History

Timeline of scheme data updates and security events tracked on this site.

  1. Attack

    Key-recovery attack on SNOVA's biased vinegar sampling (Beullens & Hess, IBM Research, pqc-forum OFFICIAL COMMENT, paper to appear on ePrint): the round-3 signer draws vinegar variables by reducing uniform byte strings modulo q^g, which is never uniform when q is odd, so every signature yields noisy linear equations in the secret transformation T. Key recovery becomes a q-ary LPN problem with a known full-support error distribution, solved with BKW reduction plus Fourier hypothesis testing. This affects only the six odd-characteristic alternative parameter sets of Table 6 in the round-3 spec — (27 4 19 4 6), (27 5 13 4 4), (39 5 11 4 6), (38 5 19 4 6), (40 5 19 5 6) and (47 6 19 4 6) — all of which fall far below their claimed 170–331 bits (2^90–2^130 operations from ~6–11k signatures). Four were broken end to end against the unmodified reference implementation: 9M, 16.5M, 9M and 180M signatures recovered in 22s, 34s, 22s and 16min respectively (proof of concept). The recommended parameter sets shown here (SNOVA_{I,III,V}_{K,B,S}) use q = 16 and are unaffected, since 16^g divides 256^b exactly; no flags are changed for them. The fix is simple: sample the vinegar variables uniformly, e.g. by rejection sampling as QR-UOV does. The first version of the attack was found independently by an AI system (gpt-5.6-sol); the authors verified it, improved it and wrote it up.

    SNOVA

  2. Update

    SDitH round-3 update (v3.0.0, github.com/sdith/sdith): the VOLEitH-based construction gets minor signature-size growth across all six gf2 parameter sets (Category I short/fast: 3705→3721 / 4484→4914 bytes; III: 7964→8484 / 9916→10852; V: 14121→15147 / 17540→19144), public-key sizes unchanged. Sizes verified against the tag's kat_r3 KAT vectors. A separate CIPHERPOW build variant is also introduced but not yet tracked here.

    SDitH

  3. Update

    UOV round-3 parameter update (pqov/pqov): grows n at Levels I and III (Ip: n 112→119, m 44→45; III: n 184→193, m unchanged) and Level V (n 244→259, m unchanged), and adds a GFNI-optimized backend. Expanded-pk and signature sizes grow accordingly (compact-pk sizes are unchanged where m stayed fixed); Is (Level I, GF(16)) parameters are untouched. Not yet reflected on uovsig.org, which still serves the Feb-2025 round-2 package. Whether this fully re-addresses the intersection attack (Furue & Ikematsu, ePrint 2026/298) at the new parameter sizes has not been independently re-analyzed, so existing broken/warning flags are carried forward unchanged pending that analysis.

    UOV

  4. Update

    SQIsign 3.0 released as the third-round submission spec: parameters revised in response to the improved supersingular isogeny-problem algorithm (ePrint 2026/1486), and the reference implementation drops its GMP dependency for a from-scratch fixed-precision integer library. Public key and signature sizes grow (level I: 65/148 → 83/200 bytes; level III: 97/224 → 129/306; level V: 129/292 → 169/406 bytes). On our benchmark (v3.0 with its x86-64 assembly field arithmetic vs. the v2.0.1 reference build) signing is faster at levels I and III (−35% / −9%) but slower at level V (+12%), and verification is 12–38% slower at every level.

    SQIsign

  5. Update

    FAEST v3.0.0 released (release notes), the round-3 spec update. It restructures the VOLE-commitment construction around a new CRT-based scheme and, per issue #18, aligns the spec text for the first Fiat-Shamir challenge (chall_1) with what the implementation already computed (no forgery or key-recovery — a transcript-binding clarification). Signature sizes shrink by roughly 10–15% across all parameter sets (e.g. 128s: 4506→4066 bytes, 256f: 26548→20856 bytes); public-key sizes are unchanged. v2.0 is not broken, just superseded as the pinned round-3 submission.

    FAEST

  6. Update

    QR-UOV Round 3 submission (specification, github.com/qruov/round3): the parameter set list is cut from twelve to six, all with q = 127 — the q = 31 and q = 7 sets are dropped — and three new small-public-key sets with ℓ = 10 are added (I-(127 540 60 10), III-(127 820 90 10), V-(127 1040 110 10)), e.g. an 11,041-byte public key at Level I for a 541-byte signature. The secret key is now the 32-byte seed alone at every level, and signing rejects oil systems of rank below m − 2. A new AVX2 implementation (Amagasa, Ueno & Homma, TCHES 2026(2)) replaces the Round 2 avx2/avx512 code. Benchmarks here switch to that AVX2 implementation with the AES-based public-seed PRG (upstream's default), so the speedup over Round 2 combines the new implementation with the SHAKE→AES PRG change.

    QR-UOV

  7. Update

    SNOVA 3.0 (round-3 submission) reformulates the public map to support rectangular signature matrices, extending the scheme to seven parameters (v, o, q, l, r, m1, m2) and adding parameter sets over odd-characteristic fields. The recommended parameter sets (SNOVA_{I,III,V}_{K,B,S}) replace the previous v2.3 candidates; per the spec's security analysis (Tables 9–11), the Wedge product attack (Bros et al., ePrint 2026/237) that flagged several v2.3 parameter sets as broken/warning no longer applies to the reformulated public map. The “Expanded Secret Key” option is removed; only seeded secret keys remain.

    SNOVA

  8. Update

    MQOM v3.0 released (round-3 spec): adds a One-Tree (OT) BLC variant alongside the existing Correlated-Tree (CT) one (tighter security reduction to the MQ problem, similar sizes, less implementation-friendly), a new gf2-shorter variant, and drops the gf256 and three-round (*-r3) variants, leaving 18 parameter sets (3 tradeoffs × 2 BLC variants × 3 categories). Fixes the salt-less GGM root-expansion issue below (ePrint 2026/1542) via domain-separated root expansion, confirmed in the spec's changelog — the v2.1 warning is dropped for v3.0. Also expands F16 parameters for additional security margin and adds ARM NEON optimized implementations.

    MQOM

  9. Update

    MAYO published its round-3 spec (PDF): MAYO2's parameters change to increase its margin against the Wedge attack (Ran, ePrint 2025/1143), shrinking its public key from 4912B to 2928B while growing its signature from 186B to 239B; MAYO1 grows slightly (pk 1420→1456B, sig 454→464B) to push the improved-MQ attack (Asanuma et al., ePrint 2026/1054) margin back above the NIST Level I threshold — both flags are dropped for the round-3 parameter sets. Also adds an explicit linear term to the verification equation to block a newly disclosed claw-finding forgery attack, and fixes a low-rank weakness in the whipping schedule. MAYO3 and MAYO5 sizes are unchanged. The team also widened MAYO2's margin further in response to a new, not-yet-public UOV-like key-recovery attack privately disclosed by Lars Ran and Simon-Philipp Merz shortly before the deadline.

    MAYO

  10. Attack

    Passive full-key-recovery attack on MQOM v2 (Delgado, ePrint 2026/1542): the v2.x spec derives correlated GGM roots from a fresh master seed via a fixed, zero-salt PRG call (Algorithm 10), so repeated seeds across signatures, keys, and salts leak linear equations in the MQ witness. A parity-indexed XOR-collision attack recovers the complete signing key, but requires signature/query volumes at NIST's outer Q=2^64 permitted bound (~39% success in Category I) or substantial precomputation (tens of GiB–PiB of tables) to push higher; affects Categories I, III, and V, verified against every official tag from v2.0.0 through v2.1.1. Fix: salt-bound, domain-separated root expansion. v1.0 unaffected. Flagged as warning.

    MQOM

  11. Milestone

    The HAWK team withdrew HAWK from NIST's additional signature standardisation process, citing the key-recovery attack below: naïve fixes such as doubling parameters or moving to higher-rank modules make HAWK uncompetitive with other lattice signatures. NIST confirmed the withdrawal and updated the round-3 candidates page accordingly. pqc-forum announcement.

    HAWK

  12. Attack

    Deterministic key-recovery attack (Straznickas & Weis, Anthropic, paper) reduces HAWK-n key recovery to poly(n) calls to an exact-SVP oracle in dimension n/2+1, using a second Galois involution (τ: ζ↦−ζ) beyond the complex conjugation prior module-LIP attacks relied on. Lowers key-recovery cost from 2^150 to 2^108 gates (HAWK-512) and from 2^288 to 2^182 gates (HAWK-1024), both below their NIST level thresholds. The smaller HAWK-256 challenge parameter set was fully broken in practice: secret key recovered end-to-end in a few hours on a single 96-core server. Falcon is unaffected. Flagged as broken.

    HAWK

  13. Attack

    Improved algorithm for the supersingular isogeny problem (ePrint 2026/1486) achieves time/memory p^{1/3+o(1)}, down from the previous best p^{1/2}. Relies on an unproven heuristic smoothness assumption and has a superpolynomial overhead plus high memory cost; concrete impact on SQIsign's parameters not yet clarified. Flagged as warning.

    SQIsign

  14. Update

    Added SMAUG-T (finalist algorithm selected in Korea's KpqC competition) to the KEMs comparison page, with benchmarked keygen/encaps/decaps timings for SMAUG-T128, SMAUG-T192, and SMAUG-T256.

    SMAUG-T

  15. Update

    Added NTRU+ (finalist algorithm selected in Korea's KpqC competition) to the KEMs comparison page, with benchmarked keygen/encaps/decaps timings for NTRU+768, NTRU+864, and NTRU+1152.

    NTRU+

  16. Update

    Added SABER (NIST round-3 finalist, not selected) to the KEMs comparison page, with benchmarked keygen/encaps/decaps timings for LightSaber, Saber, and FireSaber.

    SABER

  17. Update

    Published a standalone KEMs comparison page — public-key and ciphertext sizes plus keygen/encaps/decaps benchmarks for ML-KEM, HQC, and classical ECDH.

  18. Attack

    Improved MQ attack (Asanuma, Chen, Furue, Sakata & Takagi, ePrint 2026/1054) reduces MAYO1 classical security estimate from 2^156 to 2^145. Still above NIST Level I threshold (128 bits); flagged as warning.

    MAYO

  19. Update

    Updated FAEST performance data to use the AVX2+AES-NI optimized implementation (faest-arch-opt) instead of the reference implementation. Signing is 10–100× faster depending on the parameter set.

    FAEST

  20. Update

    Updated SNOVA to v2.3 (2026-04-03). Split round-2 and round-3 data: round-3 now shows the 14 current parameter sets from the v2.3 spec (l=4 variants retained with warnings, new q=19 variants, rectangular 4×5 structure added per "Rectangular signatures" update).

    SNOVA

  21. Milestone

    NIST announced 9 Round 3 candidates for additional post-quantum signature schemes: FAEST, HAWK, MAYO, MQOM, QR-UOV, SDitH, SNOVA, SQIsign, UOV. Rationale in NIST IR 8610. Round 3 candidates.

    FAEST, HAWK, MAYO, MQOM, QR-UOV, SDitH, SNOVA, SQIsign, UOV

  22. Attack

    Updated UOV security flags based on pℓ-truncated polynomial ring intersection attack (Furue & Ikematsu, ePrint 2026/298). Improves on Ran's wedge attack for Ip (~128 bits), III (~182 bits), V (~223 bits). Is parameter sets newly flagged as warning (~159 bits, still above threshold).

    UOV

  23. Attack

    Updated UOV and MAYO security flags based on wedge attack (Ran, ePrint 2025/1143). MAYO-2 ("two") marked broken (~113 bits, below 128-bit threshold). UOV Ip, III, and V parameter sets marked with warning (reduced but still above threshold). UOV Is unaffected.

    UOV, MAYO

  24. Attack

    Updated SNOVA security flags based on wedge product attack (Bros et al., ePrint 2026/237). 6 parameter sets marked broken: (37 17 2), (25 8 3), (56 25 2), (24 5 5), (75 33 2), (29 6 5). 2 parameter sets marked with warning: (24 5 4), (37 8 4).

    SNOVA

  25. Update

    Updated 7 schemes to their latest published specifications. PERK redesigned parameter sets (v2.2.0). MQOM adds gf16 variants (v2.1). RYDE and Mirath corrected signature sizes and added faster variants. CROSS, SQIsign, and MAYO updated with revised benchmarks.

    CROSS, MAYO, MQOM, Mirath, PERK, RYDE, SQIsign

  26. Update

    Fixed some typos in scheme data. commit

  27. Update

    Website rewritten with SvelteKit, Tailwind CSS v4, and a new round selector, filter panel, and scatter plot.

Built by Thom Wiggers / PQShield. Data licensed under CC BY-SA 4.0. Most recent scheme data is dated 2026-09-08.

GitHub · eBACS: more comprehensive benchmarks on more platforms