← Back to Blog

ML-DSA-87: Maximum-Security Lattice Signatures

ML-DSA-87: Maximum-Security Lattice Signatures - QNSQY post-quantum encryption guide

ML-DSA-87 is the largest and most conservative parameter set of the ML-DSA family standardized in NIST FIPS 204. It produces a 2592-byte public key, a 4595-byte signature, and a 4896-byte secret key. It sits at NIST Category 5, equivalent to AES-256 against quantum attackers. The CNSA 2.0 advisory from the NSA specifies ML-DSA-87 as the required signature algorithm for top-tier national security systems by 2035. For organizations protecting the most sensitive material with the longest retention requirements, ML-DSA-87 is the right choice.

This article walks through every parameter, explains when ML-DSA-87 is justified, and shows how QNSQY Business deploys it for organizations needing maximum margin.

The Heavy Fountain Pen Analogy

If ML-DSA-44 is the slim ballpoint and ML-DSA-65 is the gel pen, ML-DSA-87 is the heavy ceremonial fountain pen used to sign treaties. It costs more, uses more ink, requires care to write smoothly, but produces the most secure and most permanent signature. Some occasions justify the extra investment; most do not.

ML-DSA-87 is for occasions when forgery in 50 years still matters. National secrets, treaty texts, intellectual property registrations that need to outlive the inventor, archival material with legal force across decades. For anything more transient, ML-DSA-65 is the right choice.

Why the Highest Security Class Is Sometimes Mandatory

Some material does not have a tolerance for any plausible future forgery. National secrets that an adversary state would benefit from forging in 30 years. Court documents that establish legal status of property. Treaty texts whose ratification record must remain authentic indefinitely. Category 5 gives the highest possible margin against unexpected lattice cryptanalysis advances or unexpected quantum-computing leaps.

The Numbers in Detail

ML-DSA-87 parameters from FIPS 204, Section 4:

ParameterValueNotes
n (polynomial degree)256Same across all three parameter sets
q (modulus)8380417Same across all three parameter sets (prime ~2^23)
(k, l) (matrix dimensions)(8, 7)Largest
eta (secret key range)2Smaller than 65's eta=4
tau (challenge weight)60Larger than 65's tau=49
beta (challenge bound)120tau * eta
omega (max number of "1" hints)75Hint vector limit
Public key2592 bytesLargest
Secret key4896 bytesLargest
Signature4595 bytesLargest

Notice that eta drops from 4 (in ML-DSA-65) back to 2 in ML-DSA-87. The increased dimension (k, l) = (8, 7) provides the security increase, allowing the noise to stay tighter. The trade-off: the matrix dimension growth dominates the size budget, leading to nearly 5-kilobyte signatures.

Why eta Drops Back to 2

In ML-DSA, the security depends on a balance between matrix dimension (k, l) and noise width (eta). At small dimensions, the algorithm needs higher eta to produce hard lattice instances. At larger dimensions, the lattice problem is hard even with smaller eta, and tighter eta improves the failure rate and makes signatures more compact relative to dimension.

Security Level: NIST Category 5

NIST Category 5 means the scheme has at least the security of AES-256 against quantum attackers. The estimated bit-strength is roughly 2^256 classical and 2^192 quantum. This is the highest security tier in NIST's post-quantum framework.

CategoryReferenceQuantum strength
Category 1AES-128 key search~64 bits
Category 2SHA-256 collision search~128 bits
Category 3AES-192 key search~96 bits
Category 4SHA-384 collision search~192 bits
Category 5AES-256 key search~128 bits

The 128-bit quantum security floor (matching AES-256 under Grover's algorithm) is the upper end of post-quantum guarantees that NIST analyzed.

CNSA 2.0 Top-Secret Requirement

The NSA's CNSA 2.0 advisory states that national-security systems handling top-secret material must transition to Category 5 PQC by 2035. ML-DSA-87 is the only Category 5 NIST FIPS 204 signature option.

Material classificationRequired ML-DSA
Public, non-sensitiveML-DSA-44 acceptable
Sensitive but unclassifiedML-DSA-65 minimum
Confidential / SecretML-DSA-65 minimum
Top SecretML-DSA-87 required

For commercial entities working with classified information, ML-DSA-87 is mandatory in the top-secret tier.

