON","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-1FED2DF1129632","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2009-LYU","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-1FF15F95394347","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1979-LAMPORT","target":"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","type":"HAS_RESULT"},{"evidenceLocator":"SPHINCS+ specification, overview and construction sections","evidenceUrl":"https://eprint.iacr.org/2019/1086","id":"SIG-REL-2309ADD1DB209F","note":"SPHINCS+ combines few-time signatures, WOTS+, and a hypertree to obtain a stateless hash-based signature rather than maintaining a stateful leaf counter.","resultId":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","target":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-268FC48F4DAE5B","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2004-BB","target":"SIG-ASSUMPTION-Q-STRONG-DIFFIE-HELLMAN","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-2721C6E95C703C","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-1999-CS","target":"SIG-PAPER-1999-CS","type":"DESCRIBED_IN"},{"evidenceLocator":"Boneh-Boyen abstract and Section 1","evidenceUrl":"https://www.iacr.org/archive/eurocrypt2004/30270272/bbsigs.pdf","id":"SIG-REL-2B8561643F45C8","note":"Boneh-Boyen gives short pairing signatures with a standard-model proof under q-SDH, in contrast with the BLS CDH/random-oracle point; this changes the assumption and proof-model profile rather than establishing assumption dominance.","resultId":"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","reviewStatus":"primary_source_checked","source":"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","target":"SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES","type":"CHANGES_PROOF_MODEL"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-2D2F311F96CF74","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-ROUTE-001","target":"SIG-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-2DE287BE79EEF2","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2011-ED25519","target":"SIG-ASSUMPTION-DISCRETE-LOGARITHM-IN-THE-EDWARDS-CURVE-GROUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-2DE88AB710E316","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2020-FALCON","target":"SIG-PAPER-2020-FALCON","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-3248CD7E518819","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","target":"SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-CRYPTOGRAPHIC-HASH-FUNCTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-371DA3DC126D26","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2024-MLDSA","target":"SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS-LINEAGE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-3D193AEC9B30F1","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2018-DILITHIUM","target":"SIG-PAPER-2018-DILITHIUM","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-41550B61CFF5FA","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1991-SCHNORR","target":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-417E04C2B77702","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2023-FIPS186-5","target":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-4B77A648E8209A","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1999-CS","target":"SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-51C34655D92A7B","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2004-BB","target":"SIG-RESULT-2004-BB-Q-SDH-EUF-CMA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-54C03B6FAFACEE","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","target":"SIG-PAPER-2019-SPHINCSPLUS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-571DCB136B5E20","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2018-DILITHIUM","target":"SIG-RESULT-2018-DILITHIUM-GAUSSIAN-FREE-CONSTANT-TIME-DESIGN","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-5D558F778E428A","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2001-BLS","target":"SIG-ASSUMPTION-COMPUTATIONAL-DIFFIE-HELLMAN-IN-PAIRING-GROUPS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-5DC3C533D6B493","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2008-GPV","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-63328F9C4AB8BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1988-GMR","target":"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-6400F011115383","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1978-RSA","target":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-64ACF6ECE905AD","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2009-LYU","target":"SIG-ASSUMPTION-SIS-FAMILY-LATTICE-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"Schnorr paper, signature construction section","evidenceUrl":"https://doi.org/10.1007/BF00196725","id":"SIG-REL-6523459031DEB3","note":"Schnorr turns a three-move discrete-log identification protocol into a noninteractive signature by hashing the commitment and message into the challenge.","resultId":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","target":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-66E4CB8E510B9D","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1979-LAMPORT","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-6A6DA8E2DA1416","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-BARRIER-001","target":"SIG-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-6A9C8CFF47A837","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-1978-RSA","target":"SIG-ASSUMPTION-RSA-INVERSION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-6FF04CE3946B4D","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2024-SLHDSA","target":"SIG-PAPER-2024-FIPS205","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-70C8A40E07310F","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-1996-PSS","target":"SIG-ASSUMPTION-RSA-INVERSION","type":"RELIES_ON"},{"evidenceLocator":"FIPS 204, Introduction and algorithm specifications","evidenceUrl":"https://csrc.nist.gov/pubs/fips/204/final","id":"SIG-REL-70C996351EF641","note":"FIPS 204 standardizes the Dilithium-derived module-lattice signature as ML-DSA with fixed algorithms, parameter sets, encodings, and interfaces.","resultId":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","reviewStatus":"primary_source_checked","source":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","target":"SIG-RESULT-2024-FIPS204-ML-DSA-STANDARDIZATION","type":"STANDARDIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-774521D597477B","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-1991-SCHNORR","target":"SIG-ASSUMPTION-DISCRETE-LOGARITHM","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-7B4E3EEB0A460E","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2008-GPV","target":"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-8322C84AF4E88B","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2004-BB","target":"SIG-PAPER-2004-BB","type":"DESCRIBED_IN"},{"evidenceLocator":"Cramer-Shoup abstract and introduction","evidenceUrl":"https://www.iacr.org/archive/crypto1999/16660531/16660531.pdf","id":"SIG-REL-85B7FED10DF861","note":"Cramer-Shoup gives a stateless Strong-RSA signature satisfying adaptive chosen-message unforgeability in the standard model, realizing the security target formalized by GMR.","resultId":"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","target":"SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES","type":"INSTANTIATES_SECURITY_MODEL"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-86F99EF0C5AD46","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-OP-001","target":"SIG-PAPER-2019-SPHINCSPLUS","type":"GROUNDED_IN"},{"evidenceLocator":"FIPS 186-5, Sections 5 and 8","evidenceUrl":"https://csrc.nist.gov/pubs/fips/186-5/final","id":"SIG-REL-8EC71EFCE1014E","note":"FIPS 186-5 retains RSA as an approved signature family only through specified encodings and parameter requirements, not textbook RSA.","resultId":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","target":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES","type":"STANDARDIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-8EDA402422B6A6","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1989-MERKLE","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-93B8834AF5BA23","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-1988-GMR","target":"SIG-ASSUMPTION-CLAW-FREE-TRAPDOOR-PERMUTATIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-9420C7BC06847F","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2019-SPHINCSPLUS","target":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-95904C36143403","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2009-LYU","target":"SIG-PAPER-2009-LYU","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-97A5F095BBC35F","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2024-MLDSA","target":"SIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-9BCB66B2C3C0F8","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2018-DILITHIUM","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-A234102191071C","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2008-GPV","target":"SIG-PAPER-2008-GPV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-A4147D3648A993","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2001-BLS","target":"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-A4A96FD0DD4806","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-ROUTE-002","target":"SIG-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-A527B4951473CD","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2024-FIPS205","target":"SIG-RESULT-2024-FIPS205-SLH-DSA-STANDARDIZATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-A5769D47838F64","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-1978-RSA","target":"SIG-PAPER-1978-RSA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-AAB1DF1C2E91B7","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2009-LYU","target":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-ABAE38E22E799B","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-OP-001","target":"SIG-PAPER-2024-FIPS205","type":"GROUNDED_IN"},{"evidenceLocator":"Ed25519 paper, Sections 2-4","evidenceUrl":"https://eprint.iacr.org/2011/368","id":"SIG-REL-AC1856691811F8","note":"Ed25519 engineers a deterministic Schnorr-family signature over a twisted Edwards curve with fixed encodings and a high-speed software profile.","resultId":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","target":"SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE","type":"ENGINEERS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-B27F32E7D490BC","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2024-SLHDSA","target":"SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-APPROVED-HASH-FUNCTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-B2BA4E100FA9B1","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-1988-GMR","target":"SIG-PAPER-1988-GMR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-C0346E48F54863","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2024-MLDSA","target":"SIG-PAPER-2024-FIPS204","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-C4A8D53688D801","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1989-MERKLE","target":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-C4BC7D551A0BC1","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2020-FALCON","target":"SIG-RESULT-2020-FALCON-COMPACT-LATTICE-SIGNATURES","type":"HAS_RESULT"},{"evidenceLocator":"Merkle thesis/paper discussion of authentication trees","evidenceUrl":"https://www.ralphmerkle.com/papers/Thesis1979.pdf","id":"SIG-REL-CB3EAEF60FF8CA","note":"Merkle authentication trees compose many one-time keys under one compact public root, extending the one-time hash-signature branch toward many signatures.","resultId":"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","reviewStatus":"bibliographic_checked","source":"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","target":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","type":"EXTENDS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-CCF05370F10864","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-OP-001","target":"SIG-PAPER-2018-DILITHIUM","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-D443F1C3ACE0F5","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2018-DILITHIUM","target":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-D77849FC63FBE0","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2001-BLS","target":"SIG-PAPER-2001-BLS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-D7C45D259431BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1996-PSS","target":"SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-DB0881A9C5B43B","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-1991-SCHNORR","target":"SIG-PAPER-1991-SCHNORR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-DBBD5034DAA6C2","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2011-ED25519","target":"SIG-PAPER-2011-ED25519","type":"DESCRIBED_IN"},{"evidenceLocator":"Bellare-Rogaway paper, abstract and Sections 1-4","evidenceUrl":"https://web.cs.ucdavis.edu/~rogaway/papers/exact.pdf","id":"SIG-REL-DF1EDEFE492F35","note":"RSA-PSS applies a randomized structured message encoding before the RSA private signing operation, replacing direct textbook message exponentiation; its security reduction is a separate contribution.","resultId":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","reviewStatus":"primary_source_checked","source":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","target":"SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING","type":"CHANGES_MECHANISM"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-E27CD184CFE553","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2020-FALCON","target":"SIG-ASSUMPTION-NTRU-LATTICE-SIS-LINEAGE","type":"RELIES_ON"},{"evidenceLocator":"Lyubashevsky paper, abstract and signature construction","evidenceUrl":"https://doi.org/10.1007/978-3-642-13190-5_42","id":"SIG-REL-E2C3A4BDAEBAE2","note":"Lyubashevsky's lattice branch adds rejection sampling and aborts so the Fiat-Shamir transcript does not expose the short secret through the response distribution.","resultId":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","reviewStatus":"bibliographic_checked","source":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","target":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","type":"CHANGES_SIGNING_DISTRIBUTION"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-E466C0BF9A5A63","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SIG-CONSTRUCTION-2018-DILITHIUM","target":"SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-E6DA7EA2BC8DB8","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2019-SPHINCSPLUS","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-E7549391328386","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2001-BLS","target":"SIG-RESULT-2001-BLS-CDH-ROM-EUF-CMA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-E79C80FDD717EE","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2024-FIPS204","target":"SIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-EA04431C412FDD","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2008-GPV","target":"SIG-RESULT-2008-GPV-LATTICE-PREIMAGE-SAMPLING-TRAPDOORS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-EBCA837971D48A","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2011-ED25519","target":"SIG-RESULT-2011-ED25519-DETERMINISTIC-NONCE-SIDE-CHANNEL-DISCIPLINE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-EEB8EB48E041C3","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1999-CS","target":"SIG-RESULT-1999-CS-STRONG-RSA-EUF-CMA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-F2996A4B309D51","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2004-BB","target":"SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-F735AEDB604554","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-1996-PSS","target":"SIG-PAPER-1996-PSS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-FA7116C259051A","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-CONSTRUCTION-2024-SLHDSA","target":"SIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-FCB876234AD9C7","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-2024-FIPS204","target":"SIG-RESULT-2024-FIPS204-ML-DSA-STANDARDIZATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SIG-REL-FE761B04C25245","note":"","resultId":null,"reviewStatus":"source_declared","source":"SIG-PAPER-1996-PSS","target":"SIG-RESULT-1996-PSS-TIGHT-ROM-RSA-SIGNATURES","type":"HAS_RESULT"}],"nodes":[{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-CLAW-FREE-TRAPDOOR-PERMUTATIONS","keywords":["trapdoor_permutation"],"metadata":{"family":"trapdoor_permutation","name":"claw-free trapdoor permutations"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"trapdoor_permutation","summary":"Assumption used by one or more Signature construction records: claw-free trapdoor permutations.","title":"claw-free trapdoor permutations","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-CLAW-FREE-TRAPDOOR-PERMUTATIONS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-COMPUTATIONAL-DIFFIE-HELLMAN-IN-PAIRING-GROUPS","keywords":["pairing"],"metadata":{"family":"pairing","name":"computational Diffie-Hellman in pairing groups"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"pairing","summary":"Assumption used by one or more Signature construction records: computational Diffie-Hellman in pairing groups.","title":"computational Diffie-Hellman in pairing groups","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-COMPUTATIONAL-DIFFIE-HELLMAN-IN-PAIRING-GROUPS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-DISCRETE-LOGARITHM","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"discrete logarithm"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Signature construction records: discrete logarithm.","title":"discrete logarithm","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-DISCRETE-LOGARITHM"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-DISCRETE-LOGARITHM-IN-THE-EDWARDS-CURVE-GROUP","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"discrete logarithm in the Edwards-curve group"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Signature construction records: discrete logarithm in the Edwards-curve group.","title":"discrete logarithm in the Edwards-curve group","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-DISCRETE-LOGARITHM-IN-THE-EDWARDS-CURVE-GROUP"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Module-LWE and Module-SIS"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Signature construction records: Module-LWE and Module-SIS.","title":"Module-LWE and Module-SIS","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS-LINEAGE","keywords":["lattice"],"metadata":{"family":"lattice","name":"Module-LWE and Module-SIS lineage"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Signature construction records: Module-LWE and Module-SIS lineage.","title":"Module-LWE and Module-SIS lineage","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS-LINEAGE"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-NTRU-LATTICE-SIS-LINEAGE","keywords":["lattice"],"metadata":{"family":"lattice","name":"NTRU-lattice SIS lineage"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Signature construction records: NTRU-lattice SIS lineage.","title":"NTRU-lattice SIS lineage","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-NTRU-LATTICE-SIS-LINEAGE"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-Q-STRONG-DIFFIE-HELLMAN","keywords":["pairing"],"metadata":{"family":"pairing","name":"q-strong Diffie-Hellman"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"pairing","summary":"Assumption used by one or more Signature construction records: q-strong Diffie-Hellman.","title":"q-strong Diffie-Hellman","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-Q-STRONG-DIFFIE-HELLMAN"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-RSA-INVERSION","keywords":["factoring"],"metadata":{"family":"factoring","name":"RSA inversion"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"factoring","summary":"Assumption used by one or more Signature construction records: RSA inversion.","title":"RSA inversion","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-RSA-INVERSION"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-APPROVED-HASH-FUNCTIONS","keywords":["hash"],"metadata":{"family":"hash","name":"security properties of approved hash functions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"hash","summary":"Assumption used by one or more Signature construction records: security properties of approved hash functions.","title":"security properties of approved hash functions","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-APPROVED-HASH-FUNCTIONS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-CRYPTOGRAPHIC-HASH-FUNCTIONS","keywords":["hash"],"metadata":{"family":"hash","name":"security properties of cryptographic hash functions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"hash","summary":"Assumption used by one or more Signature construction records: security properties of cryptographic hash functions.","title":"security properties of cryptographic hash functions","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-SECURITY-PROPERTIES-OF-CRYPTOGRAPHIC-HASH-FUNCTIONS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-SIS-AND-WORST-CASE-LATTICE-PROBLEMS","keywords":["lattice"],"metadata":{"family":"lattice","name":"SIS and worst-case lattice problems"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Signature construction records: SIS and worst-case lattice problems.","title":"SIS and worst-case lattice problems","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-SIS-AND-WORST-CASE-LATTICE-PROBLEMS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-SIS-FAMILY-LATTICE-ASSUMPTIONS","keywords":["lattice"],"metadata":{"family":"lattice","name":"SIS-family lattice assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Signature construction records: SIS-family lattice assumptions.","title":"SIS-family lattice assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-SIS-FAMILY-LATTICE-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"SIG-ASSUMPTION-STRONG-RSA-ASSUMPTION","keywords":["factoring"],"metadata":{"family":"factoring","name":"strong RSA assumption"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"factoring","summary":"Assumption used by one or more Signature construction records: strong RSA assumption.","title":"strong RSA assumption","type":"assumption","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ASSUMPTION-STRONG-RSA-ASSUMPTION"},{"evidence":"primary_sources_compared","id":"SIG-BARRIER-001","keywords":[],"metadata":{"claim":"The audited ML-DSA, Falcon, and SLH-DSA lineages realize different combinations of these axes; evidence for one family cannot be transferred to another by comparing only nominal security level.","does_not_exclude":["New designs that improve more than one axis","Parameter-set-specific optimizations with a new security analysis","Hybrid profiles that explicitly pay multiple verification or bandwidth costs"],"dossier_type":"barrier","escape_hatches":["new compact hash authentication structures","simpler lattice sampling","new conservative algebraic assumptions","profile-specific co-design"],"evidence":"primary_sources_compared","excludes":["Treating selection or standardization status as proof that all three families have the same implementation and assumption profile","Claiming a cross-family size winner without fixing parameter set, encoding, and security target"],"id":"SIG-BARRIER-001","scope":{"axes":"signature size assumption profile and signing implementation","families":"standardized post-quantum signatures at the cutoff"},"status":"scoped_literature_barrier","targets":["SIG-OP-001"],"title":"Compactness, conservative assumptions, and simple constant-time signing are separate design axes"},"primaryUrl":null,"sections":[{"content":"This is a taxonomy barrier, not a lower bound. It prevents an invalid apples-to-oranges inference while leaving the normalized target open.","heading":"Evidence note"}],"status":"scoped_literature_barrier","subtitle":"","summary":"This is a taxonomy barrier, not a lower bound. It prevents an invalid apples-to-oranges inference while leaving the normalized target open.","title":"Compactness, conservative assumptions, and simple constant-time signing are separate design axes","type":"barrier","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-BARRIER-001"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-1978-RSA","keywords":["digital_signature","rsa","public-verification","message-recovery-encoding"],"metadata":{"assumption":{"family":"factoring","name":"RSA inversion"},"capabilities":["public-verification","message-recovery-encoding"],"construction_family":"rsa","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-1978-RSA","name":"Textbook RSA signature relation","nonce_generation":"none","normative_status":"historical foundation; not a secure encoding by itself","primitive":"digital_signature","proof_model":"pre-modern heuristic security","security":{"mode":"public-key","model":"deterministic algebraic relation","notion":"not EUF-CMA as written"},"signer_model":"single_signer","signing_cost":"one private RSA exponentiation","sizes":{"public_key":"RSA modulus and exponent","secret_key":"RSA trapdoor","signature":"one RSA group element"},"statefulness":"stateless","status":"historical","title":"Textbook RSA signature relation","verification":{"status":"primary_source_reviewed"},"verification_cost":"one public RSA exponentiation","work_id":"SIG-PAPER-1978-RSA","year":1978},"primaryUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","sections":[{"content":"This card records the algebraic root. Secure deployed RSA signatures require an encoding such as PSS.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 1978","summary":"This card records the algebraic root. Secure deployed RSA signatures require an encoding such as PSS.","title":"Textbook RSA signature relation","type":"construction","venue":"Communications of the ACM 21(2)","year":1978,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-1978-RSA"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-1988-GMR","keywords":["digital_signature","foundations","public-verification","adaptive-chosen-message-security"],"metadata":{"assumption":{"family":"trapdoor_permutation","name":"claw-free trapdoor permutations"},"capabilities":["public-verification","adaptive-chosen-message-security"],"construction_family":"foundations","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-1988-GMR","name":"GMR provably secure signature","nonce_generation":"not applicable","normative_status":"theoretical foundation","primitive":"digital_signature","proof_model":"standard model","security":{"mode":"public-key","model":"standard","notion":"existential unforgeability under adaptive chosen-message attack"},"signer_model":"single_signer","signing_cost":"theoretical polynomial-time signer","sizes":{"public_key":"asymptotic construction parameters","secret_key":"evolving signer state","signature":"polynomial-size historical construction"},"statefulness":"stateful tree traversal","status":"theoretical","title":"GMR provably secure signature","verification":{"status":"primary_source_reviewed"},"verification_cost":"theoretical polynomial-time verifier","work_id":"SIG-PAPER-1988-GMR","year":1988},"primaryUrl":"https://doi.org/10.1137/0217017","sections":[{"content":"The canonical security-definition anchor, rather than a modern deployment profile.