# ML-DSA-87: Maximum-Security Lattice Signatures

**Source**: https://quantumsequrity.com/blog/ml-dsa-87-deep-dive
**Category**: PQC Algorithms

---

[← Back to Blog](../../blog.html) PQC Algorithms

# ML-DSA-87: Maximum-Security Lattice Signatures

10 min read

ML-DSA-87 is the largest and most conservative parameter set of the ML-DSA family standardized in NIST FIPS 204. It produces a 2592-byte public key, a 4595-byte signature, and a 4896-byte secret key. It sits at NIST Category 5, equivalent to AES-256 against quantum attackers. The CNSA 2.0 advisory from the NSA specifies ML-DSA-87 as the required signature algorithm for top-tier national security systems by 2035. For organizations protecting the most sensitive material with the longest retention requirements, ML-DSA-87 is the right choice.

This article walks through every parameter, explains when ML-DSA-87 is justified, and shows how QNSQY Business deploys it for organizations needing maximum margin.

## The Heavy Fountain Pen Analogy

If ML-DSA-44 is the slim ballpoint and ML-DSA-65 is the gel pen, ML-DSA-87 is the heavy ceremonial fountain pen used to sign treaties. It costs more, uses more ink, requires care to write smoothly, but produces the most secure and most permanent signature. Some occasions justify the extra investment; most do not.

ML-DSA-87 is for occasions when forgery in 50 years still matters. National secrets, treaty texts, intellectual property registrations that need to outlive the inventor, archival material with legal force across decades. For anything more transient, ML-DSA-65 is the right choice.

### Why the Highest Security Class Is Sometimes Mandatory

Some material does not have a tolerance for any plausible future forgery. National secrets that an adversary state would benefit from forging in 30 years. Court documents that establish legal status of property. Treaty texts whose ratification record must remain authentic indefinitely. Category 5 gives the highest possible margin against unexpected lattice cryptanalysis advances or unexpected quantum-computing leaps.

## The Numbers in Detail

ML-DSA-87 parameters from FIPS 204, Section 4:

| Parameter | Value | Notes |
|-----------|-------|-------|
| n (polynomial degree) | 256 | Same across all three parameter sets |
| q (modulus) | 8380417 | Same across all three parameter sets (prime ~2^23) |
| (k, l) (matrix dimensions) | (8, 7) | Largest |
| eta (secret key range) | 2 | Smaller than 65's eta=4 |
| tau (challenge weight) | 60 | Larger than 65's tau=49 |
| beta (challenge bound) | 120 | tau * eta |
| omega (max number of "1" hints) | 75 | Hint vector limit |
| Public key | 2592 bytes | Largest |
| Secret key | 4896 bytes | Largest |
| Signature | 4595 bytes | Largest |

Notice that eta drops from 4 (in ML-DSA-65) back to 2 in ML-DSA-87. The increased dimension (k, l) = (8, 7) provides the security increase, allowing the noise to stay tighter. The trade-off: the matrix dimension growth dominates the size budget, leading to nearly 5-kilobyte signatures.

### Why eta Drops Back to 2

In ML-DSA, the security depends on a balance between matrix dimension (k, l) and noise width (eta). At small dimensions, the algorithm needs higher eta to produce hard lattice instances. At larger dimensions, the lattice problem is hard even with smaller eta, and tighter eta improves the failure rate and makes signatures more compact relative to dimension.

## Security Level: NIST Category 5

NIST Category 5 means the scheme has at least the security of AES-256 against quantum attackers. The estimated bit-strength is roughly 2^256 classical and 2^192 quantum. This is the highest security tier in NIST's post-quantum framework.

| Category | Reference | Quantum strength |
|----------|-----------|------------------|
| Category 1 | AES-128 key search | ~64 bits |
| Category 2 | SHA-256 collision search | ~128 bits |
| Category 3 | AES-192 key search | ~96 bits |
| Category 4 | SHA-384 collision search | ~192 bits |
| Category 5 | AES-256 key search | ~128 bits |

The 128-bit quantum security floor (matching AES-256 under Grover's algorithm) is the upper end of post-quantum guarantees that NIST analyzed.

### CNSA 2.0 Top-Secret Requirement

The NSA's CNSA 2.0 advisory states that national-security systems handling top-secret material must transition to Category 5 PQC by 2035. ML-DSA-87 is the only Category 5 NIST FIPS 204 signature option.

| Material classification | Required ML-DSA |
|------------------------|------------------|
| Public, non-sensitive | ML-DSA-44 acceptable |
| Sensitive but unclassified | ML-DSA-65 minimum |
| Confidential / Secret | ML-DSA-65 minimum |
| Top Secret | ML-DSA-87 required |

For commercial entities working with classified information, ML-DSA-87 is mandatory in the top-secret tier.

## Speed Comparison

Numbers from Open Quantum Safe liboqs benchmarks on a Skylake-class x86 CPU at 3 GHz:

| Operation | ML-DSA-44 | ML-DSA-65 | ML-DSA-87 |
|-----------|-----------|-----------|-----------|
| Keygen | ~80 microseconds | ~140 microseconds | ~210 microseconds |
| Sign (avg) | ~280 microseconds | ~430 microseconds | ~640 microseconds |
| Verify | ~75 microseconds | ~120 microseconds | ~190 microseconds |

ML-DSA-87 sign is roughly 2.3x slower than ML-DSA-44. Verify is about 2.5x slower. For application-level signing (one signature per document, per session, per file), this is invisible. For high-volume TLS or DKIM, the cost matters.

## When to Pick ML-DSA-87

Pick ML-DSA-87 when:

- You handle CNSA 2.0 top-tier national security material.
- Documents must remain unforgeable for 50+ years.
- The 4595-byte signature size is acceptable.
- You want maximum margin against unexpected lattice cryptanalysis.
- Treaty texts, court documents, intellectual property registrations.

## When NOT to Pick ML-DSA-87

Skip ML-DSA-87 when:

- Bandwidth is constrained (TLS over satellite, IoT). Use ML-DSA-65.
- Sign throughput matters (high-volume DKIM, frequent commits). Use ML-DSA-44 or 65.
- Document retention is under 25 years. ML-DSA-65 is plenty.
- Storage cost of nearly 5KB signatures is a concern.

## How QNSQY Uses ML-DSA-87

QNSQY Business supports ML-DSA-87 in both hybrid mode (paired with Ed25519) and pure-PQC mode (no classical backup). The pure-PQC mode is for organizations that explicitly want a 100% post-quantum posture with no classical fallback.

| QNSQY tier | ML-DSA-87 hybrid | ML-DSA-87 pure-PQC |
|------------|-------------------|---------------------|
| Free | No | No |
| Pro | Yes (opt-in) | No |
| Business | Yes | Yes |

For Business customers doing CNSA 2.0 top-tier alignment, the recommendation is ML-DSA-87 hybrid for general document signing and ML-DSA-87 pure-PQC for the most sensitive material.

### Hybrid Combined Signature Size

| Component | Public key | Signature |
|-----------|------------|-----------|
| Ed25519 | 32 bytes | 64 bytes |
| ML-DSA-87 | 2592 bytes | 4595 bytes |
| Hybrid combined | 2624 bytes | 4659 bytes |

The Ed25519 piece adds less than 2% overhead while providing classical security guarantees today. If lattice math falls, classical Ed25519 still holds. If Shor's algorithm breaks Ed25519 in the future, ML-DSA-87 still holds against quantum adversaries.

## Side-Channel Considerations

ML-DSA-87 has the same constant-time considerations as the smaller variants. The Number Theoretic Transform must be implemented in constant time. The rejection sampling must avoid timing leaks. The reference implementation and the audited pqcrypto-mldsa crate handle these correctly.

| Side channel | Mitigation |
|--------------|-----------|
| Timing | Constant-time NTT, branchless rejection sampling |
| Power analysis | Application-level countermeasures |
| Cache | Constant-time table lookups |
| Fault injection | Independent verification within sign function |

QNSQY's implementation has been audited and uses the same hardened code path across all ML-DSA parameter sets.

## How ML-DSA-87 Affects Document Signing Workflows

In document-signing workflows, the signature is typically embedded in the document container (PDF signature dictionary, Office document XML, S/MIME envelope). ML-DSA-87's 4595-byte signature plus the 2592-byte public key push the embedded signature to roughly 7KB before any timestamp or chain certificate overhead. For PDF signatures with a chain of three certificates and a timestamp, the total signature block can reach 30-40 KB.

This is large compared to RSA-4096 signatures (under 1KB embedded) but small compared to the document content itself. PDF processors handle multi-megabyte attachments routinely, so a 30-40 KB signature block is not a constraint. The real concern is software compatibility: not every PDF reader recognizes the new signature OIDs yet. Adobe added preview support for NIST PQC signatures in Acrobat 2025, and other readers are expected to follow through 2026 and 2027.

## Why ML-DSA-87 Often Uses Larger Hash Choices Internally

ML-DSA's specification includes the choice of hash function for the Fiat-Shamir transform (the challenge generation step). All parameter sets use SHAKE-256 by default, but ML-DSA-87 in particular benefits from the longer hash output because the larger challenge space gives more entropy in the rejection-sampling tail. SHAKE-256 produces variable-length output, so the algorithm extracts exactly the bits needed for the challenge polynomial.

For organizations doing CNSA 2.0 alignment, the explicit requirement is SHA-384 or SHA-512 for general hashing, with SHAKE-256 acceptable for the lattice-internal hash applications. The ML-DSA-87 specification's use of SHAKE-256 is consistent with this guidance.

## Long-Term Storage Considerations

When ML-DSA-87 signatures are stored alongside long-term documents, the signature must remain verifiable indefinitely. This means:

| Concern | Mitigation |
|---------|-----------|
| Algorithm OID stability | NIST has registered ML-DSA-87 OIDs in the IANA registry; these will not change |
| Public key validation | Trust chain to a long-lived root CA |
| Hash collision resistance | SHA-512 used internally; expected to remain secure for 50+ years |
| Verifier software availability | Open-source verifiers will exist; private vendors may not |
| Signature format documentation | FIPS 204 is a stable public standard |

The conservative practice is to re-sign archival documents every 10-20 years with the latest highest-strength algorithm, even if the original signature is still verifiable. This protects against unforeseen advances in cryptanalysis that might weaken the original signature long-term.

## When to Pick FN-DSA-1024 Instead

FN-DSA-1024 (Falcon-1024) is also Category 5, with much smaller signatures (about 1280 bytes vs ML-DSA-87's 4595). The trade-offs:

| Property | ML-DSA-87 | FN-DSA-1024 |
|----------|-----------|--------------|
| Signature size | 4595 bytes | ~1280 bytes |
| Signing speed | ~640 microseconds | ~5000 microseconds |
| Verification speed | ~190 microseconds | ~120 microseconds |
| Implementation complexity | Lower (Module-LWE) | Higher (NTRU + floating-point Gaussian sampling) |
| Constant-time guarantees | Strong (no floating-point) | Difficult (uses floats) |

FN-DSA-1024 wins on signature size and verification speed but is harder to implement correctly because of its floating-point Gaussian sampling. ML-DSA-87 is easier to make constant-time and has a more straightforward security argument.

QNSQY Business supports both, letting customers pick based on their constraints.

## Frequently Asked Questions

### Why is ML-DSA-87 needed if ML-DSA-65 is already strong?
ML-DSA-65 is Category 3 (AES-192-equivalent). ML-DSA-87 is Category 5 (AES-256-equivalent). For top-secret national security work, regulators want AES-256-grade protection across all primitives. ML-DSA-87 is the only Category 5 option in FIPS 204.

### How does ML-DSA-87 compare to RSA-15360?
RSA-15360 is a hypothetical RSA size that would match Category 5 classical strength but offers no quantum resistance. ML-DSA-87 is far stronger against quantum adversaries.

### Is ML-DSA-87 too slow for production use?
For application-level signing (documents, files, certificates), no. Sign and verify times under a millisecond support thousands of operations per second per core. Only ultra-high-volume TLS handshake signing or DKIM at internet scale would feel the cost.

### Can I downgrade from ML-DSA-87 to ML-DSA-65 later?
Technically yes, but verifiers must support both. QNSQY Business retains all algorithms simultaneously, so files signed at any parameter level remain verifiable. New files can use any supported level.

### How does ML-DSA-87 compare to SLH-DSA-256s for top-secret work?
SLH-DSA-256s is hash-based (NIST FIPS 205) and offers Category 5 security with a different hardness assumption. SLH-DSA-256s has 64-byte public keys but 29,792-byte signatures. ML-DSA-87 has 2592-byte public keys and 4595-byte signatures. SLH-DSA wins on public key size and on hardness diversity (hashes, not lattices); ML-DSA-87 wins on signature size and signing speed. CNSA 2.0 allows both.

## Sources

1. NIST FIPS 204, Module-Lattice-Based Digital Signature Standard (August 2024). [https://csrc.nist.gov/pubs/fips/204/final](https://csrc.nist.gov/pubs/fips/204/final)
2. NSA CNSA 2.0 Cybersecurity Advisory (September 2022). [https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF](https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF)
3. Bai, S. et al. "CRYSTALS-Dilithium Algorithm Specifications." NIST PQC Round 3 (2021). [https://pq-crystals.org/dilithium/data/dilithium-specification-round3-20210208.pdf](https://pq-crystals.org/dilithium/data/dilithium-specification-round3-20210208.pdf)
4. NIST FIPS 205, Stateless Hash-Based Digital Signature Standard (August 2024). [https://csrc.nist.gov/pubs/fips/205/final](https://csrc.nist.gov/pubs/fips/205/final)
5. NIST IR 8413, Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process (2022). [https://csrc.nist.gov/pubs/ir/8413/upd1/final](https://csrc.nist.gov/pubs/ir/8413/upd1/final)

## Related Articles

- [ML-DSA vs SLH-DSA](../mldsa-vs-slhdsa.html)
- [FN-DSA Falcon Explained](../fn-dsa-falcon-explained.html)
- [LMS Stateful Signatures](../lms-stateful-signatures.html)
- [Lattice-Based Cryptography Explained](../lattice-based-cryptography-explained.html)
- [NIST FIPS Guide](../nist-fips-guide.html)

---

### Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

[Try QNSQY](../../pricing.html)