Speed Comparison

Numbers from Open Quantum Safe liboqs benchmarks on a Skylake-class x86 CPU at 3 GHz:

OperationML-DSA-44ML-DSA-65ML-DSA-87
Keygen~80 microseconds~140 microseconds~210 microseconds
Sign (avg)~280 microseconds~430 microseconds~640 microseconds
Verify~75 microseconds~120 microseconds~190 microseconds

ML-DSA-87 sign is roughly 2.3x slower than ML-DSA-44. Verify is about 2.5x slower. For application-level signing (one signature per document, per session, per file), this is invisible. For high-volume TLS or DKIM, the cost matters.

When to Pick ML-DSA-87

Pick ML-DSA-87 when:

  • You handle CNSA 2.0 top-tier national security material.
  • Documents must remain unforgeable for 50+ years.
  • The 4595-byte signature size is acceptable.
  • You want maximum margin against unexpected lattice cryptanalysis.
  • Treaty texts, court documents, intellectual property registrations.

When NOT to Pick ML-DSA-87

Skip ML-DSA-87 when:

  • Bandwidth is constrained (TLS over satellite, IoT). Use ML-DSA-65.
  • Sign throughput matters (high-volume DKIM, frequent commits). Use ML-DSA-44 or 65.
  • Document retention is under 25 years. ML-DSA-65 is plenty.
  • Storage cost of nearly 5KB signatures is a concern.

How QNSQY Uses ML-DSA-87

QNSQY Business supports ML-DSA-87 in both hybrid mode (paired with Ed25519) and pure-PQC mode (no classical backup). The pure-PQC mode is for organizations that explicitly want a 100% post-quantum posture with no classical fallback.

QNSQY tierML-DSA-87 hybridML-DSA-87 pure-PQC
FreeNoNo
ProYes (opt-in)No
BusinessYesYes

For Business customers doing CNSA 2.0 top-tier alignment, the recommendation is ML-DSA-87 hybrid for general document signing and ML-DSA-87 pure-PQC for the most sensitive material.

Hybrid Combined Signature Size

ComponentPublic keySignature
Ed2551932 bytes64 bytes
ML-DSA-872592 bytes4595 bytes
Hybrid combined2624 bytes4659 bytes

The Ed25519 piece adds less than 2% overhead while providing classical security guarantees today. If lattice math falls, classical Ed25519 still holds. If Shor's algorithm breaks Ed25519 in the future, ML-DSA-87 still holds against quantum adversaries.

Side-Channel Considerations

ML-DSA-87 has the same constant-time considerations as the smaller variants. The Number Theoretic Transform must be implemented in constant time. The rejection sampling must avoid timing leaks. The reference implementation and the audited pqcrypto-mldsa crate handle these correctly.

Side channelMitigation
TimingConstant-time NTT, branchless rejection sampling
Power analysisApplication-level countermeasures
CacheConstant-time table lookups
Fault injectionIndependent verification within sign function

QNSQY's implementation has been audited and uses the same hardened code path across all ML-DSA parameter sets.

How ML-DSA-87 Affects Document Signing Workflows

In document-signing workflows, the signature is typically embedded in the document container (PDF signature dictionary, Office document XML, S/MIME envelope). ML-DSA-87's 4595-byte signature plus the 2592-byte public key push the embedded signature to roughly 7KB before any timestamp or chain certificate overhead. For PDF signatures with a chain of three certificates and a timestamp, the total signature block can reach 30-40 KB.

This is large compared to RSA-4096 signatures (under 1KB embedded) but small compared to the document content itself. PDF processors handle multi-megabyte attachments routinely, so a 30-40 KB signature block is not a constraint. The real concern is software compatibility: not every PDF reader recognizes the new signature OIDs yet. Adobe added preview support for NIST PQC signatures in Acrobat 2025, and other readers are expected to follow through 2026 and 2027.

Why ML-DSA-87 Often Uses Larger Hash Choices Internally

ML-DSA's specification includes the choice of hash function for the Fiat-Shamir transform (the challenge generation step). All parameter sets use SHAKE-256 by default, but ML-DSA-87 in particular benefits from the longer hash output because the larger challenge space gives more entropy in the rejection-sampling tail. SHAKE-256 produces variable-length output, so the algorithm extracts exactly the bits needed for the challenge polynomial.