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 1988","summary":"The canonical security-definition anchor, rather than a modern deployment profile.","title":"GMR provably secure signature","type":"construction","venue":"SIAM Journal on Computing 17(2)","year":1988,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-1988-GMR"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-1991-SCHNORR","keywords":["digital_signature","schnorr","public-verification","compact-signature","linear-key-relation"],"metadata":{"assumption":{"family":"discrete_log","name":"discrete logarithm"},"capabilities":["public-verification","compact-signature","linear-key-relation"],"construction_family":"schnorr","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-1991-SCHNORR","name":"Schnorr signature","nonce_generation":"fresh secret nonce per signature","normative_status":"deployed family","primitive":"digital_signature","proof_model":"random-oracle lineage","security":{"mode":"public-key","model":"random oracle in later analyses","notion":"EUF-CMA lineage"},"signer_model":"single_signer","signing_cost":"one scalar multiplication plus hashing","sizes":{"public_key":"one group element","secret_key":"one scalar","signature":"two scalars or equivalent encoding"},"statefulness":"stateless with nonce-safety requirement","status":"active_family","title":"Schnorr signature","verification":{"status":"primary_source_reviewed"},"verification_cost":"multi-scalar multiplication plus hashing","work_id":"SIG-PAPER-1991-SCHNORR","year":1991},"primaryUrl":"https://doi.org/10.1007/BF00196725","sections":[{"content":"Nonce reuse or bias can reveal the signing key; deterministic and hedged nonce derivation are separate profile choices.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 1991","summary":"Nonce reuse or bias can reveal the signing key; deterministic and hedged nonce derivation are separate profile choices.","title":"Schnorr signature","type":"construction","venue":"Journal of Cryptology 4(3)","year":1991,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-1991-SCHNORR"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-1996-PSS","keywords":["digital_signature","rsa_pss","public-verification","probabilistic-encoding","standards-profile"],"metadata":{"assumption":{"family":"factoring","name":"RSA inversion"},"capabilities":["public-verification","probabilistic-encoding","standards-profile"],"construction_family":"rsa_pss","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-1996-PSS","name":"RSA Probabilistic Signature Scheme","nonce_generation":"randomized salt","normative_status":"standardized in FIPS 186-5","primitive":"digital_signature","proof_model":"random oracle","security":{"mode":"public-key","model":"random oracle with RSA-PSS reduction","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"one private RSA operation plus hashing","sizes":{"public_key":"RSA modulus and exponent","secret_key":"RSA trapdoor","signature":"one RSA modulus element"},"statefulness":"stateless","status":"standardized","title":"RSA-PSS","verification":{"status":"primary_source_reviewed"},"verification_cost":"one public RSA operation plus hashing","work_id":"SIG-PAPER-1996-PSS","year":1996},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_34","sections":[{"content":"PSS is the security-oriented encoding layer missing from textbook RSA.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 1996","summary":"PSS is the security-oriented encoding layer missing from textbook RSA.","title":"RSA Probabilistic Signature Scheme","type":"construction","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-1996-PSS"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-1999-CS","keywords":["digital_signature","strong_rsa","public-verification","standard-model-proof"],"metadata":{"assumption":{"family":"factoring","name":"strong RSA assumption"},"capabilities":["public-verification","standard-model-proof"],"construction_family":"strong_rsa","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-1999-CS","name":"Cramer-Shoup signature","nonce_generation":"randomized signing","normative_status":"research construction","primitive":"digital_signature","proof_model":"standard model","security":{"mode":"public-key","model":"standard","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"modular exponentiations and prime generation/search","sizes":{"public_key":"RSA-group parameters","secret_key":"factorization-derived trapdoor","signature":"constant number of group and integer values"},"statefulness":"stateless","status":"research","title":"Cramer-Shoup signature","verification":{"status":"primary_source_reviewed"},"verification_cost":"modular exponentiations","work_id":"SIG-PAPER-1999-CS","year":1999},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho99.html","sections":[{"content":"An important standard-model branch distinct from the random-oracle encodings used by deployed RSA profiles.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 1999","summary":"An important standard-model branch distinct from the random-oracle encodings used by deployed RSA profiles.","title":"Cramer-Shoup signature","type":"construction","venue":"ACM CCS 1999","year":1999,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-1999-CS"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2001-BLS","keywords":["digital_signature","pairing","public-verification","short-signature","aggregation-friendly"],"metadata":{"assumption":{"family":"pairing","name":"computational Diffie-Hellman in pairing groups"},"capabilities":["public-verification","short-signature","aggregation-friendly"],"construction_family":"pairing","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2001-BLS","name":"Boneh-Lynn-Shacham signature","nonce_generation":"none beyond hash-to-curve","normative_status":"deployed ecosystem profile","primitive":"digital_signature","proof_model":"random oracle","security":{"mode":"public-key","model":"random oracle","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"hash-to-curve and one scalar multiplication","sizes":{"public_key":"one group element","secret_key":"one scalar","signature":"one group element"},"statefulness":"stateless","status":"active_family","title":"BLS short signature","verification":{"status":"primary_source_reviewed"},"verification_cost":"pairing equation","work_id":"SIG-PAPER-2001-BLS","year":2001},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","sections":[{"content":"This dossier records ordinary BLS signing; multisignature and aggregate protocols remain out of scope unless needed as lineage context.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2001","summary":"This dossier records ordinary BLS signing; multisignature and aggregate protocols remain out of scope unless needed as lineage context.","title":"Boneh-Lynn-Shacham signature","type":"construction","venue":"ASIACRYPT 2001","year":2001,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2001-BLS"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2004-BB","keywords":["digital_signature","pairing","public-verification","short-signature","standard-model-proof"],"metadata":{"assumption":{"family":"pairing","name":"q-strong Diffie-Hellman"},"capabilities":["public-verification","short-signature","standard-model-proof"],"construction_family":"pairing","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2004-BB","name":"Boneh-Boyen short signature","nonce_generation":"randomized signing in the full construction","normative_status":"research construction","primitive":"digital_signature","proof_model":"standard model for the full construction","security":{"mode":"public-key","model":"standard","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"pairing-group exponentiation","sizes":{"public_key":"pairing-group elements","secret_key":"scalar","signature":"constant-size pairing-group encoding"},"statefulness":"stateless","status":"research","title":"Boneh-Boyen short signature","verification":{"status":"primary_source_reviewed"},"verification_cost":"pairing equation","work_id":"SIG-PAPER-2004-BB","year":2004},"primaryUrl":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","sections":[{"content":"This card distinguishes the full standard-model signature from the weak-message variant discussed in the same work.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2004","summary":"This card distinguishes the full standard-model signature from the weak-message variant discussed in the same work.","title":"Boneh-Boyen short signature","type":"construction","venue":"EUROCRYPT 2004","year":2004,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2004-BB"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2008-GPV","keywords":["digital_signature","lattice_hash_and_sign","public-verification","trapdoor-preimage-sampling","post-quantum"],"metadata":{"assumption":{"family":"lattice","name":"SIS and worst-case lattice problems"},"capabilities":["public-verification","trapdoor-preimage-sampling","post-quantum"],"construction_family":"lattice_hash_and_sign","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2008-GPV","name":"GPV lattice signature framework","nonce_generation":"randomized preimage sampling","normative_status":"foundational research framework","primitive":"digital_signature","proof_model":"random oracle for signatures","security":{"mode":"public-key","model":"random oracle","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"discrete Gaussian preimage sampling","sizes":{"public_key":"lattice matrix","secret_key":"short trapdoor basis","signature":"short lattice preimage"},"statefulness":"stateless","status":"foundational","title":"GPV hash-and-sign lattice signature","verification":{"status":"primary_source_reviewed"},"verification_cost":"matrix-vector relation and norm check","work_id":"SIG-PAPER-2008-GPV","year":2008},"primaryUrl":"https://doi.org/10.1145/1374376.1374407","sections":[{"content":"The hash-and-sign lattice root later optimized by compact trapdoors and fast Fourier sampling.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2008","summary":"The hash-and-sign lattice root later optimized by compact trapdoors and fast Fourier sampling.","title":"GPV lattice signature framework","type":"construction","venue":"STOC 2008","year":2008,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2008-GPV"},{"evidence":"bibliographic_reviewed","id":"SIG-CONSTRUCTION-2009-LYU","keywords":["digital_signature","lattice_fswa","public-verification","rejection-sampling","post-quantum"],"metadata":{"assumption":{"family":"lattice","name":"SIS-family lattice assumptions"},"capabilities":["public-verification","rejection-sampling","post-quantum"],"construction_family":"lattice_fswa","dossier_type":"construction","evidence":"bibliographic_checked","id":"SIG-CONSTRUCTION-2009-LYU","name":"Lyubashevsky lattice signature with rejection sampling","nonce_generation":"short random mask plus rejection sampling","normative_status":"foundational research framework","primitive":"digital_signature","proof_model":"random oracle","security":{"mode":"public-key","model":"random oracle","notion":"EUF-CMA lineage"},"signer_model":"single_signer","signing_cost":"repeated masking and rejection sampling","sizes":{"public_key":"lattice relation","secret_key":"short vector","signature":"masked short vector and challenge"},"statefulness":"stateless with fresh signing randomness","status":"foundational","title":"Lyubashevsky Fiat-Shamir-with-aborts signature","verification":{"status":"bibliographic_reviewed"},"verification_cost":"lattice linear relation and norm check","work_id":"SIG-PAPER-2009-LYU","year":2009},"primaryUrl":"https://doi.org/10.1007/978-3-642-10366-7_35","sections":[],"status":"bibliographic_reviewed","subtitle":"digital_signature · 2009","summary":"Exact theorem and parameter locators remain queued for a local full-text audit.","title":"Lyubashevsky lattice signature with rejection sampling","type":"construction","venue":"ASIACRYPT 2009","year":2009,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2009-LYU"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2011-ED25519","keywords":["digital_signature","eddsa","public-verification","deterministic-signing","high-speed-software"],"metadata":{"assumption":{"family":"discrete_log","name":"discrete logarithm in the Edwards-curve group"},"capabilities":["public-verification","deterministic-signing","high-speed-software"],"construction_family":"eddsa","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2011-ED25519","name":"Ed25519 deterministic Edwards-curve signature","nonce_generation":"deterministic secret-prefix-and-message hash","normative_status":"EdDSA standardized in FIPS 186-5","primitive":"digital_signature","proof_model":"Schnorr-derived design","security":{"mode":"public-key","model":"hash-function idealization in analyses","notion":"public-key unforgeability lineage"},"signer_model":"single_signer","signing_cost":"fixed-base and variable-base scalar arithmetic plus hashing","sizes":{"public_key":"32 bytes","secret_key":"32-byte seed in the reference format","signature":"64 bytes"},"statefulness":"stateless","status":"standardized","title":"Ed25519","verification":{"status":"primary_source_reviewed"},"verification_cost":"double-scalar multiplication plus hashing","work_id":"SIG-PAPER-2011-ED25519","year":2011},"primaryUrl":"https://eprint.iacr.org/2011/368","sections":[{"content":"The size fields describe Ed25519's reference encoding, not every EdDSA parameterization.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2011","summary":"The size fields describe Ed25519's reference encoding, not every EdDSA parameterization.","title":"Ed25519 deterministic Edwards-curve signature","type":"construction","venue":"CHES 2011","year":2011,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2011-ED25519"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2018-DILITHIUM","keywords":["digital_signature","module_lattice_fswa","public-verification","post-quantum","gaussian-free-design"],"metadata":{"assumption":{"family":"lattice","name":"Module-LWE and Module-SIS"},"capabilities":["public-verification","post-quantum","gaussian-free-design"],"construction_family":"module_lattice_fswa","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2018-DILITHIUM","name":"CRYSTALS-Dilithium","nonce_generation":"deterministic or randomized seed expansion depending profile","normative_status":"design lineage standardized as ML-DSA","primitive":"digital_signature","proof_model":"quantum random oracle lineage","security":{"mode":"public-key","model":"random-oracle lineage","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"polynomial arithmetic with rejection sampling","sizes":{"public_key":"module-lattice vectors","secret_key":"short module-lattice vectors","signature":"masked vector challenge and hint"},"statefulness":"stateless","status":"standardized_lineage","title":"CRYSTALS-Dilithium","verification":{"status":"primary_source_reviewed"},"verification_cost":"polynomial arithmetic and norm checks","work_id":"SIG-PAPER-2018-DILITHIUM","year":2018},"primaryUrl":"https://eprint.iacr.org/2017/633","sections":[{"content":"Algorithmic family card; exact FIPS encodings and parameter sets belong to the ML-DSA card.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2018","summary":"Algorithmic family card; exact FIPS encodings and parameter sets belong to the ML-DSA card.","title":"CRYSTALS-Dilithium","type":"construction","venue":"IACR TCHES 2018(1)","year":2018,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2018-DILITHIUM"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","keywords":["digital_signature","stateless_hash_based","public-verification","post-quantum","stateless-signing"],"metadata":{"assumption":{"family":"hash","name":"security properties of cryptographic hash functions"},"capabilities":["public-verification","post-quantum","stateless-signing"],"construction_family":"stateless_hash_based","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","name":"SPHINCS+ stateless hash-based signature","nonce_generation":"randomized or deterministic message randomization by profile","normative_status":"design lineage standardized as SLH-DSA","primitive":"digital_signature","proof_model":"hash-based reduction","security":{"mode":"public-key","model":"hash-function assumptions","notion":"EUF-CMA and stronger multi-target analyses by profile"},"signer_model":"single_signer","signing_cost":"many hash computations","sizes":{"public_key":"compact hash roots","secret_key":"compact seeds and root","signature":"many hash outputs across FORS and hypertree paths"},"statefulness":"stateless","status":"standardized_lineage","title":"SPHINCS+","verification":{"status":"primary_source_reviewed"},"verification_cost":"many hash computations","work_id":"SIG-PAPER-2019-SPHINCSPLUS","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/1086","sections":[{"content":"The conservative-assumption branch trades comparatively large signatures and hashing work for stateless operation.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2019","summary":"The conservative-assumption branch trades comparatively large signatures and hashing work for stateless operation.","title":"SPHINCS+ stateless hash-based signature","type":"construction","venue":"ACM CCS 2019","year":2019,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2019-SPHINCSPLUS"},{"evidence":"primary_source_reviewed","id":"SIG-CONSTRUCTION-2020-FALCON","keywords":["digital_signature","ntru_lattice_hash_and_sign","public-verification","post-quantum","compact-signature"],"metadata":{"assumption":{"family":"lattice","name":"NTRU-lattice SIS lineage"},"capabilities":["public-verification","post-quantum","compact-signature"],"construction_family":"ntru_lattice_hash_and_sign","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2020-FALCON","name":"Falcon fast-Fourier lattice signature","nonce_generation":"randomized hash-to-point and Gaussian preimage sampling","normative_status":"selected by NIST; FN-DSA standard in development at cutoff","primitive":"digital_signature","proof_model":"random oracle lineage","security":{"mode":"public-key","model":"random-oracle lineage","notion":"EUF-CMA"},"signer_model":"single_signer","signing_cost":"fast Fourier Gaussian sampling","sizes":{"public_key":"compressed NTRU polynomial","secret_key":"compressed NTRU trapdoor","signature":"salt and compressed short vector"},"statefulness":"stateless","status":"selected_pending_final_standard","title":"Falcon","verification":{"status":"primary_source_reviewed"},"verification_cost":"NTRU polynomial arithmetic and norm check","work_id":"SIG-PAPER-2020-FALCON","year":2020},"primaryUrl":"https://falcon-sign.info/falcon.pdf","sections":[{"content":"Implementation assurance centers on the correctness and side-channel behavior of the sampler as well as the algebraic core.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"digital_signature · 2020","summary":"Implementation assurance centers on the correctness and side-channel behavior of the sampler as well as the algebraic core.","title":"Falcon fast-Fourier lattice signature","type":"construction","venue":"NIST PQC supporting documentation","year":2020,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2020-FALCON"},{"evidence":"standard_reviewed","id":"SIG-CONSTRUCTION-2024-MLDSA","keywords":["digital_signature","module_lattice_fswa","public-verification","post-quantum","federal-standard"],"metadata":{"assumption":{"family":"lattice","name":"Module-LWE and Module-SIS lineage"},"capabilities":["public-verification","post-quantum","federal-standard"],"construction_family":"module_lattice_fswa","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2024-MLDSA","name":"Module-Lattice-Based Digital Signature Standard","nonce_generation":"deterministic signing with an optional randomness input in the standard","normative_status":"NIST FIPS 204 final","primitive":"digital_signature","proof_model":"standardized Dilithium-derived profile","security":{"mode":"public-key","model":"FIPS 204 specification","notion":"standardized digital-signature security profile"},"signer_model":"single_signer","signing_cost":"parameter-set-defined NTT polynomial arithmetic and rejection sampling","sizes":{"public_key":"parameter-set-defined byte string","secret_key":"parameter-set-defined byte string","signature":"parameter-set-defined byte string"},"statefulness":"stateless","status":"standardized","title":"ML-DSA","verification":{"status":"standard_reviewed"},"verification_cost":"parameter-set-defined NTT polynomial arithmetic and checks","work_id":"SIG-PAPER-2024-FIPS204","year":2024},"primaryUrl":"https://csrc.nist.gov/pubs/fips/204/final","sections":[{"content":"Use the three named FIPS parameter sets for concrete byte counts; this cross-family card deliberately avoids mixing them.","heading":"Construction note"}],"status":"standard_reviewed","subtitle":"digital_signature · 2024","summary":"Use the three named FIPS parameter sets for concrete byte counts; this cross-family card deliberately avoids mixing them.","title":"Module-Lattice-Based Digital Signature Standard","type":"construction","venue":"FIPS 204","year":2024,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2024-MLDSA"},{"evidence":"standard_reviewed","id":"SIG-CONSTRUCTION-2024-SLHDSA","keywords":["digital_signature","stateless_hash_based","public-verification","post-quantum","federal-standard","conservative-assumption-profile"],"metadata":{"assumption":{"family":"hash","name":"security properties of approved hash functions"},"capabilities":["public-verification","post-quantum","federal-standard","conservative-assumption-profile"],"construction_family":"stateless_hash_based","dossier_type":"construction","evidence":"primary_source_checked","id":"SIG-CONSTRUCTION-2024-SLHDSA","name":"Stateless Hash-Based Digital Signature Standard","nonce_generation":"deterministic or hedged randomized signing mode","normative_status":"NIST FIPS 205 final","primitive":"digital_signature","proof_model":"standardized SPHINCS+-derived profile","security":{"mode":"public-key","model":"FIPS 205 specification","notion":"standardized digital-signature security profile"},"signer_model":"single_signer","signing_cost":"parameter-set-defined hash computation","sizes":{"public_key":"parameter-set-defined byte string","secret_key":"parameter-set-defined byte string","signature":"parameter-set-defined large hash-based byte string"},"statefulness":"stateless","status":"standardized","title":"SLH-DSA","verification":{"status":"standard_reviewed"},"verification_cost":"parameter-set-defined hash computation","work_id":"SIG-PAPER-2024-FIPS205","year":2024},"primaryUrl":"https://csrc.nist.gov/pubs/fips/205/final","sections":[{"content":"The SHA2 and SHAKE parameter families expose different speed/size/security tradeoffs and should be compared at parameter-set granularity.","heading":"Construction note"}],"status":"standard_reviewed","subtitle":"digital_signature · 2024","summary":"The SHA2 and SHAKE parameter families expose different speed/size/security tradeoffs and should be compared at parameter-set granularity.","title":"Stateless Hash-Based Digital Signature Standard","type":"construction","venue":"FIPS 205","year":2024,"sourcePath":"data/signature-catalog.json#SIG-CONSTRUCTION-2024-SLHDSA"},{"evidence":"normalized_from_literature","id":"SIG-OP-001","keywords":[],"metadata":{"acceptance":{"evidence":"interoperable test vectors and two independent implementations","implementation":"constant-time portable reference plus side-channel review","security":"complete reduction and concrete parameter analysis"},"barriers":["SIG-BARRIER-001"],"closest_results":["SIG-CONSTRUCTION-2024-MLDSA","SIG-CONSTRUCTION-2020-FALCON","SIG-CONSTRUCTION-2024-SLHDSA"],"dossier_type":"open_problem","evidence":"normalized_from_literature","hierarchy_links":[],"hierarchy_role":"cross_family_design_endpoint","id":"SIG-OP-001","normalization_delta":"Normalizes the still-separated advantages of ML-DSA's simple arithmetic, Falcon's compact encodings, and SLH-DSA's conservative hash-based assumptions; no source claims this exact conjunction.","origin_evidence":["SIG-PAPER-2018-DILITHIUM","SIG-PAPER-2019-SPHINCSPLUS","SIG-PAPER-2020-FALCON","SIG-PAPER-2024-FIPS204","SIG-PAPER-2024-FIPS205"],"origin_type":"normalized_lineage_gap","profile":{"assumptions":"SLH-DSA-like conservative foundation","assurance":"ML-DSA-like implementation simplicity","compactness":"Falcon-like signature and public-key footprint"},"provenance":["SIG-PAPER-2018-DILITHIUM","SIG-PAPER-2019-SPHINCSPLUS","SIG-PAPER-2020-FALCON","SIG-PAPER-2024-FIPS204","SIG-PAPER-2024-FIPS205"],"resolution_condition":"A publicly specified and independently audited construction meets the declared security, size, implementation, state, and interoperability profile in one parameter set, with no unreported setup or signer state.","routes":["SIG-ROUTE-001","SIG-ROUTE-002"],"status":"open","target_profile":{"implementation":"constant-time reference implementation without delicate floating-point or Gaussian-sampling obligations","security":"post-quantum EUF-CMA under a clearly delimited conservative assumption set","signature_size":"competitive with the compact lattice branch","standardization":"complete interoperable specification and test vectors","state":"stateless signing"},"title":"Compact and implementation-simple post-quantum signatures under conservative assumptions"},"primaryUrl":null,"sections":[{"content":"Construct and independently audit a stateless post-quantum signature that simultaneously offers compact encodings, conservative assumptions, a simple constant-time implementation path, and a complete interoperable standard profile.","heading":"Exact normalized target"},{"content":"The audited standardized families intentionally occupy different tradeoff points. The target is useful as a comparison endpoint even if future evidence shows that one part of the conjunction must be relaxed.","heading":"Why the conjunction matters"}],"status":"open","subtitle":"","summary":"Construct and independently audit a stateless post-quantum signature that simultaneously offers compact encodings, conservative assumptions, a simple constant-time implementation path, and a complete interoperable standard profile.","title":"Compact and