LLMpediaThe first transparent, open encyclopedia generated by LLMs

CRYSTALS-Dilithium

Note: This article was automatically generated by a large language model (LLM) from purely parametric knowledge (no retrieval). It may contain inaccuracies or hallucinations. This encyclopedia is part of a research project currently under review.
Article Genealogy

This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.

CRYSTALS-Dilithium
NameCRYSTALS-Dilithium
Typepost-quantum digital signature
DesignersEric Persichetti, Vadim Lyubashevsky, Vadim Lyubashevsky (note: duplicate avoided), Thomas Prest, Nikita Lyubashevsky
Publish date2017
StandardNIST Post-Quantum Cryptography Standardization
RelatedCRYSTALS-Kyber, NTRU

CRYSTALS-Dilithium

CRYSTALS-Dilithium is a lattice-based post-quantum digital signature scheme originating from the CRYSTALS suite. It was developed to provide resistance against adversaries equipped with quantum computers and to offer practical performance for use in protocols and applications influenced by organizations such as Internet Engineering Task Force, European Union Agency for Cybersecurity, and National Institute of Standards and Technology. The scheme sits alongside other submissions to the NIST Post-Quantum Cryptography Standardization project including FALCON, SPHINCS+, and Round5.

Introduction

CRYSTALS-Dilithium combines design principles from lattice problems studied in the context of Learning with Errors and structured number-theoretic constructions used by schemes like NTRU and proposals from research groups at institutions such as EPFL, IBM Research, Microsoft Research, and Google. Its authors presented it at venues alongside submissions referenced by committees like IACR and conferences including CRYPTO, EUROCRYPT, and ASIACRYPT. The scheme targets deployment scenarios involving standards bodies such as IETF and agencies like NIST and ENISA.

Design and Algorithm

Dilithium's algorithm is built on module-lattice primitives derived from the Learning with Errors problem and uses rejection sampling with an inner-product relation similar in spirit to constructions evaluated in papers by researchers from MIT, UC Berkeley, ETH Zurich, and University of Waterloo. The signature generation and verification procedures reference operations on vectors and matrices of polynomials over rings reminiscent of those in NTRU and employ hash functions and randomness sources comparable to SHA-3 and constructions discussed at IETF meetings. Public-key, secret-key, and signature formats were designed with interoperability goals relevant to implementations by vendors like OpenSSL, SSH, and platforms such as Linux Kernel and Windows.

Security Properties and Proofs

Security reductions for Dilithium relate existential unforgeability under chosen message attack to hardness assumptions on module-LWE and short integer solutions studied in the literature associated with scholars from Tel Aviv University, University of Maryland, Princeton University, and Harvard University. Proof techniques draw on the random-oracle model and parallels to proofs used for lattice schemes discussed at TCC and FOCS. The scheme aims to balance worst-case to average-case reductions discussed in work from Centrum Wiskunde & Informatica and Technische Universität Darmstadt while addressing side-channel considerations analyzed by teams at NXP Semiconductors, ARM, and Intel.

Performance and Implementation

Implementations of Dilithium have been benchmarked in contexts relevant to TLS, SSH, and PGP integrations and compared against alternatives like FALCON and SPHINCS+ by groups at Google and Open Quantum Safe. Performance metrics include signature generation time, verification time, and public-key and signature sizes, with reference implementations optimized for platforms from ARM Cortex series, x86 Intel processors, and embedded systems from STMicroelectronics and Raspberry Pi Foundation. Optimizations leverage algorithmic techniques reported at USENIX Security and IEEE S&P and employ constant-time implementations to mitigate timing attacks studied by researchers at University of California, San Diego and TU Graz.

Standardization and Adoption

Dilithium advanced through rounds of the NIST Post-Quantum Cryptography Standardization process, influencing draft standards and interoperability test vectors adopted by consortia including IETF and stakeholders such as Mozilla, Cloudflare, Amazon Web Services, and Google Cloud Platform. Implementations and reference code have been contributed to projects like OpenSSL, LibreSSL, and BoringSSL, and integrated into toolchains maintained by organizations such as GitHub and Eclipse Foundation.

Attacks and Cryptanalysis

Cryptanalysis efforts have targeted Dilithium via both classical and quantum-capable techniques, with papers and break attempts disseminated at venues like IACR, Eurocrypt, and CRYPTO and by researchers from NCSA, CWI, INRIA, and Weizmann Institute of Science. Attack vectors studied include lattice-reduction strategies influenced by algorithms such as BKZ and LLL, side-channel leakage analyses similar to ones demonstrated for RSA and ECDSA by teams at KU Leuven and Ruhr University Bochum, and fault-injection scenarios examined by groups at TU Darmstadt and University of Bristol. Results have led to parameter adjustments and implementation guidelines advocated by NIST and labs such as Sandia National Laboratories.

Variants and Parameters

Dilithium specifies multiple security levels and parameter sets intended to align with equivalent classical strengths referenced by frameworks from NIST, ENISA, and ISO/IEC. Variants differ in modulus, lattice dimension, and rejection thresholds analogous to tunings discussed in works from Delft University of Technology and University of Technology Sydney. Implementers have proposed trade-offs and hardened parameter choices influenced by studies from NTU Singapore, KAUST, Seoul National University, and industry labs including Qualcomm Research.

Category:Post-quantum cryptography