NIST finalized two post-quantum signature standards on the same day in August 2024, and that decision still confuses engineers picking a signature scheme in 2026. ML-DSA (FIPS 204, built on CRYSTALS-Dilithium) and SLH-DSA (FIPS 205, built on SPHINCS+) both survive a quantum computer attack that would break RSA and ECDSA. They do it in almost opposite ways. ML-DSA leans on lattice math and ships signatures under 5 KB. SLH-DSA leans on plain hash functions and ships signatures that run past 49 KB in some configurations. One signs in a tenth of a millisecond. The other can take over a second. Picking wrong doesn’t break security since both meet the same FIPS bar, but it can quietly break a budget, a battery life target, or a TLS handshake’s latency margin. This piece breaks down the exact byte counts, the benchmark numbers from three independent sources, what OpenSSL, Cloudflare, AWS, and Google Cloud have actually shipped, and which algorithm fits which job.
SLH-DSA vs ML-DSA: Post-Quantum Signature Comparison
NIST finalized two post-quantum signature standards on the same day in August 2024, and that decision still confuses engineers picking a signature scheme in 2026. ML-DSA (FIPS 204, built on CRYSTALS-Dilithium) and SLH-DSA (FIPS 205,…
shattered.io
Publisher
Sep 18, 2026 at 12:20 PM UTC · 23 phút đọc

What Is ML-DSA? The Lattice-Based Default
ML-DSA stands for Module-Lattice-Based Digital Signature Algorithm. NIST standardized it as FIPS 204 on August 13, 2024, and it descends directly from CRYSTALS-Dilithium, the submission that won NIST’s original post-quantum signature competition. The algorithm builds its security on the Module Learning With Errors problem, a lattice-based hardness assumption that has held up against both classical and quantum cryptanalysis since it entered serious academic review over a decade ago.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