implementation-simple post-quantum signatures under conservative assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-OP-001"},{"evidence":"primary_source_checked","id":"SIG-PAPER-1978-RSA","keywords":["foundations","rsa","factoring","trapdoor-permutation"],"metadata":{"authors":["Ronald L. Rivest","Adi Shamir","Leonard M. Adleman"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-1978-RSA","keywords":["foundations","rsa","factoring","trapdoor-permutation"],"maps_to":[],"primary_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","status":"published","title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","venue":"Communications of the ACM 21(2)","versions":["CACM article"],"year":1978},"primaryUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","sections":[{"content":"The private RSA transformation can sign and the public transformation can verify. The card does not attribute modern EUF-CMA security to textbook RSA.","heading":"Atomic claims"},{"content":"Abstract and the signature discussion in the author-hosted CACM paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Ronald L. Rivest, Adi Shamir, Leonard M. Adleman · 1978","summary":"The private RSA transformation can sign and the public transformation can verify. The card does not attribute modern EUF-CMA security to textbook RSA.","title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","type":"paper","venue":"Communications of the ACM 21(2)","year":1978,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1978-RSA"},{"evidence":"bibliographic_checked","id":"SIG-PAPER-1979-LAMPORT","keywords":["foundations","hash-based","one-time","post-quantum"],"metadata":{"authors":["Leslie Lamport"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"SIG-PAPER-1979-LAMPORT","keywords":["foundations","hash-based","one-time","post-quantum"],"maps_to":["SIG-OP-001"],"primary_url":"https://lamport.azurewebsites.net/pubs/dig-sig.pdf","status":"published","title":"Constructing Digital Signatures from a One Way Function","venue":"SRI technical report CSL-98","versions":["technical report"],"year":1979},"primaryUrl":"https://lamport.azurewebsites.net/pubs/dig-sig.pdf","sections":[{"content":"Introduces a one-time signature from one-way functions, the conservative root of the hash-based post-quantum line.","heading":"Atomic claims"}],"status":"published","subtitle":"Leslie Lamport · 1979","summary":"Introduces a one-time signature from one-way functions, the conservative root of the hash-based post-quantum line.","title":"Constructing Digital Signatures from a One Way Function","type":"paper","venue":"SRI technical report CSL-98","year":1979,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1979-LAMPORT"},{"evidence":"primary_source_checked","id":"SIG-PAPER-1986-FS","keywords":["foundations","fiat-shamir","identification","random-oracle"],"metadata":{"authors":["Amos Fiat","Adi Shamir"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-1986-FS","keywords":["foundations","fiat-shamir","identification","random-oracle"],"maps_to":[],"primary_url":"https://doi.org/10.1007/3-540-47721-7_12","status":"published","title":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","venue":"CRYPTO 1986","versions":["conference paper"],"year":1986},"primaryUrl":"https://doi.org/10.1007/3-540-47721-7_12","sections":[{"content":"Turns public-coin identification transcripts into non-interactive signatures by deriving the verifier challenge from a hash.","heading":"Atomic claims"},{"content":"The later random-oracle formalization and QROM analyses are not silently attributed to the 1986 paper.","heading":"Scope"}],"status":"published","subtitle":"Amos Fiat, Adi Shamir · 1986","summary":"Turns public-coin identification transcripts into non-interactive signatures by deriving the verifier challenge from a hash.","title":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","type":"paper","venue":"CRYPTO 1986","year":1986,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1986-FS"},{"evidence":"primary_source_checked","id":"SIG-PAPER-1988-GMR","keywords":["foundations","euf-cma","factoring","claw-free-permutations"],"metadata":{"authors":["Shafi Goldwasser","Silvio Micali","Ronald L. Rivest"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-1988-GMR","keywords":["foundations","euf-cma","factoring","claw-free-permutations"],"maps_to":[],"primary_url":"https://doi.org/10.1137/0217017","status":"published","title":"A Digital Signature Scheme Secure Against Adaptive Chosen-Message Attacks","venue":"SIAM Journal on Computing 17(2)","versions":["journal article"],"year":1988},"primaryUrl":"https://doi.org/10.1137/0217017","sections":[{"content":"Defines adaptive chosen-message unforgeability and gives a claw-free-permutation construction meeting it, with factoring as an instantiation.","heading":"Atomic claims"},{"content":"Journal abstract and paper security experiment.","heading":"Evidence locator"}],"status":"published","subtitle":"Shafi Goldwasser, Silvio Micali, Ronald L. Rivest · 1988","summary":"Defines adaptive chosen-message unforgeability and gives a claw-free-permutation construction meeting it, with factoring as an instantiation.","title":"A Digital Signature Scheme Secure Against Adaptive Chosen-Message Attacks","type":"paper","venue":"SIAM Journal on Computing 17(2)","year":1988,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1988-GMR"},{"evidence":"bibliographic_checked","id":"SIG-PAPER-1989-MERKLE","keywords":["hash-based","stateful","merkle-tree","post-quantum"],"metadata":{"authors":["Ralph C. Merkle"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"SIG-PAPER-1989-MERKLE","keywords":["hash-based","stateful","merkle-tree","post-quantum"],"maps_to":["SIG-OP-001"],"primary_url":"https://doi.org/10.1007/0-387-34805-0_21","status":"published","title":"A Certified Digital Signature","venue":"CRYPTO 1989","versions":["conference paper"],"year":1989},"primaryUrl":"https://doi.org/10.1007/0-387-34805-0_21","sections":[{"content":"Authenticates many one-time verification keys beneath one public root, turning one-time hash signatures into a bounded many-signature system with state.","heading":"Atomic claims"}],"status":"published","subtitle":"Ralph C. Merkle · 1989","summary":"Authenticates many one-time verification keys beneath one public root, turning one-time hash signatures into a bounded many-signature system with state.","title":"A Certified Digital Signature","type":"paper","venue":"CRYPTO 1989","year":1989,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1989-MERKLE"},{"evidence":"primary_source_checked","id":"SIG-PAPER-1991-SCHNORR","keywords":["schnorr","discrete-log","fiat-shamir","deterministic-compatible"],"metadata":{"authors":["Claus-Peter Schnorr"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-1991-SCHNORR","keywords":["schnorr","discrete-log","fiat-shamir","deterministic-compatible"],"maps_to":[],"primary_url":"https://doi.org/10.1007/BF00196725","status":"published","title":"Efficient Signature Generation by Smart Cards","venue":"Journal of Cryptology 4(3)","versions":["journal article"],"year":1991},"primaryUrl":"https://doi.org/10.1007/BF00196725","sections":[{"content":"Presents a compact discrete-log signature whose expensive commitment computation can be performed before the message is known.","heading":"Atomic claims"},{"content":"Abstract and Section 1 of the author-hosted paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Claus-Peter Schnorr · 1991","summary":"Presents a compact discrete-log signature whose expensive commitment computation can be performed before the message is known.","title":"Efficient Signature Generation by Smart Cards","type":"paper","venue":"Journal of Cryptology 4(3)","year":1991,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1991-SCHNORR"},{"evidence":"bibliographic_checked","id":"SIG-PAPER-1996-PSS","keywords":["rsa","pss","random-oracle","probabilistic-encoding"],"metadata":{"authors":["Mihir Bellare","Phillip Rogaway"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"SIG-PAPER-1996-PSS","keywords":["rsa","pss","random-oracle","probabilistic-encoding"],"maps_to":[],"primary_url":"https://doi.org/10.1007/3-540-68339-9_34","status":"published","title":"Optimal Asymmetric Encryption and Signature","venue":"EUROCRYPT 1996","versions":["conference paper"],"year":1996},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_34","sections":[{"content":"Introduces the PSS randomized encoding and a reduction-oriented RSA signature profile in the random-oracle model.","heading":"Atomic claims"}],"status":"published","subtitle":"Mihir Bellare, Phillip Rogaway · 1996","summary":"Introduces the PSS randomized encoding and a reduction-oriented RSA signature profile in the random-oracle model.","title":"Optimal Asymmetric Encryption and Signature","type":"paper","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1996-PSS"},{"evidence":"primary_source_checked","id":"SIG-PAPER-1999-CS","keywords":["rsa","strong-rsa","standard-model","euf-cma"],"metadata":{"authors":["Ronald Cramer","Victor Shoup"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-1999-CS","keywords":["rsa","strong-rsa","standard-model","euf-cma"],"maps_to":[],"primary_url":"https://crypto.ethz.ch/publications/CraSho99.html","status":"published","title":"Signature Schemes Based on the Strong RSA Assumption","venue":"ACM CCS 1999","versions":["CCS extended abstract","ACM TISSEC 2000 journal version"],"year":1999},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho99.html","sections":[{"content":"Gives an efficient stateless signature proven secure against adaptive chosen-message attacks in the standard model under Strong RSA.","heading":"Atomic claims"},{"content":"Author publication page abstract and journal-version introduction.","heading":"Evidence locator"}],"status":"published","subtitle":"Ronald Cramer, Victor Shoup · 1999","summary":"Gives an efficient stateless signature proven secure against adaptive chosen-message attacks in the standard model under Strong RSA.","title":"Signature Schemes Based on the Strong RSA Assumption","type":"paper","venue":"ACM CCS 1999","year":1999,"sourcePath":"data/signature-catalog.json#SIG-PAPER-1999-CS"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2001-BLS","keywords":["pairing","bls","cdh","random-oracle","short-signature"],"metadata":{"authors":["Dan Boneh","Ben Lynn","Hovav Shacham"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2001-BLS","keywords":["pairing","bls","cdh","random-oracle","short-signature"],"maps_to":[],"primary_url":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","status":"published","title":"Short Signatures from the Weil Pairing","venue":"ASIACRYPT 2001","versions":["conference paper"],"year":2001},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","sections":[{"content":"Uses a bilinear pairing to verify a one-group-element signature, with EUF-CMA security under CDH in the ROM.","heading":"Atomic claims"},{"content":"Abstract and Introduction of the IACR proceedings PDF.","heading":"Evidence locator"}],"status":"published","subtitle":"Dan Boneh, Ben Lynn, Hovav Shacham · 2001","summary":"Uses a bilinear pairing to verify a one-group-element signature, with EUF-CMA security under CDH in the ROM.","title":"Short Signatures from the Weil Pairing","type":"paper","venue":"ASIACRYPT 2001","year":2001,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2001-BLS"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2004-BB","keywords":["pairing","q-sdh","standard-model","short-signature"],"metadata":{"authors":["Dan Boneh","Xavier Boyen"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2004-BB","keywords":["pairing","q-sdh","standard-model","short-signature"],"maps_to":[],"primary_url":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","status":"published","title":"Short Signatures Without Random Oracles","venue":"EUROCRYPT 2004","versions":["conference paper","Journal of Cryptology 2008"],"year":2004},"primaryUrl":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","sections":[{"content":"Removes random oracles from a short pairing-based signature at the cost of the q-SDH assumption.","heading":"Atomic claims"},{"content":"Abstract and Introduction of the IACR proceedings PDF.","heading":"Evidence locator"}],"status":"published","subtitle":"Dan Boneh, Xavier Boyen · 2004","summary":"Removes random oracles from a short pairing-based signature at the cost of the q-SDH assumption.","title":"Short Signatures Without Random Oracles","type":"paper","venue":"EUROCRYPT 2004","year":2004,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2004-BB"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2008-GPV","keywords":["lattice","post-quantum","hash-and-sign","gaussian-sampling","trapdoor"],"metadata":{"authors":["Craig Gentry","Chris Peikert","Vinod Vaikuntanathan"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2008-GPV","keywords":["lattice","post-quantum","hash-and-sign","gaussian-sampling","trapdoor"],"maps_to":["SIG-OP-001"],"primary_url":"https://doi.org/10.1145/1374376.1374407","status":"published","title":"Trapdoors for Hard Lattices and New Cryptographic Constructions","venue":"STOC 2008","versions":["conference paper"],"year":2008},"primaryUrl":"https://doi.org/10.1145/1374376.1374407","sections":[{"content":"Introduces preimage-sampling lattice trapdoors and a hash-and-sign construction grounded in worst-case lattice hardness.","heading":"Atomic claims"},{"content":"Abstract and construction overview in the ACM version.","heading":"Evidence locator"}],"status":"published","subtitle":"Craig Gentry, Chris Peikert, Vinod Vaikuntanathan · 2008","summary":"Introduces preimage-sampling lattice trapdoors and a hash-and-sign construction grounded in worst-case lattice hardness.","title":"Trapdoors for Hard Lattices and New Cryptographic Constructions","type":"paper","venue":"STOC 2008","year":2008,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2008-GPV"},{"evidence":"abstract_checked","id":"SIG-PAPER-2009-LYU","keywords":["lattice","post-quantum","fiat-shamir","rejection-sampling"],"metadata":{"authors":["Vadim Lyubashevsky"],"dossier_type":"paper","evidence":"abstract_checked","id":"SIG-PAPER-2009-LYU","keywords":["lattice","post-quantum","fiat-shamir","rejection-sampling"],"maps_to":["SIG-OP-001"],"primary_url":"https://doi.org/10.1007/978-3-642-10366-7_35","status":"published","title":"Fiat-Shamir with Aborts: Applications to Lattice and Factoring-Based Signatures","venue":"ASIACRYPT 2009","versions":["conference paper"],"year":2009},"primaryUrl":"https://doi.org/10.1007/978-3-642-10366-7_35","sections":[{"content":"Adds rejection/abort sampling to Fiat-Shamir-style identification so responses can hide a lattice signing secret without a trapdoor sampler.","heading":"Atomic claims"}],"status":"published","subtitle":"Vadim Lyubashevsky · 2009","summary":"Adds rejection/abort sampling to Fiat-Shamir-style identification so responses can hide a lattice signing secret without a trapdoor sampler.","title":"Fiat-Shamir with Aborts: Applications to Lattice and Factoring-Based Signatures","type":"paper","venue":"ASIACRYPT 2009","year":2009,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2009-LYU"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2011-ED25519","keywords":["schnorr","eddsa","ed25519","deterministic","side-channel"],"metadata":{"authors":["Daniel J. Bernstein","Niels Duif","Tanja Lange","Peter Schwabe","Bo-Yin Yang"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2011-ED25519","keywords":["schnorr","eddsa","ed25519","deterministic","side-channel"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2011/368","status":"published","title":"High-Speed High-Security Signatures","venue":"CHES 2011","versions":["ePrint 2011/368","conference paper"],"year":2011},"primaryUrl":"https://eprint.iacr.org/2011/368","sections":[{"content":"Builds a high-speed Edwards-curve Schnorr-style signature with 32-byte public keys, 64-byte signatures, deterministic nonces, and constant-time software discipline.","heading":"Atomic claims"},{"content":"Abstract and Introduction of ePrint 2011/368.","heading":"Evidence locator"}],"status":"published","subtitle":"Daniel J. Bernstein, Niels Duif, Tanja Lange et al. · 2011","summary":"Builds a high-speed Edwards-curve Schnorr-style signature with 32-byte public keys, 64-byte signatures, deterministic nonces, and constant-time software discipline.","title":"High-Speed High-Security Signatures","type":"paper","venue":"CHES 2011","year":2011,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2011-ED25519"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2018-DILITHIUM","keywords":["lattice","post-quantum","module-lwe","module-sis","fiat-shamir-with-aborts"],"metadata":{"authors":["Léo Ducas","Eike Kiltz","Tancrède Lepoint","Vadim Lyubashevsky","Peter Schwabe","Gregor Seiler","Damien Stehlé"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2018-DILITHIUM","keywords":["lattice","post-quantum","module-lwe","module-sis","fiat-shamir-with-aborts"],"maps_to":["SIG-OP-001"],"primary_url":"https://eprint.iacr.org/2017/633","status":"published","title":"CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme","venue":"IACR TCHES 2018(1)","versions":["ePrint 2017/633","TCHES article"],"year":2018},"primaryUrl":"https://eprint.iacr.org/2017/633","sections":[{"content":"Builds a module-lattice Fiat-Shamir-with-aborts signature that avoids discrete Gaussian sampling and is designed for constant-time implementation.","heading":"Atomic claims"},{"content":"Abstract and Introduction of ePrint 2017/633 and the TCHES paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Léo Ducas, Eike Kiltz, Tancrède Lepoint et al. · 2018","summary":"Builds a module-lattice Fiat-Shamir-with-aborts signature that avoids discrete Gaussian sampling and is designed for constant-time implementation.","title":"CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme","type":"paper","venue":"IACR TCHES 2018(1)","year":2018,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2018-DILITHIUM"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2019-SPHINCSPLUS","keywords":["hash-based","stateless","post-quantum","hypertree","fors"],"metadata":{"authors":["Andreas Hülsing","Stefan Kölbl","Daniel J. Bernstein","Ruben Niederhagen","Joost Rijneveld","Peter Schwabe"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2019-SPHINCSPLUS","keywords":["hash-based","stateless","post-quantum","hypertree","fors"],"maps_to":["SIG-OP-001"],"primary_url":"https://eprint.iacr.org/2019/1086","status":"published","title":"The SPHINCS+ Signature Framework","venue":"ACM CCS 2019","versions":["ePrint 2019/1086","conference paper"],"year":2019},"primaryUrl":"https://eprint.iacr.org/2019/1086","sections":[{"content":"Introduces a stateless hash-based framework using FORS and tweakable hashes, avoiding the state discipline of classic Merkle signature systems.","heading":"Atomic claims"},{"content":"Abstract and Introduction of ePrint 2019/1086.","heading":"Evidence locator"}],"status":"published","subtitle":"Andreas Hülsing, Stefan Kölbl, Daniel J. Bernstein et al. · 2019","summary":"Introduces a stateless hash-based framework using FORS and tweakable hashes, avoiding the state discipline of classic Merkle signature systems.","title":"The SPHINCS+ Signature Framework","type":"paper","venue":"ACM CCS 2019","year":2019,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2019-SPHINCSPLUS"},{"evidence":"primary_source_checked","id":"SIG-PAPER-2020-FALCON","keywords":["lattice","post-quantum","ntru","gpv","gaussian-sampling","falcon"],"metadata":{"authors":["Pierre-Alain Fouque","Jeffrey Hoffstein","Paul Kirchner","Vadim Lyubashevsky","Thomas Pornin","Thomas Prest","Thomas Ricosset","Gregor Seiler","William Whyte","Zhenfei Zhang"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SIG-PAPER-2020-FALCON","keywords":["lattice","post-quantum","ntru","gpv","gaussian-sampling","falcon"],"maps_to":["SIG-OP-001"],"primary_url":"https://falcon-sign.info/falcon.pdf","status":"published","title":"Falcon: Fast-Fourier Lattice-Based Compact Signatures over NTRU","venue":"NIST PQC supporting documentation","versions":["Falcon specification"],"year":2020},"primaryUrl":"https://falcon-sign.info/falcon.pdf","sections":[{"content":"Instantiates GPV hash-and-sign with NTRU lattices and fast Fourier sampling to obtain compact signatures.","heading":"Atomic claims"},{"content":"Specification Chapter 1 and complete scheme specification.","heading":"Evidence locator"}],"status":"published","subtitle":"Pierre-Alain Fouque, Jeffrey Hoffstein, Paul Kirchner et al. · 2020","summary":"Instantiates GPV hash-and-sign with NTRU lattices and fast Fourier sampling to obtain compact signatures.","title":"Falcon: Fast-Fourier Lattice-Based Compact Signatures over NTRU","type":"paper","venue":"NIST PQC supporting documentation","year":2020,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2020-FALCON"},{"evidence":"official_source_checked","id":"SIG-PAPER-2023-FIPS186-5","keywords":["standard","rsa","ecdsa","eddsa","nist"],"metadata":{"authors":["National Institute of Standards and Technology"],"dossier_type":"paper","evidence":"official_source_checked","id":"SIG-PAPER-2023-FIPS186-5","keywords":["standard","rsa","ecdsa","eddsa","nist"],"maps_to":[],"primary_url":"https://csrc.nist.gov/pubs/fips/186-5/final","status":"standard","title":"FIPS 186-5: Digital Signature Standard","venue":"FIPS 186-5","versions":["final standard"],"year":2023},"primaryUrl":"https://csrc.nist.gov/pubs/fips/186-5/final","sections":[{"content":"Specifies RSA, ECDSA, and EdDSA signature generation/verification; DSA remains only for verification of existing signatures.","heading":"Normative contribution"},{"content":"NIST final publication page and FIPS 186-5 overview.","heading":"Evidence locator"}],"status":"standard","subtitle":"National Institute of Standards and Technology · 2023","summary":"Specifies RSA, ECDSA, and EdDSA signature generation/verification; DSA remains only for verification of existing signatures.","title":"FIPS 186-5: Digital Signature Standard","type":"paper","venue":"FIPS 186-5","year":2023,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2023-FIPS186-5"},{"evidence":"official_source_checked","id":"SIG-PAPER-2024-FIPS204","keywords":["standard","post-quantum","lattice","ml-dsa","nist"],"metadata":{"authors":["National Institute of Standards and Technology"],"citation_key":"NIST24/FIPS204","dossier_type":"paper","evidence":"official_source_checked","id":"SIG-PAPER-2024-FIPS204","keywords":["standard","post-quantum","lattice","ml-dsa","nist"],"maps_to":["SIG-OP-001"],"primary_url":"https://csrc.nist.gov/pubs/fips/204/final","status":"standard","title":"FIPS 204: Module-Lattice-Based Digital Signature Standard","venue":"FIPS 204","versions":["final standard"],"year":2024},"primaryUrl":"https://csrc.nist.gov/pubs/fips/204/final","sections":[{"content":"Standardizes ML-DSA, the module-lattice signature family derived from CRYSTALS-Dilithium.","heading":"Normative contribution"},{"content":"NIST final publication page and normative standard.","heading":"Evidence locator"}],"status":"standard","subtitle":"National Institute of Standards and Technology · 2024","summary":"Standardizes ML-DSA, the module-lattice signature family derived from CRYSTALS-Dilithium.","title":"FIPS 204: Module-Lattice-Based Digital Signature Standard","type":"paper","venue":"FIPS 204","year":2024,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2024-FIPS204"},{"evidence":"official_source_checked","id":"SIG-PAPER-2024-FIPS205","keywords":["standard","post-quantum","hash-based","slh-dsa","nist"],"metadata":{"authors":["National Institute of Standards and Technology"],"citation_key":"NIST24/FIPS205","dossier_type":"paper","evidence":"official_source_checked","id":"SIG-PAPER-2024-FIPS205","keywords":["standard","post-quantum","hash-based","slh-dsa","nist"],"maps_to":["SIG-OP-001"],"primary_url":"https://csrc.nist.gov/pubs/fips/205/final","status":"standard","title":"FIPS 205: Stateless Hash-Based Digital Signature Standard","venue":"FIPS 205","versions":["final standard"],"year":2024},"primaryUrl":"https://csrc.nist.gov/pubs/fips/205/final","sections":[{"content":"Standardizes SLH-DSA, the stateless hash-based signature family derived from SPHINCS+.","heading":"Normative contribution"},{"content":"NIST final publication page and normative standard.","heading":"Evidence locator"}],"status":"standard","subtitle":"National Institute of Standards and Technology · 2024","summary":"Standardizes SLH-DSA, the stateless hash-based signature family derived from SPHINCS+.","title":"FIPS 205: Stateless Hash-Based Digital Signature Standard","type":"paper","venue":"FIPS 205","year":2024,"sourcePath":"data/signature-catalog.json#SIG-PAPER-2024-FIPS205"},{"evidence":"primary_source_checked","id":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","keywords":["atomic-result","foundations","rsa","factoring","trapdoor-permutation","signature_security_roots","provable_unforgeability","boundary_result"],"metadata":{"claim_slug":"public-key-signature-feasibility","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["signature_security_roots"]},"historical_context":{"narrative":"In the 1970s, a digital signature with public verification was still a new cryptographic interface rather than a routine application primitive. The RSA paper showed that one algebraic key pair could separate a private operation held by the signer from a public operation available to every verifier. This made publicly checkable origin authentication concrete and connected it to the emerging idea of public-key cryptography. The narrow breakthrough captured here is the asymmetric interface itself: applying the private RSA transformation creates a value that the public transformation checks. Textbook RSA's later-known weaknesses mean this node must not be read as an EUF-CMA construction.","prior_boundary":"Before public-key cryptography, signature mechanisms did not provide a public verification operation separated from the signing secret.","significance_at_publication":"It established the feasibility and interface of public-key signing, making signatures a first-class public-key primitive rather than a symmetric authentication convention.","technical_delta":"RSA used the private exponent for signing and the public exponent for verification, separating signer capability from public verification."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","keywords":["foundations","rsa","factoring","trapdoor-permutation","signature_security_roots","provable_unforgeability","boundary_result"],"limitations":["Does not attribute modern EUF-CMA security to textbook RSA."],"paper_id":"SIG-PAPER-1978-RSA","qualifiers":["Feasibility claim for the RSA relation."],"source_locator":{"dossier_section":"SIG-PAPER-1978-RSA § Atomic claims and Evidence locator","primary_source":"Abstract and the signature discussion in the author-hosted CACM paper.","primary_source_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","status":"section_checked"},"statement":"The RSA private transformation can produce a value that anyone holding the public key can verify, establishing a public-key signature interface.","statement_status":"source_normalized_statement","status":"published","title":"Public-key signature feasibility via the RSA private transformation","work_id":"SIG-PAPER-1978-RSA"},"primaryUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","sections":[],"status":"published","subtitle":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","summary":"The RSA private transformation can produce a value that anyone holding the public key can verify, establishing a public-key signature interface.","title":"Public-key signature feasibility via the RSA private transformation","type":"result","venue":"Communications of the ACM 21(2)","year":1978,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY"},{"evidence":"bibliographic_checked","id":"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","keywords":["atomic-result","foundations","hash-based","one-time","post-quantum","hash_tree_signatures","post_quantum_signature_design","construction"],"metadata":{"claim_slug":"one-time-signatures-from-one-way-functions","contribution_kind":"construction","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design"],"technical_thread":["hash_tree_signatures"]},"historical_context":{"narrative":"Early signature proposals drew their security intuition from algebraic trapdoors. Lamport instead asked whether the much weaker premise of a one-way function already sufficed. His answer used pairs of secret values and published images, revealing only the message-selected secrets when signing. The construction opened a conservative branch whose security did not depend on factoring or discrete logarithms. Its guarantee is deliberately one-time: reusing the secret material can disclose both alternatives at bit positions and destroy security. Later hash-tree systems build on this primitive by managing many such keys under one root.","prior_boundary":"Early public-key signatures were tied to algebraic trapdoor assumptions, leaving unclear how little structure was sufficient for signing.","significance_at_publication":"The construction showed that one-way functions alone support one-time authentication, creating the conservative foundation later hash-based systems compose.","technical_delta":"The signing key publishes one-way images of secret values and reveals message-selected preimages in a single signature."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","keywords":["foundations","hash-based","one-time","post-quantum","hash_tree_signatures","post_quantum_signature_design","construction"],"limitations":["Key material must not be reused for unrestricted messages."],"paper_id":"SIG-PAPER-1979-LAMPORT","qualifiers":["One-time security and a one-way-function foundation."],"source_locator":{"dossier_section":"SIG-PAPER-1979-LAMPORT § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://lamport.azurewebsites.net/pubs/dig-sig.pdf","status":"not_normalized"},"statement":"Lamport constructs a one-time signature using only one-way functions.","statement_status":"source_normalized_statement","status":"published","title":"One-time signatures from one-way functions","work_id":"SIG-PAPER-1979-LAMPORT"},"primaryUrl":"https://lamport.azurewebsites.net/pubs/dig-sig.pdf","sections":[],"status":"published","subtitle":"Constructing Digital Signatures from a One Way Function","summary":"Lamport constructs a one-time signature using only one-way functions.","title":"One-time signatures from one-way functions","type":"result","venue":"SRI technical report CSL-98","year":1979,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS"},{"evidence":"primary_source_checked","id":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","keywords":["atomic-result","foundations","fiat-shamir","identification","random-oracle","fiat_shamir_schnorr","provable_unforgeability","transform"],"metadata":{"claim_slug":"fiat-shamir-identification-to-signature","contribution_kind":"transform","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["fiat_shamir_schnorr"]},"historical_context":{"narrative":"Interactive identification let a prover answer a verifier's fresh random challenge, but a signature had to be transferable and checkable later without that verifier. Fiat and Shamir connected these settings by deriving the challenge from a hash of the commitment and message. The move created a general design pattern through which efficient identification protocols could become noninteractive signature candidates. Here the atomic change is compilation: the verifier's coin is replaced by a message-bound digest. Security still depends on the identification protocol and hash model, so the transform is not a blanket theorem for every three-move proof.","prior_boundary":"Identification protocols offered interactive proofs of secret-key possession, while signatures required a transferable noninteractive transcript bound to a message.","significance_at_publication":"The transform connected identification design to signature design and became a reusable compilation pattern across discrete-log and lattice constructions.","technical_delta":"A hash-derived challenge made an identification transcript message-bound and publicly transferable without an online verifier."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","keywords":["foundations","fiat-shamir","identification","random-oracle","fiat_shamir_schnorr","provable_unforgeability","transform"],"limitations":["The transform alone does not establish security for every identification protocol."],"paper_id":"SIG-PAPER-1986-FS","qualifiers":["Heuristic random-oracle-style compilation in this historical record."],"source_locator":{"dossier_section":"SIG-PAPER-1986-FS § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/3-540-47721-7_12","status":"section_checked"},"statement":"The Fiat–Shamir transform replaces a public-coin verifier challenge with a hash of the message and commitment to obtain a noninteractive signature.","statement_status":"source_normalized_statement","status":"published","title":"Hash-derived challenges compile identification into signatures","work_id":"SIG-PAPER-1986-FS"},"primaryUrl":"https://doi.org/10.1007/3-540-47721-7_12","sections":[],"status":"published","subtitle":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","summary":"The Fiat–Shamir transform replaces a public-coin verifier challenge with a hash of the message and commitment to obtain a noninteractive signature.","title":"Hash-derived challenges compile identification into signatures","type":"result","venue":"CRYPTO 1986","year":1986,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE"},{"evidence":"primary_source_checked","id":"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","keywords":["atomic-result","foundations","euf-cma","factoring","claw-free-permutations","signature_security_roots","provable_unforgeability","definition"],"metadata":{"claim_slug":"adaptive-chosen-message-unforgeability","contribution_kind":"definition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["signature_security_roots"]},"historical_context":{"narrative":"Signature proposals lacked a stable adversarial target when Goldwasser, Micali, and Rivest formulated their result. A realistic attacker could request signatures on messages chosen in response to earlier answers and then attempt a fresh forgery. Making that sequence explicit supplied the security boundary against which later constructions could compare assumptions, proof models, and efficiency. The paper also gave a claw-free-permutation construction meeting its definition, but this record deliberately isolates the definition rather than merging the security game with the feasibility construction. Its role on the map is therefore definitional, not a claim about practical performance.","prior_boundary":"Earlier signature proposals lacked a durable game capturing an adversary that adaptively requests signatures before attempting a fresh forgery.","significance_at_publication":"GMR gave later signature constructions a durable adversarial target against which assumptions and efficiency could be compared.","technical_delta":"The work made adaptive signing queries followed by a fresh-message forgery the explicit security experiment."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","keywords":["foundations","euf-cma","factoring","claw-free-permutations","signature_security_roots","provable_unforgeability","definition"],"limitations":["The foundational construction is not an efficiency benchmark for later schemes."],"paper_id":"SIG-PAPER-1988-GMR","qualifiers":["Adaptive chosen-message attack model."],"source_locator":{"dossier_section":"SIG-PAPER-1988-GMR § Atomic claims and Evidence locator","primary_source":"Journal abstract and paper security experiment.","primary_source_url":"https://doi.org/10.1137/0217017","status":"section_checked"},"statement":"GMR formalizes signature security against an adversary that adaptively obtains signatures before forging a new message.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive chosen-message unforgeability for digital signatures","work_id":"SIG-PAPER-1988-GMR"},"primaryUrl":"https://doi.org/10.1137/0217017","sections":[],"status":"published","subtitle":"A Digital Signature Scheme Secure Against Adaptive Chosen-Message Attacks","summary":"GMR formalizes signature security against an adversary that adaptively obtains signatures before forging a new message.","title":"Adaptive chosen-message unforgeability for digital signatures","type":"result","venue":"SIAM Journal on Computing 17(2)","year":1988,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY"},{"evidence":"bibliographic_checked","id":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","keywords":["atomic-result","hash-based","stateful","merkle-tree","post-quantum","hash_tree_signatures","post_quantum_signature_design","capability_result"],"metadata":{"claim_slug":"merkle-tree-many-time-hash-signatures","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design"],"technical_thread":["hash_tree_signatures"]},"historical_context":{"narrative":"A Lamport-style key could safely authenticate only one message, so using it repeatedly required an unwieldy collection of independently trusted public keys. Merkle authentication trees compressed that collection into one root. Each signature carried a one-time signature and an authentication path, while the signer tracked which leaf keys had already been consumed. The idea transformed one-time primitives into a bounded many-signature system. The resulting capability is many-time only within a finite tree, and safe use requires persistent leaf state. That explicit limitation distinguishes the Merkle construction from the later stateless hypertree design of SPHINCS+.","prior_boundary":"One-time signatures from one-way functions required a fresh public key for every message and therefore did not by themselves provide a practical many-signature interface.","significance_at_publication":"Authentication trees amortized one public root across many one-time keys, establishing the stateful composition pattern behind the hash-based signature lineage.","technical_delta":"Tree authentication paths let each one-time key inherit trust from a compact root while signer state prevents leaf reuse."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","keywords":["hash-based","stateful","merkle-tree","post-quantum","hash_tree_signatures","post_quantum_signature_design","capability_result"],"limitations":["The construction does not remove signer-state management."],"paper_id":"SIG-PAPER-1989-MERKLE","qualifiers":["Bounded, stateful many-time signing."],"source_locator":{"dossier_section":"SIG-PAPER-1989-MERKLE § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/0-387-34805-0_21","status":"not_normalized"},"statement":"A Merkle authentication tree binds many one-time verification keys to one public root, enabling a bounded number of signatures.","statement_status":"source_normalized_statement","status":"published","title":"Merkle trees lift one-time keys to stateful many-time signatures","work_id":"SIG-PAPER-1989-MERKLE"},"primaryUrl":"https://doi.org/10.1007/0-387-34805-0_21","sections":[],"status":"published","subtitle":"A Certified Digital Signature","summary":"A Merkle authentication tree binds many one-time verification keys to one public root, enabling a bounded number of signatures.","title":"Merkle trees lift one-time keys to stateful many-time signatures","type":"result","venue":"CRYPTO 1989","year":1989,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES"},{"evidence":"primary_source_checked","id":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","keywords":["atomic-result","schnorr","discrete-log","fiat-shamir","deterministic-compatible","fiat_shamir_schnorr","compact_safe_signing","provable_unforgeability","construction"],"metadata":{"claim_slug":"compact-discrete-log-signature","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["compact_safe_signing","provable_unforgeability"],"technical_thread":["fiat_shamir_schnorr"]},"historical_context":{"narrative":"Fiat–Shamir provided a route from identification to signing, but deployment still depended on a clean algebraic instantiation with compact communication and little message-dependent work. Schnorr supplied such an instantiation in a discrete-log group. Its commitment could be prepared before the message arrived, after which hashing and one scalar response completed a small, easily verified signature. The contribution is the compact commitment–challenge–response signature and its shiftable precomputation boundary. Its apparent simplicity does not relax the essential requirement that every nonce remain secret and never be reused.","prior_boundary":"Fiat–Shamir made identification transcripts noninteractive, but practical signing still needed a compact discrete-log instantiation with low online work.","significance_at_publication":"Schnorr supplied a particularly simple commitment–challenge–response signature whose preprocessing and compact algebraic form shaped later classical implementations and threshold protocols.","technical_delta":"The construction instantiated commitment–challenge–response signing with a small response and shiftable offline group work."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","keywords":["schnorr","discrete-log","fiat-shamir","deterministic-compatible","fiat_shamir_schnorr","compact_safe_signing","provable_unforgeability","construction"],"limitations":["Nonce uniqueness and secrecy remain essential to security."],"paper_id":"SIG-PAPER-1991-SCHNORR","qualifiers":["Discrete-log setting; hash-derived challenge."],"source_locator":{"dossier_section":"SIG-PAPER-1991-SCHNORR § Atomic claims and Evidence locator","primary_source":"Abstract and Section 1 of the author-hosted paper.","primary_source_url":"https://doi.org/10.1007/BF00196725","status":"section_checked"},"statement":"Schnorr gives a compact discrete-log signature whose commitment computation can be performed before the message is known.","statement_status":"source_normalized_statement","status":"published","title":"Compact discrete-log signatures with offline commitment work","work_id":"SIG-PAPER-1991-SCHNORR"},"primaryUrl":"https://doi.org/10.1007/BF00196725","sections":[],"status":"published","subtitle":"Efficient Signature Generation by Smart Cards","summary":"Schnorr gives a compact discrete-log signature whose commitment computation can be performed before the message is known.","title":"Compact discrete-log signatures with offline commitment work","type":"result","venue":"Journal of Cryptology 4(3)","year":1991,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE"},{"evidence":"bibliographic_checked","id":"SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING","keywords":["atomic-result","rsa","pss","random-oracle","probabilistic-encoding","rsa_encoding_signatures","provable_unforgeability","mechanism"],"metadata":{"claim_slug":"rsa-pss-probabilistic-encoding","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["rsa_encoding_signatures"]},"historical_context":{"narrative":"Direct RSA exponentiation did not provide the randomized message encoding or chosen-message analysis expected of a modern signature. Bellare and Rogaway designed PSS so that the RSA representative incorporates a salt and hash-derived structure before the private permutation is applied. The encoding and its random-oracle proof made security reduction quality an explicit part of an RSA signature profile. One node isolates the encoding mechanism: randomized salt and structured hashing replace raw message exponentiation. That object is distinct from the accompanying reduction and remains tied to the RSA trapdoor-permutation and random-oracle setting.","prior_boundary":"Textbook RSA signing exposed the raw algebraic relation and did not provide the modern chosen-message security treatment expected of a signature encoding.","significance_at_publication":"PSS made randomized message encoding and a reduction in the random-oracle model explicit design objectives for the RSA signature family.","technical_delta":"The encoding replaced direct deterministic message exponentiation with a salt-based representative designed for reduction-oriented security."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING","keywords":["rsa","pss","random-oracle","probabilistic-encoding","rsa_encoding_signatures","provable_unforgeability","mechanism"],"limitations":["The encoding is not a standard-model construction."],"paper_id":"SIG-PAPER-1996-PSS","qualifiers":["RSA trapdoor permutation in the random-oracle model."],"source_locator":{"dossier_section":"SIG-PAPER-1996-PSS § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/3-540-68339-9_34","status":"not_normalized"},"statement":"PSS randomizes and structures the message representative before applying the RSA private operation.","statement_status":"source_normalized_statement","status":"published","title":"Probabilistic RSA-PSS message encoding","work_id":"SIG-PAPER-1996-PSS"},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_34","sections":[],"status":"published","subtitle":"Optimal Asymmetric Encryption and Signature","summary":"PSS randomizes and structures the message representative before applying the RSA private operation.","title":"Probabilistic RSA-PSS message encoding","type":"result","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING"},{"evidence":"bibliographic_checked","id":"SIG-RESULT-1996-PSS-TIGHT-ROM-RSA-SIGNATURES","keywords":["atomic-result","rsa","pss","random-oracle","probabilistic-encoding","rsa_encoding_signatures","provable_unforgeability","security_result"],"metadata":{"claim_slug":"tight-rom-rsa-signatures","contribution_kind":"security_result","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["rsa_encoding_signatures"]},"historical_context":{"narrative":"Direct RSA exponentiation did not provide the randomized message encoding or chosen-message analysis expected of a modern signature. Bellare and Rogaway designed PSS so that the RSA representative incorporates a salt and hash-derived structure before the private permutation is applied. The encoding and its random-oracle proof made security reduction quality an explicit part of an RSA signature profile. The second node records the proof contribution, which relates forgery of the encoded signature to inversion of RSA far more directly than textbook signing allowed. It does not remove the idealized hash oracle.","prior_boundary":"Textbook RSA signing exposed the raw algebraic relation and did not provide the modern chosen-message security treatment expected of a signature encoding.","significance_at_publication":"PSS made randomized message encoding and a reduction in the random-oracle model explicit design objectives for the RSA signature family.","technical_delta":"The proof supplied a substantially sharper security account for an RSA encoding than textbook signing offered."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1996-PSS-TIGHT-ROM-RSA-SIGNATURES","keywords":["rsa","pss","random-oracle","probabilistic-encoding","rsa_encoding_signatures","provable_unforgeability","security_result"],"limitations":["The claim does not remove the random-oracle idealization."],"paper_id":"SIG-PAPER-1996-PSS","qualifiers":["Random-oracle model and the paper's exact RSA reduction."],"source_locator":{"dossier_section":"SIG-PAPER-1996-PSS § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/3-540-68339-9_34","status":"not_normalized"},"statement":"The PSS analysis relates adaptive signature forgery to inverting the underlying RSA permutation in the random-oracle model.","statement_status":"source_normalized_statement","status":"published","title":"Reduction-oriented RSA-PSS security in the random-oracle model","work_id":"SIG-PAPER-1996-PSS"},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_34","sections":[],"status":"published","subtitle":"Optimal Asymmetric Encryption and Signature","summary":"The PSS analysis relates adaptive signature forgery to inverting the underlying RSA permutation in the random-oracle model.","title":"Reduction-oriented RSA-PSS security in the random-oracle model","type":"result","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1996-PSS-TIGHT-ROM-RSA-SIGNATURES"},{"evidence":"primary_source_checked","id":"SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES","keywords":["atomic-result","rsa","strong-rsa","standard-model","euf-cma","rsa_encoding_signatures","provable_unforgeability","compact_safe_signing","optimization"],"metadata":{"claim_slug":"efficient-standard-model-signatures","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability","compact_safe_signing"],"technical_thread":["rsa_encoding_signatures"]},"historical_context":{"narrative":"Foundational standard-model signatures had established feasibility but remained far from the simplicity and cost of popular random-oracle designs. Cramer and Shoup narrowed that gap with a stateless construction based on Strong RSA. Their work showed that adaptive chosen-message security without a programmable hash oracle could coexist with a substantially more practical signing structure, although under a different and stronger-looking assumption profile. The efficiency node concerns the construction's practical structure relative to earlier provable standard-model schemes. It should not be interpreted as faster than every contemporary random-oracle signature or as a benchmark claim.","prior_boundary":"Provably secure signatures in the standard model existed, but the gap between foundational feasibility and efficient stateless constructions remained substantial.","significance_at_publication":"Cramer–Shoup demonstrated a practical-looking adaptive chosen-message construction under Strong RSA without programming a random oracle, clarifying a different assumption/proof-model tradeoff from RSA-PSS.","technical_delta":"The construction reduced key and signing complexity relative to earlier standard-model feasibility results while avoiding random oracles."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES","keywords":["rsa","strong-rsa","standard-model","euf-cma","rsa_encoding_signatures","provable_unforgeability","compact_safe_signing","optimization"],"limitations":["Efficiency is relative to prior provable standard-model constructions, not every ROM scheme."],"paper_id":"SIG-PAPER-1999-CS","qualifiers":["Strong RSA assumption; standard model."],"source_locator":{"dossier_section":"SIG-PAPER-1999-CS § Atomic claims and Evidence locator","primary_source":"Author publication page abstract and journal-version introduction.","primary_source_url":"https://crypto.ethz.ch/publications/CraSho99.html","status":"section_checked"},"statement":"Cramer–Shoup gives a stateless Strong-RSA signature construction that the paper compares as more efficient than earlier provably secure standard-model schemes.","statement_status":"source_normalized_statement","status":"published","title":"Stateless Strong-RSA signing with lower cost than prior standard-model schemes","work_id":"SIG-PAPER-1999-CS"},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho99.html","sections":[],"status":"published","subtitle":"Signature Schemes Based on the Strong RSA Assumption","summary":"Cramer–Shoup gives a stateless Strong-RSA signature construction that the paper compares as more efficient than earlier provably secure standard-model schemes.","title":"Stateless Strong-RSA signing with lower cost than prior standard-model schemes","type":"result","venue":"ACM CCS 1999","year":1999,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES"},{"evidence":"primary_source_checked","id":"SIG-RESULT-1999-CS-STRONG-RSA-EUF-CMA","keywords":["atomic-result","rsa","strong-rsa","standard-model","euf-cma","rsa_encoding_signatures","provable_unforgeability","security_result"],"metadata":{"claim_slug":"strong-rsa-euf-cma","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["rsa_encoding_signatures"]},"historical_context":{"narrative":"Foundational standard-model signatures had established feasibility but remained far from the simplicity and cost of popular random-oracle designs. Cramer and Shoup narrowed that gap with a stateless construction based on Strong RSA. Their work showed that adaptive chosen-message security without a programmable hash oracle could coexist with a substantially more practical signing structure, although under a different and stronger-looking assumption profile. A separate security node records adaptive unforgeability under Strong RSA without a random oracle. Keeping it apart from the construction's efficiency prevents the proof model and performance comparison from collapsing into one adjective.","prior_boundary":"Provably secure signatures in the standard model existed, but the gap between foundational feasibility and efficient stateless constructions remained substantial.","significance_at_publication":"Cramer–Shoup demonstrated a practical-looking adaptive chosen-message construction under Strong RSA without programming a random oracle, clarifying a different assumption/proof-model tradeoff from RSA-PSS.","technical_delta":"The analysis changed the assumption and proof-model coordinate rather than merely proposing a faster RSA encoding."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-1999-CS-STRONG-RSA-EUF-CMA","keywords":["rsa","strong-rsa","standard-model","euf-cma","rsa_encoding_signatures","provable_unforgeability","security_result"],"limitations":["The security statement is bound to the paper's exact construction and parameters."],"paper_id":"SIG-PAPER-1999-CS","qualifiers":["Strong RSA assumption; adaptive chosen-message security."],"source_locator":{"dossier_section":"SIG-PAPER-1999-CS § Atomic claims and Evidence locator","primary_source":"Author publication page abstract and journal-version introduction.","primary_source_url":"https://crypto.ethz.ch/publications/CraSho99.html","status":"section_checked"},"statement":"The Cramer–Shoup signature is proved adaptively unforgeable under the Strong RSA assumption in the standard model.","statement_status":"source_normalized_statement","status":"published","title":"EUF-CMA security from Strong RSA without random oracles","work_id":"SIG-PAPER-1999-CS"},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho99.html","sections":[],"status":"published","subtitle":"Signature Schemes Based on the Strong RSA Assumption","summary":"The Cramer–Shoup signature is proved adaptively unforgeable under the Strong RSA assumption in the standard model.","title":"EUF-CMA security from Strong RSA without random oracles","type":"result","venue":"ACM CCS 1999","year":1999,"sourcePath":"data/signature-catalog.json#SIG-RESULT-1999-CS-STRONG-RSA-EUF-CMA"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2001-BLS-CDH-ROM-EUF-CMA","keywords":["atomic-result","pairing","bls","cdh","random-oracle","short-signature","pairing_short_signatures","provable_unforgeability","security_result"],"metadata":{"claim_slug":"cdh-rom-euf-cma","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["pairing_short_signatures"]},"historical_context":{"narrative":"Existing signatures generally occupied several group or field elements, making very short public authentication a distinct design objective. Boneh, Lynn, and Shacham used a bilinear pairing to check a single group element derived from a hash of the message. This established a compact pairing-based construction whose algebraic output was unusually simple. The security record identifies computational Diffie–Hellman and the random-oracle model as the basis for chosen-message unforgeability, rather than treating short output as evidence of a stronger proof. That boundary also distinguishes BLS from the later Boneh–Boyen standard-model point.","prior_boundary":"Classical signatures generally used multiple group or field elements, so substantially shorter public signatures required a new verification mechanism.","significance_at_publication":"Bilinear pairings enabled verification of a single-group-element signature and established a compact pairing-based construction under an explicit CDH/ROM security boundary.","technical_delta":"The proof connected pairing-based compactness to a named hardness assumption while retaining a programmable hash oracle."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2001-BLS-CDH-ROM-EUF-CMA","keywords":["pairing","bls","cdh","random-oracle","short-signature","pairing_short_signatures","provable_unforgeability","security_result"],"limitations":["This result does not provide a standard-model proof."],"paper_id":"SIG-PAPER-2001-BLS","qualifiers":["CDH-family assumption and random-oracle model."],"source_locator":{"dossier_section":"SIG-PAPER-2001-BLS § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of the IACR proceedings PDF.","primary_source_url":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","status":"section_checked"},"statement":"The BLS signature is analyzed for adaptive chosen-message unforgeability from computational Diffie–Hellman in the random-oracle model.","statement_status":"source_normalized_statement","status":"published","title":"BLS unforgeability from CDH in the random-oracle model","work_id":"SIG-PAPER-2001-BLS"},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","sections":[],"status":"published","subtitle":"Short Signatures from the Weil Pairing","summary":"The BLS signature is analyzed for adaptive chosen-message unforgeability from computational Diffie–Hellman in the random-oracle model.","title":"BLS unforgeability from CDH in the random-oracle model","type":"result","venue":"ASIACRYPT 2001","year":2001,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2001-BLS-CDH-ROM-EUF-CMA"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","keywords":["atomic-result","pairing","bls","cdh","random-oracle","short-signature","pairing_short_signatures","compact_safe_signing","construction"],"metadata":{"claim_slug":"one-group-element-pairing-signatures","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["compact_safe_signing"],"technical_thread":["pairing_short_signatures"]},"historical_context":{"narrative":"Existing signatures generally occupied several group or field elements, making very short public authentication a distinct design objective. Boneh, Lynn, and Shacham used a bilinear pairing to check a single group element derived from a hash of the message. This established a compact pairing-based construction whose algebraic output was unusually simple. The construction record isolates the one-element output and pairing check, while its companion card carries the CDH and random-oracle proof boundary. Actual byte length depends on the selected group and encoding, so the historical compactness claim is not silently converted into a current parameter recommendation.","prior_boundary":"Classical signatures generally used multiple group or field elements, so substantially shorter public signatures required a new verification mechanism.","significance_at_publication":"Bilinear pairings made one group element sufficient for a publicly verifiable signature, creating a sharply different compactness point from earlier schemes.","technical_delta":"Pairing verification made a single group element sufficient for a publicly verifiable signature."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","keywords":["pairing","bls","cdh","random-oracle","short-signature","pairing_short_signatures","compact_safe_signing","construction"],"limitations":["Concrete byte size depends on the chosen group and encoding."],"paper_id":"SIG-PAPER-2001-BLS","qualifiers":["Bilinear-group setting and hash-to-group operation."],"source_locator":{"dossier_section":"SIG-PAPER-2001-BLS § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of the IACR proceedings PDF.","primary_source_url":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","status":"section_checked"},"statement":"BLS hashes a message to a group and signs with one exponentiation, yielding a signature represented by one group element.","statement_status":"source_normalized_statement","status":"published","title":"One-group-element signatures verified by a bilinear pairing","work_id":"SIG-PAPER-2001-BLS"},"primaryUrl":"https://www.iacr.org/archive/asiacrypt2001/22480516.pdf","sections":[],"status":"published","subtitle":"Short Signatures from the Weil Pairing","summary":"BLS hashes a message to a group and signs with one exponentiation, yielding a signature represented by one group element.","title":"One-group-element signatures verified by a bilinear pairing","type":"result","venue":"ASIACRYPT 2001","year":2001,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2004-BB-Q-SDH-EUF-CMA","keywords":["atomic-result","pairing","q-sdh","standard-model","short-signature","pairing_short_signatures","provable_unforgeability","security_result"],"metadata":{"claim_slug":"q-sdh-euf-cma","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability"],"technical_thread":["pairing_short_signatures"]},"historical_context":{"narrative":"BLS made pairing signatures exceptionally short, but its full security argument programmed a random oracle. Boneh and Boyen explored the adjacent point where similarly compact output could be justified in the standard model. Their construction moved the proof-model boundary while introducing the parameterized q-SDH assumption, making the trade between idealized hashing and assumption strength visible rather than hiding it behind the word “short.” The proof node makes that cost explicit by tying adaptive forgery to the q-Strong Diffie–Hellman problem. It applies to the exact Boneh–Boyen construction rather than to pairing signatures as a family.","prior_boundary":"BLS achieved very short pairing signatures in the random-oracle model, leaving open whether comparable compactness could be obtained with a standard-model proof.","significance_at_publication":"Boneh–Boyen changed the proof-model boundary for short pairing signatures, at the cost of relying on the parameterized q-SDH assumption.","technical_delta":"The proof introduced a parameterized pairing assumption as the price of standard-model compact signatures."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2004-BB-Q-SDH-EUF-CMA","keywords":["pairing","q-sdh","standard-model","short-signature","pairing_short_signatures","provable_unforgeability","security_result"],"limitations":["The claim applies to the paper's scheme, not to pairing signatures generically."],"paper_id":"SIG-PAPER-2004-BB","qualifiers":["q-SDH assumption with its parameter dependence."],"source_locator":{"dossier_section":"SIG-PAPER-2004-BB § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of the IACR proceedings PDF.","primary_source_url":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","status":"section_checked"},"statement":"The Boneh–Boyen analysis derives chosen-message unforgeability for its short signature from the q-Strong Diffie–Hellman assumption.","statement_status":"source_normalized_statement","status":"published","title":"EUF-CMA proof for short signatures under q-SDH","work_id":"SIG-PAPER-2004-BB"},"primaryUrl":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","sections":[],"status":"published","subtitle":"Short Signatures Without Random Oracles","summary":"The Boneh–Boyen analysis derives chosen-message unforgeability for its short signature from the q-Strong Diffie–Hellman assumption.","title":"EUF-CMA proof for short signatures under q-SDH","type":"result","venue":"EUROCRYPT 2004","year":2004,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2004-BB-Q-SDH-EUF-CMA"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES","keywords":["atomic-result","pairing","q-sdh","standard-model","short-signature","pairing_short_signatures","provable_unforgeability","compact_safe_signing","security_result"],"metadata":{"claim_slug":"short-standard-model-signatures","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["provable_unforgeability","compact_safe_signing"],"technical_thread":["pairing_short_signatures"]},"historical_context":{"narrative":"BLS made pairing signatures exceptionally short, but its full security argument programmed a random oracle. Boneh and Boyen explored the adjacent point where similarly compact output could be justified in the standard model. Their construction moved the proof-model boundary while introducing the parameterized q-SDH assumption, making the trade between idealized hashing and assumption strength visible rather than hiding it behind the word “short.” The central capability is short pairing-based output backed by a proof that does not program a hash oracle. “Without random oracles” does not mean assumption-free: q-SDH remains fundamental to the claim.","prior_boundary":"BLS achieved very short pairing signatures in the random-oracle model, leaving open whether comparable compactness could be obtained with a standard-model proof.","significance_at_publication":"Boneh–Boyen changed the proof-model boundary for short pairing signatures, at the cost of relying on the parameterized q-SDH assumption.","technical_delta":"The construction retained compact pairing-based output while removing random-oracle programming from the full signature proof."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES","keywords":["pairing","q-sdh","standard-model","short-signature","pairing_short_signatures","provable_unforgeability","compact_safe_signing","security_result"],"limitations":["Removing random oracles changes the assumption profile rather than making it assumption-free."],"paper_id":"SIG-PAPER-2004-BB","qualifiers":["Pairing groups and the q-SDH assumption."],"source_locator":{"dossier_section":"SIG-PAPER-2004-BB § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of the IACR proceedings PDF.","primary_source_url":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","status":"section_checked"},"statement":"Boneh–Boyen constructs short pairing-based signatures with a standard-model security proof.","statement_status":"source_normalized_statement","status":"published","title":"Short pairing signatures without random oracles","work_id":"SIG-PAPER-2004-BB"},"primaryUrl":"https://iacr.org/archive/eurocrypt2004/30270057/BBsigsEC04.pdf","sections":[],"status":"published","subtitle":"Short Signatures Without Random Oracles","summary":"Boneh–Boyen constructs short pairing-based signatures with a standard-model security proof.","title":"Short pairing signatures without random oracles","type":"result","venue":"EUROCRYPT 2004","year":2004,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","keywords":["atomic-result","lattice","post-quantum","hash-and-sign","gaussian-sampling","trapdoor","lattice_hash_and_sign","post_quantum_signature_design","construction"],"metadata":{"claim_slug":"lattice-hash-and-sign","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design"],"technical_thread":["lattice_hash_and_sign"]},"historical_context":{"narrative":"Lattice cryptography needed more than hard worst-case problems to support hash-and-sign: a signer had to invert a public map while returning a short preimage with the right distribution. Gentry, Peikert, and Vaikuntanathan developed trapdoors and sampling algorithms for precisely that interface. The resulting mechanism supported a lattice signature paradigm and later became the conceptual foundation for compact NTRU-lattice instantiations. At the scheme level, hashing selects a syndrome and the trapdoor produces a short preimage as the signature. Correct distributional sampling is part of security, not a replaceable implementation detail.","prior_boundary":"Lattice signatures lacked a general trapdoor interface that could sample short preimages with a distribution suitable for secure hash-and-sign.","significance_at_publication":"GPV created both the preimage-sampling mechanism and the resulting signature paradigm, grounding a major post-quantum family in worst-case lattice hardness.","technical_delta":"The construction transferred the hash-and-sign paradigm to lattices through distribution-controlled trapdoor inversion."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","keywords":["lattice","post-quantum","hash-and-sign","gaussian-sampling","trapdoor","lattice_hash_and_sign","post_quantum_signature_design","construction"],"limitations":["Secure implementation requires faithful short-vector sampling."],"paper_id":"SIG-PAPER-2008-GPV","qualifiers":["Trapdoor lattices and discrete-Gaussian-style preimage sampling."],"source_locator":{"dossier_section":"SIG-PAPER-2008-GPV § Atomic claims and Evidence locator","primary_source":"Abstract and construction overview in the ACM version.","primary_source_url":"https://doi.org/10.1145/1374376.1374407","status":"section_checked"},"statement":"GPV signs by hashing a message to a lattice syndrome and sampling a short preimage with a trapdoor.","statement_status":"source_normalized_statement","status":"published","title":"Lattice hash-and-sign from short preimage sampling","work_id":"SIG-PAPER-2008-GPV"},"primaryUrl":"https://doi.org/10.1145/1374376.1374407","sections":[],"status":"published","subtitle":"Trapdoors for Hard Lattices and New Cryptographic Constructions","summary":"GPV signs by hashing a message to a lattice syndrome and sampling a short preimage with a trapdoor.","title":"Lattice hash-and-sign from short preimage sampling","type":"result","venue":"STOC 2008","year":2008,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2008-GPV-LATTICE-PREIMAGE-SAMPLING-TRAPDOORS","keywords":["atomic-result","lattice","post-quantum","hash-and-sign","gaussian-sampling","trapdoor","lattice_hash_and_sign","post_quantum_signature_design","mechanism"],"metadata":{"claim_slug":"lattice-preimage-sampling-trapdoors","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design"],"technical_thread":["lattice_hash_and_sign"]},"historical_context":{"narrative":"Lattice cryptography needed more than hard worst-case problems to support hash-and-sign: a signer had to invert a public map while returning a short preimage with the right distribution. Gentry, Peikert, and Vaikuntanathan developed trapdoors and sampling algorithms for precisely that interface. The resulting mechanism supported a lattice signature paradigm and later became the conceptual foundation for compact NTRU-lattice instantiations. At the component level, the contribution is an interface for generating short, properly distributed preimages with a lattice trapdoor. It is reusable beyond signatures and therefore remains distinct from the complete hash-and-sign construction.","prior_boundary":"Lattice signatures lacked a general trapdoor interface that could sample short preimages with a distribution suitable for secure hash-and-sign.","significance_at_publication":"GPV created both the preimage-sampling mechanism and the resulting signature paradigm, grounding a major post-quantum family in worst-case lattice hardness.","technical_delta":"The mechanism exposed a reusable trapdoor-sampling interface rather than only an isolated signature construction."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2008-GPV-LATTICE-PREIMAGE-SAMPLING-TRAPDOORS","keywords":["lattice","post-quantum","hash-and-sign","gaussian-sampling","trapdoor","lattice_hash_and_sign","post_quantum_signature_design","mechanism"],"limitations":["A trapdoor sampler alone is not a complete signature scheme."],"paper_id":"SIG-PAPER-2008-GPV","qualifiers":["Distributional guarantees and parameter conditions are part of the mechanism."],"source_locator":{"dossier_section":"SIG-PAPER-2008-GPV § Atomic claims and Evidence locator","primary_source":"Abstract and construction overview in the ACM version.","primary_source_url":"https://doi.org/10.1145/1374376.1374407","status":"section_checked"},"statement":"GPV develops lattice trapdoors supporting short preimage sampling with distributions suitable for cryptographic use.","statement_status":"source_normalized_statement","status":"published","title":"Trapdoors that sample short lattice preimages","work_id":"SIG-PAPER-2008-GPV"},"primaryUrl":"https://doi.org/10.1145/1374376.1374407","sections":[],"status":"published","subtitle":"Trapdoors for Hard Lattices and New Cryptographic Constructions","summary":"GPV develops lattice trapdoors supporting short preimage sampling with distributions suitable for cryptographic use.","title":"Trapdoors that sample short lattice preimages","type":"result","venue":"STOC 2008","year":2008,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2008-GPV-LATTICE-PREIMAGE-SAMPLING-TRAPDOORS"},{"evidence":"abstract_checked","id":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","keywords":["atomic-result","lattice","post-quantum","fiat-shamir","rejection-sampling","lattice_fs_with_aborts","post_quantum_signature_design","compact_safe_signing","mechanism"],"metadata":{"claim_slug":"fiat-shamir-with-aborts","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design","compact_safe_signing"],"technical_thread":["lattice_fs_with_aborts"]},"historical_context":{"narrative":"Fiat–Shamir responses built from a short lattice secret can betray that secret when their distribution shifts with the witness. Lyubashevsky introduced rejection sampling and intentional aborts so that accepted transcripts follow a controlled distribution. This offered a trapdoor-free route to lattice signing and made abort probability, response bounds, and distributional hiding central design coordinates for later schemes. The mapped mechanism is the accept-or-reject step that hides witness dependence in successful responses. Because this dossier has only abstract-level evidence for the paper, exact theorem parameters remain curation debt and the node stays outside the default backbone.","prior_boundary":"Lattice identification responses could reveal information about a short signing secret because their distribution depended on that secret.","significance_at_publication":"Rejection sampling with aborts made a trapdoor-free Fiat–Shamir route possible and became the conceptual mechanism behind several efficient lattice signatures.","technical_delta":"The abort step replaced trapdoor preimage sampling with a secret-hiding response distribution in a Fiat–Shamir-style design."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","keywords":["lattice","post-quantum","fiat-shamir","rejection-sampling","lattice_fs_with_aborts","post_quantum_signature_design","compact_safe_signing","mechanism"],"limitations":["This record is based on abstract-level review and does not normalize every theorem parameter."],"paper_id":"SIG-PAPER-2009-LYU","qualifiers":["Abort probability and response bounds are integral to correctness and efficiency."],"source_locator":{"dossier_section":"SIG-PAPER-2009-LYU § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/978-3-642-10366-7_35","status":"abstract_checked"},"statement":"Fiat–Shamir with aborts uses rejection sampling so accepted response distributions are sufficiently independent of the lattice signing secret.","statement_status":"source_normalized_statement","status":"published","title":"Abort sampling hides secrets in lattice Fiat–Shamir signatures","work_id":"SIG-PAPER-2009-LYU"},"primaryUrl":"https://doi.org/10.1007/978-3-642-10366-7_35","sections":[],"status":"published","subtitle":"Fiat-Shamir with Aborts: Applications to Lattice and Factoring-Based Signatures","summary":"Fiat–Shamir with aborts uses rejection sampling so accepted response distributions are sufficiently independent of the lattice signing secret.","title":"Abort sampling hides secrets in lattice Fiat–Shamir signatures","type":"result","venue":"ASIACRYPT 2009","year":2009,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2011-ED25519-DETERMINISTIC-NONCE-SIDE-CHANNEL-DISCIPLINE","keywords":["atomic-result","schnorr","eddsa","ed25519","deterministic","side-channel","fiat_shamir_schnorr","compact_safe_signing","security_analysis"],"metadata":{"claim_slug":"deterministic-nonce-side-channel-discipline","contribution_kind":"security_analysis","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["compact_safe_signing"],"technical_thread":["fiat_shamir_schnorr"]},"historical_context":{"narrative":"An abstract Schnorr-family construction left many security-critical deployment choices unspecified: curve form, point encoding, nonce generation, scalar arithmetic, and timing behavior. Ed25519 fixed those choices together over a twisted Edwards curve and accompanied them with high-speed software. The result treated implementation discipline and wire compatibility as part of the named signature profile rather than as afterthoughts around a theorem. A second contribution isolates deterministic nonce derivation and constant-time-oriented execution. These choices reduce dependence on runtime randomness and timing leakage, but they do not prove resistance to every fault or side-channel technique.","prior_boundary":"Schnorr-family signatures were compact, but deployments still depended on curve choices, nonce handling, encodings, and implementation discipline not fixed by the abstract construction.","significance_at_publication":"Ed25519 packaged those choices into a fast deterministic software profile, turning implementation safety and interoperability into part of the named construction.","technical_delta":"The profile reduced dependence on per-signature randomness and made timing discipline an explicit part of the implementation design."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2011-ED25519-DETERMINISTIC-NONCE-SIDE-CHANNEL-DISCIPLINE","keywords":["schnorr","eddsa","ed25519","deterministic","side-channel","fiat_shamir_schnorr","compact_safe_signing","security_analysis"],"limitations":["It does not by itself prove resistance to every side channel or fault attack."],"paper_id":"SIG-PAPER-2011-ED25519","qualifiers":["Deterministic nonce derivation does not relax secret-key protection."],"source_locator":{"dossier_section":"SIG-PAPER-2011-ED25519 § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of ePrint 2011/368.","primary_source_url":"https://eprint.iacr.org/2011/368","status":"section_checked"},"statement":"Ed25519 derives the signing nonce from secret material and the message and uses a constant-time-oriented implementation profile.","statement_status":"source_normalized_statement","status":"published","title":"Deterministic nonce derivation and constant-time signing discipline","work_id":"SIG-PAPER-2011-ED25519"},"primaryUrl":"https://eprint.iacr.org/2011/368","sections":[],"status":"published","subtitle":"High-Speed High-Security Signatures","summary":"Ed25519 derives the signing nonce from secret material and the message and uses a constant-time-oriented implementation profile.","title":"Deterministic nonce derivation and constant-time signing discipline","type":"result","venue":"CHES 2011","year":2011,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2011-ED25519-DETERMINISTIC-NONCE-SIDE-CHANNEL-DISCIPLINE"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE","keywords":["atomic-result","schnorr","eddsa","ed25519","deterministic","side-channel","fiat_shamir_schnorr","compact_safe_signing","optimization"],"metadata":{"claim_slug":"ed25519-engineering-profile","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["compact_safe_signing"],"technical_thread":["fiat_shamir_schnorr"]},"historical_context":{"narrative":"An abstract Schnorr-family construction left many security-critical deployment choices unspecified: curve form, point encoding, nonce generation, scalar arithmetic, and timing behavior. Ed25519 fixed those choices together over a twisted Edwards curve and accompanied them with high-speed software. The result treated implementation discipline and wire compatibility as part of the named signature profile rather than as afterthoughts around a theorem. One contribution is the co-designed Ed25519 profile—curve, arithmetic, encoding, signing procedure, and software strategy. Its reported speed belongs to the cited implementation context rather than every future implementation bearing the same name.","prior_boundary":"Schnorr-family signatures were compact, but deployments still depended on curve choices, nonce handling, encodings, and implementation discipline not fixed by the abstract construction.","significance_at_publication":"Ed25519 packaged those choices into a fast deterministic software profile, turning implementation safety and interoperability into part of the named construction.","technical_delta":"The work co-designed the curve, arithmetic, wire format, and signing procedure instead of leaving them as deployment choices around abstract Schnorr."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE","keywords":["schnorr","eddsa","ed25519","deterministic","side-channel","fiat_shamir_schnorr","compact_safe_signing","optimization"],"limitations":["Reported speed is contextual, not a timeless property of all Ed25519 implementations."],"paper_id":"SIG-PAPER-2011-ED25519","qualifiers":["The paper's concrete Ed25519 profile and software environment."],"source_locator":{"dossier_section":"SIG-PAPER-2011-ED25519 § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of ePrint 2011/368.","primary_source_url":"https://eprint.iacr.org/2011/368","status":"section_checked"},"statement":"Ed25519 combines a twisted Edwards curve, fixed encodings, deterministic signing, and constant-time-oriented software into a named signature profile.","statement_status":"source_normalized_statement","status":"published","title":"Ed25519 fixes an Edwards-curve software and wire profile","work_id":"SIG-PAPER-2011-ED25519"},"primaryUrl":"https://eprint.iacr.org/2011/368","sections":[],"status":"published","subtitle":"High-Speed High-Security Signatures","summary":"Ed25519 combines a twisted Edwards curve, fixed encodings, deterministic signing, and constant-time-oriented software into a named signature profile.","title":"Ed25519 fixes an Edwards-curve software and wire profile","type":"result","venue":"CHES 2011","year":2011,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2018-DILITHIUM-GAUSSIAN-FREE-CONSTANT-TIME-DESIGN","keywords":["atomic-result","lattice","post-quantum","module-lwe","module-sis","fiat-shamir-with-aborts","lattice_fs_with_aborts","compact_safe_signing","post_quantum_signature_design","optimization"],"metadata":{"claim_slug":"gaussian-free-constant-time-design","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["compact_safe_signing","post_quantum_signature_design"],"technical_thread":["lattice_fs_with_aborts"]},"historical_context":{"narrative":"Efficient lattice signatures based on abort sampling still faced difficult choices around Gaussian sampling, structured lattices, response compression, and constant-time implementation. Dilithium combined module-lattice assumptions with bounded sampling, decomposition hints, and a carefully engineered rejection procedure. The resulting architecture occupied a balanced post-quantum design point and later provided the technical basis for the ML-DSA standard. The engineering node isolates removal of discrete Gaussian sampling and use of simple bounded distributions suitable for constant-time code. Whether a concrete implementation is constant-time still requires artifact-level evidence.","prior_boundary":"Fiat–Shamir-with-aborts lattice signatures could be efficient, but Gaussian sampling and implementation complexity remained central engineering concerns.","significance_at_publication":"Dilithium combined module lattices, bounded sampling, decomposition hints, and rejection sampling into a constant-time-oriented architecture that later became ML-DSA.","technical_delta":"The engineering choice removed a difficult sampler from the signing path while preserving the abort-based security structure."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2018-DILITHIUM-GAUSSIAN-FREE-CONSTANT-TIME-DESIGN","keywords":["lattice","post-quantum","module-lwe","module-sis","fiat-shamir-with-aborts","lattice_fs_with_aborts","compact_safe_signing","post_quantum_signature_design","optimization"],"limitations":["Constant-time behavior still depends on the exact implementation."],"paper_id":"SIG-PAPER-2018-DILITHIUM","qualifiers":["Implementation-aware design claim, not a benchmark observation."],"source_locator":{"dossier_section":"SIG-PAPER-2018-DILITHIUM § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of ePrint 2017/633 and the TCHES paper.","primary_source_url":"https://eprint.iacr.org/2017/633","status":"section_checked"},"statement":"Dilithium avoids discrete Gaussian sampling and uses simple bounded distributions and arithmetic designed for constant-time implementation.","statement_status":"source_normalized_statement","status":"published","title":"Gaussian-free, constant-time-oriented Dilithium signing","work_id":"SIG-PAPER-2018-DILITHIUM"},"primaryUrl":"https://eprint.iacr.org/2017/633","sections":[],"status":"published","subtitle":"CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme","summary":"Dilithium avoids discrete Gaussian sampling and uses simple bounded distributions and arithmetic designed for constant-time implementation.","title":"Gaussian-free, constant-time-oriented Dilithium signing","type":"result","venue":"IACR TCHES 2018(1)","year":2018,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2018-DILITHIUM-GAUSSIAN-FREE-CONSTANT-TIME-DESIGN"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","keywords":["atomic-result","lattice","post-quantum","module-lwe","module-sis","fiat-shamir-with-aborts","lattice_fs_with_aborts","post_quantum_signature_design","compact_safe_signing","construction"],"metadata":{"claim_slug":"module-lattice-fswa-signature","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design","compact_safe_signing"],"technical_thread":["lattice_fs_with_aborts"]},"historical_context":{"narrative":"Efficient lattice signatures based on abort sampling still faced difficult choices around Gaussian sampling, structured lattices, response compression, and constant-time implementation. Dilithium combined module-lattice assumptions with bounded sampling, decomposition hints, and a carefully engineered rejection procedure. The resulting architecture occupied a balanced post-quantum design point and later provided the technical basis for the ML-DSA standard. The architecture node captures the complete module-lattice signing relation and its decomposition machinery. It predates and is not identical to the later normative ML-DSA encoding and interface.","prior_boundary":"Fiat–Shamir-with-aborts lattice signatures could be efficient, but Gaussian sampling and implementation complexity remained central engineering concerns.","significance_at_publication":"Dilithium combined module lattices, bounded sampling, decomposition hints, and rejection sampling into a constant-time-oriented architecture that later became ML-DSA.","technical_delta":"The architecture specialized the abort-based lattice line to a balanced module-lattice design with explicit signing and verification formats."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","keywords":["lattice","post-quantum","module-lwe","module-sis","fiat-shamir-with-aborts","lattice_fs_with_aborts","post_quantum_signature_design","compact_safe_signing","construction"],"limitations":["This paper-level architecture is distinct from the later normative ML-DSA profile."],"paper_id":"SIG-PAPER-2018-DILITHIUM","qualifiers":["Module-LWE/Module-SIS-family security foundation."],"source_locator":{"dossier_section":"SIG-PAPER-2018-DILITHIUM § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of ePrint 2017/633 and the TCHES paper.","primary_source_url":"https://eprint.iacr.org/2017/633","status":"section_checked"},"statement":"Dilithium builds a module-lattice signature from Fiat–Shamir with aborts, bounded secrets, and decomposition hints.","statement_status":"source_normalized_statement","status":"published","title":"Module-lattice Fiat–Shamir-with-aborts signature architecture","work_id":"SIG-PAPER-2018-DILITHIUM"},"primaryUrl":"https://eprint.iacr.org/2017/633","sections":[],"status":"published","subtitle":"CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme","summary":"Dilithium builds a module-lattice signature from Fiat–Shamir with aborts, bounded secrets, and decomposition hints.","title":"Module-lattice Fiat–Shamir-with-aborts signature architecture","type":"result","venue":"IACR TCHES 2018(1)","year":2018,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","keywords":["atomic-result","hash-based","stateless","post-quantum","hypertree","fors","hash_tree_signatures","post_quantum_signature_design","capability_result"],"metadata":{"claim_slug":"stateless-hash-based-hypertree","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design"],"technical_thread":["hash_tree_signatures"]},"historical_context":{"narrative":"Merkle-tree signatures offered a conservative hash-based foundation but traditionally relied on durable state to avoid reusing one-time leaves. SPHINCS+ removed that operational dependency by arranging WOTS+ and FORS instances beneath a hypertree and choosing authentication material pseudorandomly. The price was larger signatures and substantial hashing, yielding a deliberately different post-quantum deployment point from lattice signatures. Its capability contribution is the stateless signing contract produced by FORS, WOTS+, and hypertree authentication. Statelessness mitigates leaf-counter failures but does not erase the family's signature-size and computation tradeoffs.","prior_boundary":"Merkle-tree signatures were conservative but traditionally required state to prevent reuse of one-time signing keys, creating a demanding operational contract.","significance_at_publication":"SPHINCS+ traded larger signatures and more computation for stateless operation under a hash-based security foundation, defining a distinct post-quantum deployment point.","technical_delta":"The framework removed the stateful signer contract of classic Merkle signatures by selecting and authenticating many-time components pseudorandomly."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","keywords":["hash-based","stateless","post-quantum","hypertree","fors","hash_tree_signatures","post_quantum_signature_design","capability_result"],"limitations":["Statelessness is obtained with larger signatures and substantial computation."],"paper_id":"SIG-PAPER-2019-SPHINCSPLUS","qualifiers":["Hash-based security with fixed parameter-set tradeoffs."],"source_locator":{"dossier_section":"SIG-PAPER-2019-SPHINCSPLUS § Atomic claims and Evidence locator","primary_source":"Abstract and Introduction of ePrint 2019/1086.","primary_source_url":"https://eprint.iacr.org/2019/1086","status":"section_checked"},"statement":"SPHINCS+ combines FORS, WOTS+, and a hypertree so signing does not require persistent leaf-use state.","statement_status":"source_normalized_statement","status":"published","title":"Stateless hash-based signatures from FORS and hypertrees","work_id":"SIG-PAPER-2019-SPHINCSPLUS"},"primaryUrl":"https://eprint.iacr.org/2019/1086","sections":[],"status":"published","subtitle":"The SPHINCS+ Signature Framework","summary":"SPHINCS+ combines FORS, WOTS+, and a hypertree so signing does not require persistent leaf-use state.","title":"Stateless hash-based signatures from FORS and hypertrees","type":"result","venue":"ACM CCS 2019","year":2019,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2020-FALCON-COMPACT-LATTICE-SIGNATURES","keywords":["atomic-result","lattice","post-quantum","ntru","gpv","gaussian-sampling","falcon","lattice_hash_and_sign","post_quantum_signature_design","compact_safe_signing","capability_result"],"metadata":{"claim_slug":"compact-lattice-signatures","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design","compact_safe_signing"],"technical_thread":["lattice_hash_and_sign"]},"historical_context":{"narrative":"GPV had shown how a trapdoor could turn short-preimage sampling into a lattice signature, but a compact concrete scheme still needed structured lattices and an efficient sampler with faithful output distribution. Falcon instantiated the paradigm over NTRU lattices and used fast Fourier techniques inside signing. This created a notably small-signature alternative whose implementation obligations differ sharply from abort-based designs. The capability node records Falcon's compact NTRU-lattice key and signature profile. Compact output should not be conflated with a simpler signing implementation or with Dilithium's abort-based mechanism.","prior_boundary":"GPV hash-and-sign offered compact lattice signatures in principle, but concrete trapdoor sampling had to be engineered without losing distributional correctness.","significance_at_publication":"Falcon specialized GPV to NTRU lattices and fast Fourier sampling, producing the compact-signature endpoint of the NIST lattice-signature finalists.","technical_delta":"The construction occupied a smaller-signature, more sampler-intensive point than abort-based module-lattice signatures."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2020-FALCON-COMPACT-LATTICE-SIGNATURES","keywords":["lattice","post-quantum","ntru","gpv","gaussian-sampling","falcon","lattice_hash_and_sign","post_quantum_signature_design","compact_safe_signing","capability_result"],"limitations":["Compact output does not imply simpler or constant-time signing."],"paper_id":"SIG-PAPER-2020-FALCON","qualifiers":["Concrete compactness depends on the Falcon parameter profile."],"source_locator":{"dossier_section":"SIG-PAPER-2020-FALCON § Atomic claims and Evidence locator","primary_source":"Specification Chapter 1 and complete scheme specification.","primary_source_url":"https://falcon-sign.info/falcon.pdf","status":"section_checked"},"statement":"Falcon realizes short public keys and signatures by instantiating GPV hash-and-sign over structured NTRU lattices.","statement_status":"source_normalized_statement","status":"published","title":"Compact NTRU-lattice signatures from GPV sampling","work_id":"SIG-PAPER-2020-FALCON"},"primaryUrl":"https://falcon-sign.info/falcon.pdf","sections":[],"status":"published","subtitle":"Falcon: Fast-Fourier Lattice-Based Compact Signatures over NTRU","summary":"Falcon realizes short public keys and signatures by instantiating GPV hash-and-sign over structured NTRU lattices.","title":"Compact NTRU-lattice signatures from GPV sampling","type":"result","venue":"NIST PQC supporting documentation","year":2020,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2020-FALCON-COMPACT-LATTICE-SIGNATURES"},{"evidence":"primary_source_checked","id":"SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING","keywords":["atomic-result","lattice","post-quantum","ntru","gpv","gaussian-sampling","falcon","lattice_hash_and_sign","post_quantum_signature_design","compact_safe_signing","optimization"],"metadata":{"claim_slug":"gpv-ntru-fast-fourier-sampling","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_signature_design","compact_safe_signing"],"technical_thread":["lattice_hash_and_sign"]},"historical_context":{"narrative":"GPV had shown how a trapdoor could turn short-preimage sampling into a lattice signature, but a compact concrete scheme still needed structured lattices and an efficient sampler with faithful output distribution. Falcon instantiated the paradigm over NTRU lattices and used fast Fourier techniques inside signing. This created a notably small-signature alternative whose implementation obligations differ sharply from abort-based designs. The mechanism node focuses on fast Fourier sampling as the bridge from GPV theory to efficient NTRU signing. Floating-point behavior and distributional fidelity remain security-critical implementation obligations.","prior_boundary":"GPV hash-and-sign offered compact lattice signatures in principle, but concrete trapdoor sampling had to be engineered without losing distributional correctness.","significance_at_publication":"Falcon specialized GPV to NTRU lattices and fast Fourier sampling, producing the compact-signature endpoint of the NIST lattice-signature finalists.","technical_delta":"The sampler made high-dimensional trapdoor sampling efficient enough for a compact concrete signature profile."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING","keywords":["lattice","post-quantum","ntru","gpv","gaussian-sampling","falcon","lattice_hash_and_sign","post_quantum_signature_design","compact_safe_signing","optimization"],"limitations":["The mechanism is not interchangeable with Dilithium's abort-based signing path."],"paper_id":"SIG-PAPER-2020-FALCON","qualifiers":["Floating-point and distributional correctness are implementation-critical."],"source_locator":{"dossier_section":"SIG-PAPER-2020-FALCON § Atomic claims and Evidence locator","primary_source":"Specification Chapter 1 and complete scheme specification.","primary_source_url":"https://falcon-sign.info/falcon.pdf","status":"section_checked"},"statement":"Falcon implements GPV-style short-preimage signing over NTRU lattices using fast Fourier sampling.","statement_status":"source_normalized_statement","status":"published","title":"Fast Fourier sampling for NTRU-lattice hash-and-sign","work_id":"SIG-PAPER-2020-FALCON"},"primaryUrl":"https://falcon-sign.info/falcon.pdf","sections":[],"status":"published","subtitle":"Falcon: Fast-Fourier Lattice-Based Compact Signatures over NTRU","summary":"Falcon implements GPV-style short-preimage signing over NTRU lattices using fast Fourier sampling.","title":"Fast Fourier sampling for NTRU-lattice hash-and-sign","type":"result","venue":"NIST PQC supporting documentation","year":2020,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING"},{"evidence":"official_source_checked","id":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES","keywords":["atomic-result","standard","rsa","ecdsa","eddsa","nist","signature_deployment_profiles","signature_standardization","standardization_result"],"metadata":{"claim_slug":"current-classical-nist-signatures","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"official_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["signature_standardization"],"technical_thread":["signature_deployment_profiles","rsa_encoding_signatures","fiat_shamir_schnorr"]},"historical_context":{"narrative":"Classical signatures had accumulated multiple federal profiles and legacy rules by the time FIPS 186-5 was issued. The revision consolidated current requirements for RSA, ECDSA, and EdDSA while changing how older DSA material may be used. Its historical role is to define an interoperable approval and conformance boundary, not to introduce the underlying mathematics or provide a new comparative security proof. The atomic decision is the current classical federal portfolio and its exact usage rules. Standard status neither upgrades old textbook variants nor makes all conforming implementations equally secure.","prior_boundary":"Classical signature families had accumulated separate standards and deployment profiles, including legacy choices no longer suitable for new signing applications.","significance_at_publication":"FIPS 186-5 consolidated the federal classical signature interface around profiled RSA, ECDSA, and EdDSA while changing the status of legacy DSA use.","technical_delta":"The standard consolidated algorithm, parameter, generation, verification, and conformance requirements into the current classical NIST signature profile."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES","keywords":["standard","rsa","ecdsa","eddsa","nist","signature_deployment_profiles","signature_standardization","standardization_result"],"limitations":["Standardization is not a new cryptographic security proof."],"paper_id":"SIG-PAPER-2023-FIPS186-5","qualifiers":["Normative federal standard; consult exact approval and legacy-use clauses."],"source_locator":{"dossier_section":"SIG-PAPER-2023-FIPS186-5 § Atomic claims and Evidence locator","primary_source":"NIST final publication page and FIPS 186-5 overview.","primary_source_url":"https://csrc.nist.gov/pubs/fips/186-5/final","status":"section_checked"},"statement":"FIPS 186-5 normatively specifies federal use of RSA, ECDSA, and EdDSA signature methods and revises legacy DSA status.","statement_status":"source_normalized_statement","status":"standard","title":"FIPS 186-5 profiles approved classical digital signatures","work_id":"SIG-PAPER-2023-FIPS186-5"},"primaryUrl":"https://csrc.nist.gov/pubs/fips/186-5/final","sections":[],"status":"standard","subtitle":"FIPS 186-5: Digital Signature Standard","summary":"FIPS 186-5 normatively specifies federal use of RSA, ECDSA, and EdDSA signature methods and revises legacy DSA status.","title":"FIPS 186-5 profiles approved classical digital signatures","type":"result","venue":"FIPS 186-5","year":2023,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES"},{"evidence":"official_source_checked","id":"SIG-RESULT-2024-FIPS204-ML-DSA-STANDARDIZATION","keywords":["atomic-result","standard","post-quantum","lattice","ml-dsa","nist","lattice_fs_with_aborts","signature_standardization","post_quantum_signature_design","standardization_result"],"metadata":{"claim_slug":"ml-dsa-standardization","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"official_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["signature_standardization","post_quantum_signature_design"],"technical_thread":["lattice_fs_with_aborts"]},"historical_context":{"narrative":"Dilithium's selection as a post-quantum design did not by itself give implementations a permanent federal interface. FIPS 204 fixed algorithms, encodings, parameter sets, error handling, and conformance details under the name ML-DSA. The document therefore marks the transition from a research construction family to a normative deployment profile, while leaving the earlier Dilithium paper as the source of the architectural ideas. This node records ML-DSA standardization alone. It links back to Dilithium's module-lattice architecture but does not retroactively turn every historical Dilithium variant or implementation into the standardized object.","prior_boundary":"Dilithium existed as a selected post-quantum design, but deployment required normative algorithms, encodings, parameter sets, and validation-facing interfaces.","significance_at_publication":"FIPS 204 converted the design lineage into ML-DSA, a stable federal specification rather than merely another construction paper.","technical_delta":"The document fixed a normative deployment profile for module-lattice Fiat–Shamir-with-aborts signatures."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2024-FIPS204-ML-DSA-STANDARDIZATION","keywords":["standard","post-quantum","lattice","ml-dsa","nist","lattice_fs_with_aborts","signature_standardization","post_quantum_signature_design","standardization_result"],"limitations":["The standard does not make all Dilithium implementations equivalent."],"paper_id":"SIG-PAPER-2024-FIPS204","qualifiers":["Normative FIPS profile, not every historical Dilithium variant."],"source_locator":{"dossier_section":"SIG-PAPER-2024-FIPS204 § Atomic claims and Evidence locator","primary_source":"NIST final publication page and normative standard.","primary_source_url":"https://csrc.nist.gov/pubs/fips/204/final","status":"section_checked"},"statement":"FIPS 204 specifies ML-DSA algorithms, encodings, parameter sets, and interfaces derived from the Dilithium design.","statement_status":"source_normalized_statement","status":"standard","title":"ML-DSA standardizes the Dilithium-derived module-lattice signature","work_id":"SIG-PAPER-2024-FIPS204"},"primaryUrl":"https://csrc.nist.gov/pubs/fips/204/final","sections":[],"status":"standard","subtitle":"FIPS 204: Module-Lattice-Based Digital Signature Standard","summary":"FIPS 204 specifies ML-DSA algorithms, encodings, parameter sets, and interfaces derived from the Dilithium design.","title":"ML-DSA standardizes the Dilithium-derived module-lattice signature","type":"result","venue":"FIPS 204","year":2024,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2024-FIPS204-ML-DSA-STANDARDIZATION"},{"evidence":"official_source_checked","id":"SIG-RESULT-2024-FIPS205-SLH-DSA-STANDARDIZATION","keywords":["atomic-result","standard","post-quantum","hash-based","slh-dsa","nist","hash_tree_signatures","signature_standardization","post_quantum_signature_design","standardization_result"],"metadata":{"claim_slug":"slh-dsa-standardization","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"official_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["signature_standardization","post_quantum_signature_design"],"technical_thread":["hash_tree_signatures"]},"historical_context":{"narrative":"SPHINCS+ supplied a stateless hash-based framework, but interoperable deployment required one exact set of algorithms, encodings, and approved parameter choices. FIPS 205 provided that contract under the name SLH-DSA, including SHA2- and SHAKE-based families. Its importance lies in normative adoption of a conservative post-quantum rail rather than invention of hypertrees or a claim that their size and speed costs disappeared. This node similarly records SLH-DSA's normative profile rather than the invention of SPHINCS+. Conformance is parameter- and encoding-specific and does not remove the operational costs of stateless hash-based signing.","prior_boundary":"SPHINCS+ offered stateless hash-based signatures, but interoperable deployment still required fixed algorithms, parameter sets, encodings, and conformance rules.","significance_at_publication":"FIPS 205 converted that framework into SLH-DSA and supplied a normative conservative alternative to lattice-based post-quantum signatures.","technical_delta":"The document fixed a normative stateless hash-based alternative with SHA2- and SHAKE-based parameter families."},"historical_context_status":"curator_synthesis","id":"SIG-RESULT-2024-FIPS205-SLH-DSA-STANDARDIZATION","keywords":["standard","post-quantum","hash-based","slh-dsa","nist","hash_tree_signatures","signature_standardization","post_quantum_signature_design","standardization_result"],"limitations":["Standardization does not remove the signature-size and computation tradeoffs of the family."],"paper_id":"SIG-PAPER-2024-FIPS205","qualifiers":["Normative FIPS profile and its named parameter sets."],"source_locator":{"dossier_section":"SIG-PAPER-2024-FIPS205 § Atomic claims and Evidence locator","primary_source":"NIST final publication page and normative standard.","primary_source_url":"https://csrc.nist.gov/pubs/fips/205/final","status":"section_checked"},"statement":"FIPS 205 specifies SLH-DSA algorithms, encodings, and parameter sets derived from SPHINCS+.","statement_status":"source_normalized_statement","status":"standard","title":"SLH-DSA standardizes stateless hash-based signatures","work_id":"SIG-PAPER-2024-FIPS205"},"primaryUrl":"https://csrc.nist.gov/pubs/fips/205/final","sections":[],"status":"standard","subtitle":"FIPS 205: Stateless Hash-Based Digital Signature Standard","summary":"FIPS 205 specifies SLH-DSA algorithms, encodings, and parameter sets derived from SPHINCS+.","title":"SLH-DSA standardizes stateless hash-based signatures","type":"result","venue":"FIPS 205","year":2024,"sourcePath":"data/signature-catalog.json#SIG-RESULT-2024-FIPS205-SLH-DSA-STANDARDIZATION"},{"evidence":"source_grounded_route","id":"SIG-ROUTE-001","keywords":[],"metadata":{"current_bottleneck":"Changes that simplify sampling or rejection can shift signature size, tightness, failure behavior, or the exact Module-LWE and Module-SIS assumption profile.","dossier_type":"route","entry_results":["SIG-PAPER-2009-LYU","SIG-PAPER-2018-DILITHIUM","SIG-PAPER-2024-FIPS204"],"evidence":"source_grounded_route","falsifiable_next_test":"Specify one fixed security level and compare complete key/signature bytes, signing-tail latency, verification latency, failure probability, and constant-time audit findings against ML-DSA and Falcon.","id":"SIG-ROUTE-001","mechanism":"Retain structured-lattice arithmetic and compact decompositions while reducing rejection behavior, sampler complexity, and side-channel-sensitive control flow.","status":"proposed","targets":["SIG-OP-001"],"title":"Simplify module-lattice signing without surrendering compact encodings"},"primaryUrl":null,"sections":[{"content":"This route does not treat every structured-lattice signature as interchangeable and does not claim the target tradeoff is simultaneously attainable.","heading":"Route boundary"}],"status":"proposed","subtitle":"","summary":"This route does not treat every structured-lattice signature as interchangeable and does not claim the target tradeoff is simultaneously attainable.","title":"Simplify module-lattice signing without surrendering compact encodings","type":"route","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ROUTE-001"},{"evidence":"source_grounded_route","id":"SIG-ROUTE-002","keywords":[],"metadata":{"current_bottleneck":"Statelessness and conservative hash assumptions are paid for by many revealed hash values and repeated tree computation.","dossier_type":"route","entry_results":["SIG-PAPER-1979-LAMPORT","SIG-PAPER-1989-MERKLE","SIG-PAPER-2019-SPHINCSPLUS","SIG-PAPER-2024-FIPS205"],"evidence":"source_grounded_route","falsifiable_next_test":"Give a concrete parameter set with the same stated security target as one SLH-DSA profile, then measure signature bytes, peak memory, signing time, and verification time under identical hash primitives.","id":"SIG-ROUTE-002","mechanism":"Reduce the number or encoding cost of one-time and few-time signatures and their authentication paths while retaining an explicit hash-only security profile.","status":"proposed","targets":["SIG-OP-001"],"title":"Compress stateless hash-based authentication structures"},"primaryUrl":null,"sections":[{"content":"Changing to a stateful signer, an algebraic assumption, or an aggregate-signature interface resolves a different target.","heading":"Route boundary"}],"status":"proposed","subtitle":"","summary":"Changing to a stateful signer, an algebraic assumption, or an aggregate-signature interface resolves a different target.","title":"Compress stateless hash-based authentication structures","type":"route","venue":null,"year":null,"sourcePath":"data/signature-catalog.json#SIG-ROUTE-002"}],"propertyAssertions":[{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-015F8C03EAE52E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"single_signer"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-080090C2B2DF12","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"rsa"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-0A2B253B6D6696","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"hash-to-curve and one scalar multiplication"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-0A6CFFADDC3AD5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"single_signer"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-0ABD1F917BE032","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"stateless with fresh signing randomness"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-0ACFCD1711E77F","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"short-signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-0C165D00D29589","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"public-verification"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-0DC68F4B20C81B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"randomized hash-to-point and Gaussian preimage sampling"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-0F3FFB8CD0DF74","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"parameter-set-defined NTT polynomial arithmetic and rejection sampling"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-1021968AAE69FD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"pairing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-10A9EA00BA9014","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"public-verification"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-10DC8937B63DAF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"selected by NIST; FN-DSA standard in development at cutoff"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-1200739C91973F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"stateless"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-15034013D0960F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"digital_signature"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-15387712E03FA7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"stateless"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-16014D6693FF01","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"foundational research framework"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-16CD3104745FDB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"randomized salt"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-174FAB45EE6D52","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"parameter-set-defined hash computation"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-18D26A7E0C3043","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"research construction"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-1BB5269F11044D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"stateless_hash_based"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-1BB99BD499E96B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"deterministic secret-prefix-and-message hash"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-22CAE9FAEE959F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"many hash computations"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-25AA5679A183BC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"research construction"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-25F99A1841EB98","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"digital_signature"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-261607C4EECAB2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"pairing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-28D46D33FC509B","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"federal-standard"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-2975A319E175F0","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"public-verification"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-2A27DFE9829BE4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"random oracle for signatures"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-2AB121974849E6","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"deterministic-signing"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-2D6ED251CF6C0E","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"single_signer"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-2FF74A06439FDA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"polynomial arithmetic and norm checks"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-302000B6685FC6","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"probabilistic-encoding"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-33A78255964050","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"foundations"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-3516810AC110F0","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"repeated masking and rejection sampling"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-3634687B53ADEE","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"public-verification"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-3A19DA4FF4075A","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"parameter-set-defined hash computation"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-3A46A4822B1EEC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"standardized in FIPS 186-5"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-3BC1AC533B4243","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"linear-key-relation"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-3D10BBE075395F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"stateless"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-3D62A6F2B4EF7C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"one public RSA operation plus hashing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-3DD0FE2B9A425C","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"public-verification"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-3E21008862D8E6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"randomized preimage sampling"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-3EFD72E21B4B61","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"aggregation-friendly"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-4314B730E0F5D4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"NTRU polynomial arithmetic and norm check"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-44D3F3476EF90A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"digital_signature"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-45326A3D3F4C5B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"single_signer"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-490BDCFDEFD049","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"public-verification"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-49B4884D71BD93","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"post-quantum"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-4D0C1F9C5DB648","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"single_signer"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-4D1F61DF5C3085","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"polynomial arithmetic with rejection sampling"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-4F4B48E5F39A16","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"deterministic or randomized seed expansion depending profile"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-50753B64FFBAB3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"one public RSA exponentiation"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-53C9C16C4BF18E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"stateless"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-546AB7E69B5C4F","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"compact-signature"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-54E6FE53766D61","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"digital_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-593BC3C076B027","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"post-quantum"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-5CFB74124E6D14","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"compact-signature"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-5D777ABD810DF9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"stateless"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-5DF81C51DEF556","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"public-verification"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-5EC216D517AF2F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"not applicable"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-6173B21AFDCC91","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"short-signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-630F28514851E8","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"public-verification"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-657ABAE2716BCC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"stateless with nonce-safety requirement"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-6628D145672A93","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"stateless"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-664DC4F4E8857E","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"public-verification"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-670600EAEC11E2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"digital_signature"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-6760F135654292","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"schnorr"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-687B975D43632F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"stateless"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-68C9E19E66A8A7","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"federal-standard"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-69CCB49662C24E","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"deterministic or hedged randomized signing mode"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-6AA6F63BA15134","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"deployed family"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-6AD82C89A4480D","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"NIST FIPS 204 final"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-6BBAB6C4015ADB","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"single_signer"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-6E392504FCEEDF","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"lattice_fswa"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-6FCA63BA511C10","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"design lineage standardized as ML-DSA"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-71DF49C3DECD92","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"single_signer"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-7267C9A33A00E7","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"digital_signature"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-72B3BAF7E34AE0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"stateless"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-73556A9C85BF44","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"one private RSA exponentiation"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-736D2F1181B8C3","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"stateless"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-74E0304B27D5B1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"EdDSA standardized in FIPS 186-5"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-74E92851E1C2D6","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"post-quantum"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-768FCA22467DCA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"stateless"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-785B2EAA9C38D6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"historical foundation; not a secure encoding by itself"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-7936345FA628BA","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"standard-model-proof"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-7A94452E793DE4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"stateless"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-7CE4182ED0A823","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"public-verification"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-7D888DFEA56BE0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"design lineage standardized as SLH-DSA"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-7E9DC33BCACCEF","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"digital_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-80023A411A7B98","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"post-quantum"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-802840FA341330","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"standard model"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-8214D0A507F48C","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"public-verification"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-83293EDEB13257","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"digital_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-83694834B57C7A","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"post-quantum"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-8637DB758B346B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"discrete Gaussian preimage sampling"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-8657D22E05D799","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"modular exponentiations"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-88E9D96E9C3F7B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"single_signer"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-8B154A24FF6CDD","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"single_signer"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-8C0B1B44691D5B","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"public-verification"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-8F2B1D5F8CF222","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"single_signer"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-8FA1C4BE46881B","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"stateless-signing"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-8FA5D8657F0790","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"module_lattice_fswa"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-92122E649204D4","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"message-recovery-encoding"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-94FB63CD1E69C2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"single_signer"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-95EADB75D700E6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"none"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-9613B6C8F4687F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"hash-based reduction"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-965862D500EB23","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"one scalar multiplication plus hashing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-98B289BDD9646F","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"public-verification"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-98CD039C9DDCA8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"eddsa"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-992383D73D6F66","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"Schnorr-derived design"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-9C494F83FE4598","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"stateful tree traversal"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-9E6539AADEC5D7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"many hash computations"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-9F780955C80E27","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"pairing-group exponentiation"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-A036531485B1AD","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"gaussian-free-design"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-A0EF8622BDA866","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"standard model for the full construction"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-A11FA19F66479D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"modular exponentiations and prime generation/search"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-A2E78412F7E75D","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"rejection-sampling"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-A36DFFF4111D03","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"rsa_pss"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-A398FCE7DABBF1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"theoretical foundation"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-A5B0B0AD1EBE38","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"theoretical polynomial-time signer"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-A65A5F1A34E09D","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"standard-model-proof"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-AB7AAA96DB24AD","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"trapdoor-preimage-sampling"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-AFCFD7598D5050","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"fresh secret nonce per signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-B0012CD998742C","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"post-quantum"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-B0FA5E50A107E5","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"lattice linear relation and norm check"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-B24A0AF2901A4C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"random oracle"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-B66766D1FDF649","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"deployed ecosystem profile"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-B6DA8E65B05182","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"single_signer"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-B7A92D98D64782","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"standard model"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-B7FBED2A4009C1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"quantum random oracle lineage"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-B815546A9A1E9D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"digital_signature"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-BBB23FC142A6E4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"single_signer"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-C08E7E38ECE8B3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"randomized signing"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-C0DD4F8BBBBEA0","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"deterministic signing with an optional randomness input in the standard"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-C25E0645BB82F9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"pairing equation"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-C3C34A829409E1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"randomized signing in the full construction"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-C497F427670B10","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"randomized or deterministic message randomization by profile"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-C5E91706B4AF75","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"parameter-set-defined NTT polynomial arithmetic and checks"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-C63245EEB0032E","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"stateless_hash_based"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-C66A15EE79AA0F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"matrix-vector relation and norm check"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-C86BB93FBDF167","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"digital_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-C90013B398619B","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"conservative-assumption-profile"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-CC6E970927F996","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"fixed-base and variable-base scalar arithmetic plus hashing"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-CD3B8167D6C0DA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"digital_signature"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-CED01831AAA164","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"digital_signature"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-CF4B1A0FE66FDF","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"NIST FIPS 205 final"},{"dimension":"statefulness","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-D0247D85C0EC22","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"stateless"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-D13D4F48D72528","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"random oracle"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-D16E0C3AAFFC87","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"standards-profile"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-D399F840B3CA28","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"random-oracle lineage"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-D4682092D5DF1C","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"public-verification"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-D498F8BCBF44BC","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"digital_signature"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2008-GPV.md","id":"SIG-PROP-DBAB4882151D2C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2008-GPV","value":"lattice_hash_and_sign"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-MLDSA.md","id":"SIG-PROP-DDA9719EC3B4D7","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-MLDSA","value":"standardized Dilithium-derived profile"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-DE1C4CB0B36365","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"theoretical polynomial-time verifier"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-DF313EB12173CD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"double-scalar multiplication plus hashing"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2001-BLS.md","id":"SIG-PROP-DFB5668565F03C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2001-BLS","value":"none beyond hash-to-curve"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-E135C4C1995E17","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"pre-modern heuristic security"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1978-RSA.md","id":"SIG-PROP-E16D1BCE536B2A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1978-RSA","value":"single_signer"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-E4B9747995E659","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"module_lattice_fswa"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-E5C50B295AA4E0","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"post-quantum"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1999-CS.md","id":"SIG-PROP-E6444AC73140CF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1999-CS","value":"strong_rsa"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-E7DB3483689BE9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"fast Fourier Gaussian sampling"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2011-ED25519.md","id":"SIG-PROP-E7EB98A1C5DF45","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-2011-ED25519","value":"high-speed-software"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-E82CB155447E47","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"random oracle"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1988-GMR.md","id":"SIG-PROP-EA606BB40B3677","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1988-GMR","value":"adaptive-chosen-message-security"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-EC4015FFFCAA21","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"multi-scalar multiplication plus hashing"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-EC41F41A9275B5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"digital_signature"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-ECAE3E37EBB9E8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"ntru_lattice_hash_and_sign"},{"dimension":"verification_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2004-BB.md","id":"SIG-PROP-EDAE9493D94F1D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2004-BB","value":"pairing equation"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-EE16E0B463DD73","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"foundational research framework"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2019-SPHINCSPLUS.md","id":"SIG-PROP-EE2B6347139650","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2019-SPHINCSPLUS","value":"digital_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1991-SCHNORR.md","id":"SIG-PROP-EF844B66F35A08","review_status":"scheme_declared","scope":"construction","subject_id":"SIG-CONSTRUCTION-1991-SCHNORR","value":"public-verification"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2020-FALCON.md","id":"SIG-PROP-F0AB558365D3D6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2020-FALCON","value":"random oracle lineage"},{"dimension":"nonce_generation","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2009-LYU.md","id":"SIG-PROP-F11A3944D55AF4","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2009-LYU","value":"short random mask plus rejection sampling"},{"dimension":"proof_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2024-SLHDSA.md","id":"SIG-PROP-F2B5420DD092D1","review_status":"standard_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2024-SLHDSA","value":"standardized SPHINCS+-derived profile"},{"dimension":"signing_cost","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-1996-PSS.md","id":"SIG-PROP-F4A42D077E9B8E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-1996-PSS","value":"one private RSA operation plus hashing"},{"dimension":"signer_model","evidence_ref":"knowledge/primitives/signature/schemes/SIG-CONSTRUCTION-2018-DILITHIUM.md","id":"SIG-PROP-FAA6E1E922928C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SIG-CONSTRUCTION-2018-DILITHIUM","value":"single_signer"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY":{"anchor_roles":["model_definition"],"group":"foundation","label":"RSA public-verification interface","lane_rationale":"The scoped contribution establishes the public-verification interface through the RSA relation, without attributing modern unforgeability to textbook RSA.","lenses":["provable_unforgeability"],"primary":true,"selection_rationale":"Marks the shift from secret-key authentication to publicly verifiable signing; without it, later security definitions would appear without the interface they formalize.","thread":"signature_security_roots","visibility":"backbone"},"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS":{"anchor_roles":[],"group":"construction","label":"One-way-function one-time signatures","lane_rationale":"Gives a one-time signing construction from one-way functions; its first-construction status is not itself a definitional contribution.","lenses":["post_quantum_signature_design"],"primary":true,"selection_rationale":"Preserves the assumption-minimal one-time branch; it stays related because Merkle trees, rather than Lamport signing alone, create the many-signature research program.","thread":"hash_tree_signatures","visibility":"reviewed_related"},"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Hash-compiled identification signatures","lane_rationale":"Provides the reusable hash-challenge transform from identification to signatures, not a blanket theorem for every identification protocol.","lenses":["provable_unforgeability"],"primary":true,"selection_rationale":"Represents the reusable identification-to-signature transform that joins otherwise separate discrete-log and lattice branches; omitting it would hide their shared mechanism.","thread":"fiat_shamir_schnorr","visibility":"backbone"},"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY":{"anchor_roles":["model_definition"],"group":"foundation","label":"Adaptive chosen-message unforgeability","lane_rationale":"Defines the adaptive chosen-message unforgeability experiment that supplies later schemes' security target.","lenses":["provable_unforgeability"],"primary":true,"selection_rationale":"Establishes adaptive chosen-message unforgeability as the comparison target for later schemes; the construction used to prove feasibility is not merged into this definitional anchor.","thread":"signature_security_roots","visibility":"backbone"},"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES":{"anchor_roles":[],"group":"construction","label":"Stateful Merkle many-time signatures","lane_rationale":"Composes one-time verification keys through an authentication tree to construct bounded, stateful many-time signing.","lenses":["post_quantum_signature_design"],"primary":true,"selection_rationale":"Makes the bounded, stateful lift from one-time keys visible; it remains related so the later stateless SPHINCS+ transition is not mistaken for a routine parameter change.","thread":"hash_tree_signatures","visibility":"reviewed_related"},"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Offline-precomputable Schnorr signing","lane_rationale":"Introduces the concrete commitment-challenge-response signing architecture with message-independent commitment work; it is not only a comparative cost observation.","lenses":["compact_safe_signing","provable_unforgeability"],"primary":true,"selection_rationale":"Anchors the discrete-log branch with the compact commitment–challenge–response construction and its message-independent commitment work, not merely a generic use of Fiat–Shamir.","thread":"fiat_shamir_schnorr","visibility":"backbone"},"SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING":{"anchor_roles":[],"group":"construction","label":"Randomized RSA-PSS encoding","lane_rationale":"Defines randomized structured message encoding before the RSA private operation, a reusable signing mechanism.","lenses":["provable_unforgeability"],"primary":true,"selection_rationale":"Separates the randomized RSA encoding mechanism from its security reduction so readers can compare construction choices independently of proof-model claims.","thread":"rsa_encoding_signatures","visibility":"reviewed_related"},"SIG-RESULT-1996-PSS-TIGHT-ROM-RSA-SIGNATURES":{"anchor_roles":[],"group":"foundation","label":"RSA-PSS ROM reduction","lane_rationale":"The independently meaningful reduction relates forgery to RSA inversion in the random-oracle model; no exact tightness parameters are normalized by this card.","lenses":["provable_unforgeability"],"selection_rationale":"Retains the random-oracle reduction as a neighboring proof result; otherwise the PSS encoding could be misread as carrying standard-model security by itself.","thread":"rsa_encoding_signatures","visibility":"reviewed_related"},"SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES":{"anchor_roles":["practice_transition"],"group":"efficiency","label":"Stateless Strong-RSA signing","lane_rationale":"The principal claim is lower cost and stateless signing relative to earlier provable standard-model schemes, under Strong RSA rather than a universal comparison with ROM schemes.","lenses":["provable_unforgeability","compact_safe_signing"],"primary":true,"selection_rationale":"Marks the move from costly stateful standard-model feasibility results to a stateless Strong-RSA construction that the authors explicitly compare as more efficient.","thread":"rsa_encoding_signatures","visibility":"backbone"},"SIG-RESULT-1999-CS-STRONG-RSA-EUF-CMA":{"anchor_roles":[],"group":"foundation","label":"Strong-RSA EUF-CMA proof","lane_rationale":"Records the independently important Strong-RSA standard-model security boundary, separate from the companion relative-efficiency claim.","lenses":["provable_unforgeability"],"selection_rationale":"Keeps the Strong-RSA and standard-model security coordinate distinct from the construction's relative-efficiency claim; neither property should stand in for the other.","thread":"rsa_encoding_signatures","visibility":"reviewed_related"},"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"One-element pairing signatures","lane_rationale":"Gives hash-to-group signing and pairing verification as a distinct signature architecture, with one-element output scoped to its group representation.","lenses":["compact_safe_signing"],"primary":true,"selection_rationale":"Opens the pairing-based branch with a one-group-element signature and pairing verification; the companion CDH reduction is deliberately treated as a separate proof coordinate.","thread":"pairing_short_signatures","visibility":"backbone"},"SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Short standard-model pairing signatures","lane_rationale":"Provides a new short pairing-signature construction with a standard-model proof under q-SDH; a stronger proof-model point does not make the scheme a pure analysis node.","lenses":["provable_unforgeability","compact_safe_signing"],"primary":true,"selection_rationale":"Marks the short-pairing-signature point whose full proof no longer programs a random oracle, making it the serious adjacent alternative to BLS rather than another size optimization.","thread":"pairing_short_signatures","visibility":"backbone"},"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"GPV lattice hash-and-sign","lane_rationale":"Constructs signatures by trapdoor sampling a short preimage of a hashed message syndrome.","lenses":["post_quantum_signature_design"],"primary":true,"selection_rationale":"Anchors lattice hash-and-sign as a distinct architecture built around distribution-controlled short preimages, rather than treating every lattice signature as an abort-based variant.","thread":"lattice_hash_and_sign","visibility":"backbone"},"SIG-RESULT-2008-GPV-LATTICE-PREIMAGE-SAMPLING-TRAPDOORS":{"anchor_roles":[],"group":"construction","label":"Short lattice preimage sampling","lane_rationale":"Provides the independently reusable distribution-controlled short-preimage sampler underlying GPV and later constructions.","lenses":["post_quantum_signature_design"],"selection_rationale":"Keeps the reusable trapdoor sampler visible beside the complete GPV signature; this prevents a component used beyond signatures from being mistaken for the scheme itself.","thread":"lattice_hash_and_sign","visibility":"reviewed_related"},"SIG-RESULT-2011-ED25519-DETERMINISTIC-NONCE-SIDE-CHANNEL-DISCIPLINE":{"anchor_roles":[],"group":"construction","label":"Deterministic nonces and timing discipline","lane_rationale":"Specifies deterministic nonce derivation and implementation discipline as a concrete signing mechanism, not a new security theorem or a measured speedup.","lenses":["compact_safe_signing"],"selection_rationale":"Keeps deterministic nonce derivation and timing discipline separate from the broader Ed25519 profile so implementation-safety choices are not misreported as a new proof theorem.","thread":"fiat_shamir_schnorr","visibility":"reviewed_related"},"SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE":{"anchor_roles":["practice_transition"],"group":"construction","label":"Ed25519 software profile","lane_rationale":"The actual statement assembles a concrete curve, encoding, nonce, and software signing profile; it does not state a resource improvement against a specified baseline.","lenses":["compact_safe_signing"],"primary":true,"selection_rationale":"Represents the practice transition from an abstract Schnorr-family equation to a fixed curve, encoding, nonce, and software profile that implementers can actually share.","thread":"fiat_shamir_schnorr","visibility":"backbone"},"SIG-RESULT-2018-DILITHIUM-GAUSSIAN-FREE-CONSTANT-TIME-DESIGN":{"anchor_roles":[],"group":"construction","label":"Gaussian-free Dilithium signing","lane_rationale":"The scoped claim replaces Gaussian sampling with bounded-distribution signing machinery designed for constant-time implementation, without asserting a quantified performance advance.","lenses":["compact_safe_signing","post_quantum_signature_design"],"selection_rationale":"Retains the Gaussian-free, constant-time-oriented signing path as an engineering contribution; it is related because the complete Dilithium architecture carries the historical branch.","thread":"lattice_fs_with_aborts","visibility":"reviewed_related"},"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Module-lattice abort-based signing","lane_rationale":"Builds a module-lattice signature using aborts, bounded secrets, and decomposition hints; the later ML-DSA normative profile remains a separate object.","lenses":["post_quantum_signature_design","compact_safe_signing"],"primary":true,"selection_rationale":"Anchors the module-lattice Fiat–Shamir-with-aborts architecture that later becomes ML-DSA's technical basis, while leaving sampler and coding choices as adjacent engineering results.","thread":"lattice_fs_with_aborts","visibility":"backbone"},"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Stateless hash-based hypertrees","lane_rationale":"Combines FORS, WOTS+, and a hypertree into stateless signing, realizing a different state-management contract with explicit size and computation costs.","lenses":["post_quantum_signature_design"],"primary":true,"selection_rationale":"Marks the operational break from stateful Merkle signing to a stateless hash-based contract, a capability change that cannot be represented by signature-size comparisons alone.","thread":"hash_tree_signatures","visibility":"backbone"},"SIG-RESULT-2020-FALCON-COMPACT-LATTICE-SIGNATURES":{"anchor_roles":["capability_boundary"],"group":"efficiency","label":"Compact NTRU-lattice signatures","lane_rationale":"The node's principal result is a compact public-key and signature size point from the NTRU instantiation; it makes no claim of simpler or constant-time signing.","lenses":["post_quantum_signature_design","compact_safe_signing"],"primary":true,"selection_rationale":"Represents the compact NTRU-lattice realization of GPV hash-and-sign; choosing it as primary keeps the scheme-level tradeoff visible while the sampler remains inspectable nearby.","thread":"lattice_hash_and_sign","visibility":"backbone"},"SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING":{"anchor_roles":[],"group":"construction","label":"NTRU fast Fourier sampling","lane_rationale":"The contribution identifies the NTRU fast-Fourier short-preimage sampling mechanism; floating-point and distributional correctness remain part of its contract.","lenses":["post_quantum_signature_design","compact_safe_signing"],"selection_rationale":"Keeps fast Fourier sampling visible as Falcon's security-critical implementation mechanism; the complete compact signature profile, not the sampler alone, carries the paper's primary transition.","thread":"lattice_hash_and_sign","visibility":"reviewed_related"}},"overview_reading_path":["SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE"],"problems":[{"id":"provable_unforgeability","label":"Provable unforgeability","question":"How did adaptive chosen-message security, proof models, and reduction assumptions evolve?","reading_path":["SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","SIG-RESULT-1996-PSS-TIGHT-ROM-RSA-SIGNATURES","SIG-RESULT-1999-CS-STRONG-RSA-EUF-CMA","SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES"]},{"id":"compact_safe_signing","label":"Compact and implementation-safe signing","question":"Which mechanisms reduce signature or signing cost while retaining nonce and sampling discipline?","reading_path":["SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","SIG-RESULT-2011-ED25519-DETERMINISTIC-NONCE-SIDE-CHANNEL-DISCIPLINE","SIG-RESULT-2018-DILITHIUM-GAUSSIAN-FREE-CONSTANT-TIME-DESIGN","SIG-RESULT-2020-FALCON-COMPACT-LATTICE-SIGNATURES"]},{"id":"post_quantum_signature_design","label":"Post-quantum signature design","question":"How do hash-based, trapdoor-sampling, and abort-based signatures trade assumptions, state, size, and implementation complexity?","reading_path":["SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE"]},{"id":"signature_standardization","label":"Standardization and migration","question":"Which construction families became normative classical and post-quantum profiles?","reading_path":[]}],"relations":[{"change_dimensions":["mechanism"],"evidence_locator":"Bellare-Rogaway paper, abstract and Sections 1-4","evidence_url":"https://web.cs.ucdavis.edu/~rogaway/papers/exact.pdf","id":"lineage-cd375596870a2e5f","map_relation":"lineage","predecessor":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","relation_basis":"technical_dependency","relation_type":"CHANGES_MECHANISM","review_status":"primary_source_checked","statement":"RSA-PSS applies a randomized structured message encoding before the RSA private signing operation, replacing direct textbook message exponentiation; its security reduction is a separate contribution.","successor":"SIG-RESULT-1996-PSS-RSA-PSS-PROBABILISTIC-ENCODING"},{"change_dimensions":["mechanism"],"evidence_locator":"Schnorr paper, signature construction section","evidence_url":"https://doi.org/10.1007/BF00196725","id":"lineage-0f7ccc5b620f20d2","map_relation":"lineage","predecessor":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"Schnorr turns a three-move discrete-log identification protocol into a noninteractive signature by hashing the commitment and message into the challenge.","successor":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE"},{"change_dimensions":["model","security"],"evidence_locator":"Cramer-Shoup abstract and introduction","evidence_url":"https://www.iacr.org/archive/crypto1999/16660531/16660531.pdf","id":"lineage-24f27dd295acc84c","map_relation":"lineage","predecessor":"SIG-RESULT-1988-GMR-ADAPTIVE-CHOSEN-MESSAGE-UNFORGEABILITY","relation_basis":"model_relation","relation_type":"INSTANTIATES_SECURITY_MODEL","review_status":"primary_source_checked","statement":"Cramer-Shoup gives a stateless Strong-RSA signature satisfying adaptive chosen-message unforgeability in the standard model, realizing the security target formalized by GMR.","successor":"SIG-RESULT-1999-CS-EFFICIENT-STANDARD-MODEL-SIGNATURES"},{"change_dimensions":["mechanism","implementation"],"evidence_locator":"Ed25519 paper, Sections 2-4","evidence_url":"https://eprint.iacr.org/2011/368","id":"lineage-6800a1bd134f94ad","map_relation":"lineage","predecessor":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","relation_basis":"technical_dependency","relation_type":"ENGINEERS","review_status":"primary_source_checked","statement":"Ed25519 engineers a deterministic Schnorr-family signature over a twisted Edwards curve with fixed encodings and a high-speed software profile.","successor":"SIG-RESULT-2011-ED25519-ED25519-ENGINEERING-PROFILE"},{"change_dimensions":["assumption","security"],"evidence_locator":"Boneh-Boyen abstract and Section 1","evidence_url":"https://www.iacr.org/archive/eurocrypt2004/30270272/bbsigs.pdf","id":"lineage-1dab6330c0abb368","map_relation":"lineage","predecessor":"SIG-RESULT-2001-BLS-ONE-GROUP-ELEMENT-PAIRING-SIGNATURES","relation_basis":"result_progression","relation_type":"CHANGES_PROOF_MODEL","review_status":"primary_source_checked","statement":"Boneh-Boyen gives short pairing signatures with a standard-model proof under q-SDH, in contrast with the BLS CDH/random-oracle point; this changes the assumption and proof-model profile rather than establishing assumption dominance.","successor":"SIG-RESULT-2004-BB-SHORT-STANDARD-MODEL-SIGNATURES"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Merkle thesis/paper discussion of authentication trees","evidence_url":"https://www.ralphmerkle.com/papers/Thesis1979.pdf","id":"lineage-13fb9e6d7da0bd1c","map_relation":"reference","predecessor":"SIG-RESULT-1979-LAMPORT-ONE-TIME-SIGNATURES-FROM-ONE-WAY-FUNCTIONS","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"bibliographic_checked","statement":"Merkle authentication trees compose many one-time keys under one compact public root, extending the one-time hash-signature branch toward many signatures.","successor":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"SPHINCS+ specification, overview and construction sections","evidence_url":"https://eprint.iacr.org/2019/1086","id":"lineage-2cbd4cd8888906fb","map_relation":"lineage","predecessor":"SIG-RESULT-1989-MERKLE-MERKLE-TREE-MANY-TIME-HASH-SIGNATURES","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"primary_source_checked","statement":"SPHINCS+ combines few-time signatures, WOTS+, and a hypertree to obtain a stateless hash-based signature rather than maintaining a stateful leaf counter.","successor":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE"},{"change_dimensions":["mechanism","implementation"],"evidence_locator":"Falcon specification, design-rationale and key/sign algorithms","evidence_url":"https://falcon-sign.info/falcon.pdf","id":"lineage-bb3c5695d966f10d","map_relation":"lineage","predecessor":"SIG-RESULT-2008-GPV-LATTICE-HASH-AND-SIGN","relation_basis":"technical_dependency","relation_type":"ENGINEERS","review_status":"primary_source_checked","statement":"Falcon instantiates the GPV hash-and-sign paradigm over NTRU lattices and uses fast Fourier sampling to obtain compact concrete keys and signatures.","successor":"SIG-RESULT-2020-FALCON-GPV-NTRU-FAST-FOURIER-SAMPLING"},{"change_dimensions":["mechanism","security"],"evidence_locator":"Lyubashevsky paper, abstract and signature construction","evidence_url":"https://doi.org/10.1007/978-3-642-13190-5_42","id":"lineage-9a91ef9fac794768","map_relation":"reference","predecessor":"SIG-RESULT-1986-FS-FIAT-SHAMIR-IDENTIFICATION-TO-SIGNATURE","relation_basis":"technical_dependency","relation_type":"CHANGES_SIGNING_DISTRIBUTION","review_status":"bibliographic_checked","statement":"Lyubashevsky's lattice branch adds rejection sampling and aborts so the Fiat-Shamir transcript does not expose the short secret through the response distribution.","successor":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS"},{"change_dimensions":["mechanism","implementation"],"evidence_locator":"Dilithium paper, abstract and Sections 1-3","evidence_url":"https://eprint.iacr.org/2017/633","id":"lineage-28c4bbd890a0419c","map_relation":"reference","predecessor":"SIG-RESULT-2009-LYU-FIAT-SHAMIR-WITH-ABORTS","relation_basis":"technical_dependency","relation_type":"ENGINEERS","review_status":"primary_source_checked","statement":"Dilithium develops the Fiat-Shamir-with-aborts lattice line using module lattices, decomposition hints, and a Gaussian-free implementation design.","successor":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE"},{"change_dimensions":["implementation"],"evidence_locator":"FIPS 204, Introduction and algorithm specifications","evidence_url":"https://csrc.nist.gov/pubs/fips/204/final","id":"lineage-50147f7354d4cb4d","map_relation":"reference","predecessor":"SIG-RESULT-2018-DILITHIUM-MODULE-LATTICE-FSWA-SIGNATURE","relation_basis":"technical_dependency","relation_type":"STANDARDIZES","review_status":"primary_source_checked","statement":"FIPS 204 standardizes the Dilithium-derived module-lattice signature as ML-DSA with fixed algorithms, parameter sets, encodings, and interfaces.","successor":"SIG-RESULT-2024-FIPS204-ML-DSA-STANDARDIZATION"},{"change_dimensions":["implementation"],"evidence_locator":"FIPS 205, Introduction and parameter-set sections","evidence_url":"https://csrc.nist.gov/pubs/fips/205/final","id":"lineage-4492278f12c6315b","map_relation":"reference","predecessor":"SIG-RESULT-2019-SPHINCSPLUS-STATELESS-HASH-BASED-HYPERTREE","relation_basis":"technical_dependency","relation_type":"STANDARDIZES","review_status":"primary_source_checked","statement":"FIPS 205 standardizes a SPHINCS+-derived stateless hash-based signature as SLH-DSA with named SHA2 and SHAKE parameter sets.","successor":"SIG-RESULT-2024-FIPS205-SLH-DSA-STANDARDIZATION"},{"change_dimensions":["implementation"],"evidence_locator":"FIPS 186-5, Sections 5 and 8","evidence_url":"https://csrc.nist.gov/pubs/fips/186-5/final","id":"lineage-daf9bd7b8a81d415","map_relation":"reference","predecessor":"SIG-RESULT-1978-RSA-PUBLIC-KEY-SIGNATURE-FEASIBILITY","relation_basis":"technical_dependency","relation_type":"STANDARDIZES","review_status":"primary_source_checked","statement":"FIPS 186-5 retains RSA as an approved signature family only through specified encodings and parameter requirements, not textbook RSA.","successor":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES"},{"change_dimensions":["implementation"],"evidence_locator":"FIPS 186-5, Introduction and Section 7","evidence_url":"https://csrc.nist.gov/pubs/fips/186-5/final","id":"lineage-027bc96e007bd319","map_relation":"reference","predecessor":"SIG-RESULT-1991-SCHNORR-COMPACT-DISCRETE-LOG-SIGNATURE","relation_basis":"technical_dependency","relation_type":"STANDARDIZES_FAMILY","review_status":"primary_source_checked","statement":"FIPS 186-5 approves EdDSA, a deterministic Schnorr-family design, alongside RSA and ECDSA under fixed federal profiles.","successor":"SIG-RESULT-2023-FIPS186-5-CURRENT-CLASSICAL-NIST-SIGNATURES"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"Public-verification feasibility, unforgeability definitions, and their proof boundaries.","id":"signature_security_roots","label":"Signature definitions and security"},{"color":"#8b6340","description":"Trapdoor-permutation encodings and standard-model RSA-family signatures.","id":"rsa_encoding_signatures","label":"RSA encodings and strong-RSA signatures"},{"color":"#2f718e","description":"Identification-to-signature transforms and discrete-log signatures.","id":"fiat_shamir_schnorr","label":"Fiat–Shamir and Schnorr"},{"color":"#73549a","description":"Pairing-based constructions targeting compact public signatures.","id":"pairing_short_signatures","label":"Pairing-based short signatures"},{"color":"#b65358","description":"One-way-function signatures, Merkle trees, and stateless hypertrees.","id":"hash_tree_signatures","label":"One-time and hash-tree signatures"},{"color":"#9a6a32","description":"Trapdoor preimage sampling and NTRU-lattice hash-and-sign techniques.","id":"lattice_hash_and_sign","label":"Lattice hash-and-sign"},{"color":"#4f7b60","description":"Trapdoor-free lattice identification transformed into signatures with aborts.","id":"lattice_fs_with_aborts","label":"Lattice Fiat–Shamir with aborts"},{"color":"#6c5a91","description":"Cross-family algorithm portfolios, interfaces, and conformance boundaries fixed by public standards.","id":"signature_deployment_profiles","label":"Normative signature profiles"}]},"stats":{"constructions":15,"countsByType":{"assumption":14,"barrier":1,"construction":15,"open_problem":1,"paper":19,"result":27,"route":2},"entities":79,"lineageRelationships":7,"propertyAssertions":178,"relationships":91,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}