For organizations doing CNSA 2.0 alignment, the explicit requirement is SHA-384 or SHA-512 for general hashing, with SHAKE-256 acceptable for the lattice-internal hash applications. The ML-DSA-87 specification's use of SHAKE-256 is consistent with this guidance.

Long-Term Storage Considerations

When ML-DSA-87 signatures are stored alongside long-term documents, the signature must remain verifiable indefinitely. This means:

ConcernMitigation
Algorithm OID stabilityNIST has registered ML-DSA-87 OIDs in the IANA registry; these will not change
Public key validationTrust chain to a long-lived root CA
Hash collision resistanceSHA-512 used internally; expected to remain secure for 50+ years
Verifier software availabilityOpen-source verifiers will exist; private vendors may not
Signature format documentationFIPS 204 is a stable public standard

The conservative practice is to re-sign archival documents every 10-20 years with the latest highest-strength algorithm, even if the original signature is still verifiable. This protects against unforeseen advances in cryptanalysis that might weaken the original signature long-term.

When to Pick FN-DSA-1024 Instead

FN-DSA-1024 (Falcon-1024) is also Category 5, with much smaller signatures (about 1280 bytes vs ML-DSA-87's 4595). The trade-offs:

PropertyML-DSA-87FN-DSA-1024
Signature size4595 bytes~1280 bytes
Signing speed~640 microseconds~5000 microseconds
Verification speed~190 microseconds~120 microseconds
Implementation complexityLower (Module-LWE)Higher (NTRU + floating-point Gaussian sampling)
Constant-time guaranteesStrong (no floating-point)Difficult (uses floats)

FN-DSA-1024 wins on signature size and verification speed but is harder to implement correctly because of its floating-point Gaussian sampling. ML-DSA-87 is easier to make constant-time and has a more straightforward security argument.

QNSQY Business supports both, letting customers pick based on their constraints.

Frequently Asked Questions

Why is ML-DSA-87 needed if ML-DSA-65 is already strong?

ML-DSA-65 is Category 3 (AES-192-equivalent). ML-DSA-87 is Category 5 (AES-256-equivalent). For top-secret national security work, regulators want AES-256-grade protection across all primitives. ML-DSA-87 is the only Category 5 option in FIPS 204.

How does ML-DSA-87 compare to RSA-15360?

RSA-15360 is a hypothetical RSA size that would match Category 5 classical strength but offers no quantum resistance. ML-DSA-87 is far stronger against quantum adversaries.

Is ML-DSA-87 too slow for production use?

For application-level signing (documents, files, certificates), no. Sign and verify times under a millisecond support thousands of operations per second per core. Only ultra-high-volume TLS handshake signing or DKIM at internet scale would feel the cost.

Can I downgrade from ML-DSA-87 to ML-DSA-65 later?

Technically yes, but verifiers must support both. QNSQY Business retains all algorithms simultaneously, so files signed at any parameter level remain verifiable. New files can use any supported level.

How does ML-DSA-87 compare to SLH-DSA-256s for top-secret work?

SLH-DSA-256s is hash-based (NIST FIPS 205) and offers Category 5 security with a different hardness assumption. SLH-DSA-256s has 64-byte public keys but 29,792-byte signatures. ML-DSA-87 has 2592-byte public keys and 4595-byte signatures. SLH-DSA wins on public key size and on hardness diversity (hashes, not lattices); ML-DSA-87 wins on signature size and signing speed. CNSA 2.0 allows both.

Sources

  1. NIST FIPS 204, Module-Lattice-Based Digital Signature Standard (August 2024). https://csrc.nist.gov/pubs/fips/204/final
  2. NSA CNSA 2.0 Cybersecurity Advisory (September 2022). https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF
  3. Bai, S. et al. "CRYSTALS-Dilithium Algorithm Specifications." NIST PQC Round 3 (2021). https://pq-crystals.org/dilithium/data/dilithium-specification-round3-20210208.pdf
  4. NIST FIPS 205, Stateless Hash-Based Digital Signature Standard (August 2024). https://csrc.nist.gov/pubs/fips/205/final
  5. NIST IR 8413, Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process (2022). https://csrc.nist.gov/pubs/ir/8413/upd1/final

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY