---
title: PQShield | NIST Announcement Special | July 22 Newsletter
---

Welcome to a special edition of the PQShield Newsletter, covering the announcement from NIST on Post-Quantum Cryptography standards...

| View in browser     GET IN TOUCH     NIST Special Newsletter   PQShield algorithms to be standardized as NIST announces the first international PQC standards July edition       A Highly Anticipated Moment: a New Era is Here!     5th July 2022, London, UK: The US National Institute of Standards and Technology (NIST) today announced the outcome of its post-quantum cryptography standardization project.   The new draft standards are all schemes contributed to by the advisory board and researchers at PQShield, who also advised on all other algorithms developed as part of the NIST standardisation process.   Specifically:  PQShield’s Dr Thomas Prest led and co-authored Falcon, a digital signature algorithm; PQShield’s Oussama Danba co-authored NTRU, a key encapsulation mechanism also shortlisted as a finalist; PQShield advisory board members Professor Peter Schwabe (Radboud University and the Max Planck Institute for Security and Privacy) and Professor Chris Peikert (University of Michigan) co-authored the finalists and alternates CRYSTALS-Dilithium, NTRU, SPHINCS+, Classic McEliece, CRYSTALS-KYBER, and FrodoKEM.    Of these, CRYSTALS-KYBER was today chosen by NIST as the new standard for public-key encryption/KEMs. Falcon, CRYSTALS-Dilithium and SPHINCS+ will all be standardized for digital signatures.    Read on for more detail...       Standardization News     In every newsletter we bring you the latest insight into the change or adoption of new security standards:   NIST ANNOUNCEMENT   After careful consideration during the 3rd Round of the NIST PQC Standardization Process, NIST has identified four candidate algorithms for standardization. The primary algorithms NIST recommends be implemented for most use cases are CRYSTALS-KYBER (key-establishment) and CRYSTALS-Dilithium (digital signatures).  In addition, the signature schemes Falcon and SPHINCS+ will also be standardized.   Algorithms to be Standardized   Public-Key Encryption/KEMs CRYSTALS-KYBER   Digital Signatures CRYSTALS-Dilithium Falcon SPHINCS+   CRYSTALS-KYBER (key-establishment) and CRYSTALS-Dilithium(digital signatures) were both selected for their strong security and excellent performance, and NIST expects them to work well in most applications. Falcon will also be standardized by NIST since there may be use cases for which CRYSTALS-Dilithium signatures are too large. Additionally, SPHINCS+ will be standardized to avoid only relying on the security of lattices for signatures. NIST asks for public feedback on a version of SPHINCS+ with a lower number of maximum signatures.   Additionally, the following candidate KEM algorithms will advance to the fourth round:   4th Round Candidates   Public-Key Encryption/KEMs BIKE Classic McEliece HQC SIKE   Both BIKE and HQC are based on structured codes, and either would be suitable as a general-purpose KEM that is not based on lattices. NIST expects to select at most one of these two candidates for standardization at the conclusion of the fourth round. SIKE remains an attractive candidate for standardization because of its small key and ciphertext sizes and will continue to study it in the fourth round. Classic McEliece was a finalist but is not being standardized by NIST at this time.  Although Classic McEliece is widely regarded as secure, NIST does not anticipate it being widely used due to its large public key size. NIST may choose to standardize Classic McEliece at the end of the fourth round.   For the algorithms moving on to the fourth round, NIST will allow the submission teams to provide updated specifications and implementations (“tweaks”). The deadline for these tweaks will be October 1, 2022. Any submission team that feels that they may not meet the deadline should contact NIST as soon as possible. NIST will review the proposed modifications and publish the accepted submissions shortly afterwards. As a general guideline, NIST expects any modifications to be relatively minor. The fourth round will proceed similarly to the previous rounds. More detailed information and guidance will be provided in another message.   A detailed description of the decision process and rationale for selection will be included in NIST Interagency or Internal Report (NISTIR) 8413, Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process, which will soon be available at https://csrc.nist.gov/publications and on the NIST post-quantum webpage https://nist.gov/pqcrypto. Questions may be directed to pqc-comments@nist.gov.   NIST will create new draft standards for the algorithms to be standardized and will coordinate with the submission teams to ensure that the standards comply with the specifications. As part of the drafting process, NIST will seek input on specific parameter sets to include, particularly for security category 1. When finished, the standards will be posted for public comment. After the close of the comment period, NIST will revise the draft standards as appropriate based on the feedback received. A final review, approval, and promulgation process will then follow.   NIST will hold a 4th NIST PQC Standardization Conference on November 29 – December 1, 2022. The conference details have not yet been finalized. The preliminary Call for Papers will be posted, both on the pqc-forum and the NIST PQC webpage http://nist.gov/pqcrypto.   NIST also plans to issue a new Call for Proposals for public-key (quantum-resistant) digital signature algorithms by the end of summer 2022. NIST is primarily looking to diversify its signature portfolio, so signature schemes that are not based on structured lattices are of greatest interest. NIST would like submissions for signature schemes that have short signatures and fast verification (e.g., UOV). Submissions in response to this call will be due by June 1, 2023. Submitters are encouraged to communicate with NIST ahead of time. NIST will decide which (if any) of the submitted signature algorithms to accept and will initiate a new process for evaluation. NIST expects this process to be much smaller in scope than the current PQC process. The signature schemes accepted to this process will need to be thoroughly analyzed, which will similarly take several years.    NIST would like to thank the community and all of the submission teams for their efforts in this standardization process and hopes that the teams whose schemes were not selected to advance will continue to participate by evaluating and analyzing the remaining cryptosystems alongside the cryptographic community at large. These combined efforts are crucial to the development of NIST’s future post-quantum public-key standards.   At PQShield we'll of course be updating our whitepapers and documentation in the coming days, plus analysing the full detail from NIST to provide you deeper insight. In the meantime please do not hesitate to get in touch! PQSHIELD Comments on the NIST announcement:   • Professor Peter Schwabe, PQShield advisory board member, says: “It is great to see the NIST post-quantum cryptography standardization effort come to a first conclusion today after months of anticipation. This has been a major effort for the international research community across both academia and industry, and the team at PQShield has been a big part of this.    “Since the standardization project began in 2016, there’s been a shift in attitudes towards PQC, and it is now understood as a critical part of a secure future. Now, it is going to be exciting to see more and more applications and systems transition to this next generation of asymmetric cryptography." • Dr Ali El Kaafarani, PQShield’s founder and CEO, says: “Today’s news marks a turning point in the fight for information security, thanks to a huge effort by NIST and the wider cryptography community.    “Previous cryptographic standards meant that the quantum threat touched everyone, with everything from medical records to national intelligence exposed to ‘harvest now, decrypt later’ attacks. NIST’s new Post-Quantum Cryptography (PQC) standards are a welcome arrival, and I am extremely proud of the team at PQShield for their intense efforts in helping to deliver these  - especially Thomas Prest and Peter Schwabe for having their own contributions chosen.    “But there’s no room for complacency. Across sectors, the race is now on to implement the new cryptographic defences, protecting data wherever it is vulnerable. Now, having actual standards to follow will help companies to put concrete transition roadmaps in place.”  • PQShield CEO, Ali El Kaafarani, added: “When it comes to defining PQC standards, the work doesn’t stop here. NIST also confirmed a fourth round today to further examine the alternate schemes BIKE, Classic McEliece, HQC and SIKE, and the team at PQShield will be in action again scrutinising these alongside the wider community.    “On top of this, NIST also announced a new Call for Proposals to diversify the signature schemes portfolio available - and no doubt our team will submit more candidates. We very much look forward to the road ahead as we collectively work towards a quantum-safe future.” Hardware and Software products today, that protect against tomorrow   • PQShield is an algorithm-agnostic vendor, offering size optimised and side-channel resistant implementations of all  relevant NIST PQC finalists in hardware and software, which meant it could support companies in their transition to quantum-readiness even before today’s standards were announced.  PQShield has already made a series of deals to introduce its quantum-ready cryptographic solutions to organisations across sectors, including a licensing deal with Microchip Technology and a collaboration with Collins Aerospace. • Our hybrid cryptographic library, PQCryptoLib, was also the first submitted to the NIST Cryptographic Module Validation Program for FIPS 140-3, the mandatory standard for the protection of data within US and Canadian federal systems. • The expert team at PQShield have delivered significant research that has not only fed into the emerging global standards for Post-Quantum Cryptography, but also into our own solutions and product portfolio: Hardware IP Software IP Research IP These can be combined into use case specific implementations for chips, applications or the cloud - download our brochure below to find out more.   DOWNLOAD OUR BROCHURE     Events News     Where has the team been speaking or exhibiting? Where will we be next?     A great RSA show, many visitors to our booth to find out the latest on topics like: Our FIPS 140-3 ready library, PQCryptolib Our hardware and software products,  Our work with NIST, RISC-V, GlobalPlatform and many other standards   We had a great week at IEEE Computer Society International Symposium on Hardware Oriented Security and Trust (HOST22).   Lots of people listened to our presentations and visited our booth to meet the PQShield team: Alan Grau, Freddie Hudson and Markku-Juhani Saarinen to find out the latest on PQC.     DAC 2022 is rapidly approaching and we’re excited to be exhibiting in-person again, especially now the standards are here!   Will we see you there on June 6th-9th?   Register here to get your conference pass.   As the year progresses, you’ll also find us at:   UK Semiconductors 22 in July   Microchip Mi-V Summit in July   ICMC in September   ...and many more!     READ ALL NEWS     Stay updated     You received this email because you are subscribed to updates from PQShield. To opt out, update your email preferences or unsubscribe View web version   PQShield, Head Office, Oxford, Oxfordshire, # PQShield, Head Office, Prama House, Oxford, Oxfordshire OX2 7HT, UK Unsubscribe Manage preferences |
| --- |