Research

Watch · narrated whiteboard episodesL3

Post-Quantum Signatures: Fiat-Shamir Lattices versus Hash Trees

NIST standardized two very different signature philosophies. Comparing ML-DSA and SLH-DSA side by side, plus the stateful hash-based schemes, reveals the real trade-space: assumptions, size, speed, and the one operational rule that must never break. Grounded in FIPS 204, FIPS 205, SP 800-208, and the RFCs.

Murali Chillakuru·5 episodes
  1. 19 min Episode 1What a Signature Must Guarantee: EUF-CMA and the Two Roads to ItA moderator and a cryptography expert establish what a digital signature actually promises — the three algorithms, the EUF-CMA security game, why strong unforgeability and adaptivity matter, and the two independent roads post-quantum signatures take.
  2. 19 min Episode 2ML-DSA: Fiat-Shamir with Aborts and the Transcript That Leaks NothingA moderator and a cryptography expert unpack the primary post-quantum signature standard — the identification protocol at its heart, the Fiat-Shamir transform that removes the verifier, why rejection sampling ('aborts') is essential, the two hard problems it rests on, and how determinism shapes deployment.
  3. 19 min Episode 3SLH-DSA: Signing from Hashing Alone, and the Hypertree That Buys StatelessnessA moderator and a cryptography expert build the maximum-trust post-quantum signature from the ground up — one-time signatures from hash chains, Merkle trees and the statefulness problem, how few-time keys and a hypertree buy statelessness, and the deliberate cost of that conservatism.
  4. 21 min Episode 4Stateful Hash-Based Signatures: XMSS, LMS, and the Rule That Must Never BreakA moderator and a cryptography expert examine the stateful hash-based signatures — a tree of one-time keys plus an index, the state rule that must never break, how state gets corrupted in practice, capacity and multi-trees, and exactly when their smaller signatures justify the operational discipline.
  5. 20 min Episode 5Choosing a Signature: A Decision Framework over Assumptions, Size, and Operational RiskIn the series finale, a moderator and a cryptography expert synthesize the post-quantum signature family into a practical decision — the four axes that matter, size-speed-role at a glance, a decision flow from context inward, hybrid signing during the transition, and concrete recommendations by role.