Skip to content

Instantly share code, notes, and snippets.

@jedisct1
Last active September 21, 2026 07:55
Show Gist options
  • Select an option

  • Save jedisct1/c7ba25dbae1eb9fe9de23dc339748dd4 to your computer and use it in GitHub Desktop.

Select an option

Save jedisct1/c7ba25dbae1eb9fe9de23dc339748dd4 to your computer and use it in GitHub Desktop.

Round 1 candidates in China's next-generation commercial cryptography competition

China's Institute of Commercial Cryptography Standards (ICCS, 商用密码标准研究院) is running the NGCC competition to choose post-quantum algorithms to succeed SM2. The call for submissions opened in February 2025 and closed on June 30, 2026. The round 1 candidate list was published on September 20, 2026.

The public-key track has 34 digital signature candidates, 41 key encapsulation mechanisms (KEMs), and 9 key exchange candidates. This report covers the security assumptions and key, signature, and ciphertext sizes of the signature and KEM candidates. The key exchange candidates are listed in Appendix C.

Submission requirements

Each submission must support 128-bit, 256-bit, and 512-bit classical security, with at least 80-bit, 128-bit, and 256-bit quantum security, respectively. A 384-bit level is optional. These targets differ from NIST's five security categories, so the level names aren't directly comparable.

Each submission must provide one function: digital signatures, key encapsulation, or key exchange. Signature schemes must support messages of up to 2^63 bits and at least 2^64 signatures per key pair. For KEMs, the encapsulated key must be at least as long as the security level in bits.

The competition doesn't accept algorithms that are already standardized internationally, or variants that leave their core design unchanged. Many candidates nevertheless build on familiar designs, including ML-KEM, ML-DSA, SLH-DSA, HQC, BIKE, Classic McEliece, Falcon, UOV, and SQIsign.

Reading the tables

All sizes are in bytes. The summary tables show one parameter set per candidate, usually at the 128-bit classical security level. Appendix A lists all parameter sets, and Appendix B explains differences and missing information in the submissions.

The notes use pk, sk, ct, and ss for the public key, secret key, ciphertext, and shared secret. DFR means the decryption failure rate.

Secret key sizes need some care because submissions count them differently. Some give the size of a 16 to 72 byte seed, while others count an expanded key that may include a copy of the public key. The notes explain these conventions where the submission makes them clear.

Some schemes have variable-length signatures or ciphertexts. Their notes say whether the listed size is a maximum, an average, or a sample encoded length. Where a specification and its reference implementation disagree, the tables use the specification's value and the notes explain the difference.

Digital signatures

The 34 signature candidates include 11 lattice-based, 5 multivariate, 5 code-based, 4 hash-based, 4 based on symmetric primitives and MPC-in-the-head, and 3 based on isogenies. The remaining two use other problems.

Algorithm Hard problem Family Parameter set Public key Secret key Signature
Aigis-Sig+ Asymmetric Module-LWE + asymmetric Module-SIS lattice PARAMS I (Aigis-Sig+-I) 928 2,800 2,015
BIT Module-LWE + Module-SIS (bimodal SelfTargetMSIS) lattice BiT-128 1,048 1,864 1,504
CEDRUS+C Hash-based (preimage/collision resistance of the hash) hash CEDRUS+C-160s 40 80 9,460
CEDRUSɑ Hash-based (preimage/collision resistance of the hash) hash CEDRUSɑ-160s 40 80 10,300
Chinith VOLE-in-the-Head over block-cipher one-wayness symmetric/MPCitH SM4th-EM-d2-128s-lo 32 32 3,818
COMPASS-SIG Module-LWE + Module-SIS (SelfTargetMSIS_R / MISIS) lattice COMPASS-SIG-128 1,664 960 2,080
CS Module-LWE + Module-SIS lattice CS-128 976 1,888 1,548
DARTS Module-LWE + Module-SIS lattice DARTS-128 1,120 1,536 1,449
DOVE Multivariate quadratic (UOV with double vinegar) multivariate DOVE_pkc_skc_128 43,576 24 136
Facto-DSA Cubic MQ system solving + polynomial factorisation trapdoor multivariate Facto-DSA-128 40,040 3,094 40
FlexTree Hash-based (preimage/collision resistance of the hash) hash FlexTree-160s 40 80 9,580
Galas VOLE-in-the-Head over Gala OWF (F_2^lambda inversion) symmetric/MPCitH Galas-160S 40 20 4,812
GreatWall VOLE-in-the-Head over the Pylon OWF (preimage) symmetric/MPCitH GreatWall-128S 36 36 2,758
Lynxer VOLE-in-the-Head over the Lynx symmetric OWF symmetric/MPCitH Lynxer-160s 40 40 4,607
MORNING-ATLAS Module-LWR + Module-SIS lattice ATLAS-128 1,328 2,128 2,081
Octarine Radical Ring-LWR (Ring-LWR variant) + Ring/Module-SIS lattice Octarine-128 1,344 2,432 2,564
OPS Module-LWE + Module-SIS (SelfTargetMSIS) lattice Level-1 2,560 3,840 4,349
Origami Multivariate quadratic (hidden-partitioned UOV) multivariate Origami-128 2,996 16 116
Phoenix Hash-based (preimage/2nd-preimage/target collision) hash Phoenix-128s 32 64 6,258
Qing Luan MPC-in-the-Head over R-SDP (restricted syndrome dec.) code Qingluan-128 77 32 18,720
ReSolveD-ɑ VOLE-in-the-Head over Regular Syndrome Decoding code ReSolveD-α-160s 121 40 5,307
Rhyme Gram-Aided Module-LWE (GA-MLWE) + Module-SIS lattice Rhyme-128 800 11,072 1,483
Shuttle Module-LWE + Module-SIS lattice SUF-128 (SHUTTLE-128) 1,264 2,288 1,183
Sigurd VOLE-in-the-Head over Regular Syndrome Decoding code NGCC-128 (Sigurd-128) 112 80 25,108
SQIsign2D² Supersingular endomorphism ring problem isogeny Level1-eff 65 240 168
SQIsign2D-push^(1/2) Supersingular endomorphism ring problem isogeny Level-1 64 518 150
SQIsignTriangle Supersingular endomorphism ring problem isogeny lvl1 (lambda=128) 65 353 204
SYDO VOLE-in-the-Head over binary syndrome decoding code SYDO-160s 80 174 5,428
Tins MPCitH over Normalized Subfield Bilinear Collision other Tins-128 51 32 3,284
TRINE Trilinear Form Equivalence (tensor isomorphism) other Balanced TRINE-128 16,004 32 3,124
TSUOV Multivariate quadratic (UOV) + MinRank multivariate TSUOV 128 778 32 896
UVW signature Ternary syndrome decoding at large weight code UVW128 (Level 1) 5,897,612 40 1,244
VDOO Multivariate quadratic (UOV/Rainbow) + MinRank multivariate VDOO-128 330,855 232,145 85
YuanYang.DSA NTRU + Ring-SIS over NTRU lattices lattice YuanYang.DSA-512 738 15,584 561

Key encapsulation

Of the 41 KEM candidates, 25 are lattice-based, 15 are code-based, and one is based on isogenies.

Algorithm Hard problem Family Parameter set Public key Secret key Ciphertext
Aigis-Enc+ Asymmetric Ring-LWE (ARLWE) + semi-uniform-seed ARLWE lattice Aigis-Enc+-512 656 16 896
Amoeba Ring-LWE (non-power-of-two cyclotomic) + Hamming ECC lattice Amoeba-576 784 1,712 1,047
BAG-Loong Blended-block rank syndrome decoding / 2-BRSL (rank metric) code BAG-Loong-128 2,500 16 3,055
BAG-Piglet Ideal block rank syndrome decoding / support learning (IRSD, IRSL) code BAG-Piglet-128 522 16 1,011
BIKE-MLThre QC-MDPC syndrome decoding + quasi-cyclic codeword finding code BIKE_MLThre-128 1,541 281 1,573
BRA Ideal blockwise rank syndrome decoding (IBRSD) code BRA-128 1,078 98 2,092
BRQC Ideal Blockwise Rank Syndrome Decoding (IBRSD) code BRQC-128 1,954 112 3,844
BW-KEM Module-LWE (MLWE) lattice BW-KEM-c128 784 1,585 768
CheetahKEM Module-LWE (Ring-LWE at k=1) lattice Cheetah128 832 1,936 864
C-Multi-UR-AG Unstructured Rank Syndrome Decoding + Rank Support Learning code Level-128 3,866 94 7,332
COMPASS-KEM Module-LWR (prime modulus) + biased Module-LWR lattice COMPASS-KEM-128 (Level 1) 672 1,504 768
CTL NTRU + search Ring-LWR lattice CTL-128 (CTL-257-512) 521 2,953 473
DKEM Module-LWE (MLWE) lattice DKEM-128 800 1,600 800
DTRU NTRU + Ring-LWE lattice DTRU-Light 640 864 512
FLIT NTRU + Ring-LWE lattice Flit128 615 839 512
HARE Unbalanced quasi-cyclic syndrome decoding (UQCSD) code HARE-1 2,025 2,073 3,608
HEP-QC Equivalent Punctured Code + QC syndrome decoding code HEP-QC-1 285,889 285,969 4,433
LoongKEM Semi-structured LWE (SLWE) lattice Loong128 1,472 1,832 1,512
Lore CRT Module-LWR (Decision-CRT MLWR) lattice Lore-128 (Lore-L1) 545 821 641
MAMBA-Frost LWE (unstructured), via Learning With Quantization lattice Frost-128 5,152 6,736 5,192
MAMBA-Viper Module-LWE, via Module Learning With Quantization lattice MAMBA-Viper-128 608 1,424 736
Mithril Radical Ring-LWR (RR-LWR) lattice Mithril-128 944 1,136 928
Mito Quasi-dyadic (2^l-adic) syndrome decoding, Hamming metric code Mito1-E-128 3,720 3,864 5,512
MORNING-Scabbard Module-LWR (MLWR) lattice Scabbard-128 736 1,056 760
NEV NTRU + Ring-LWE (subset-sum parity RLWE) lattice NEV-C1* (NEV-C1-c, n=512, q=769, compressed) 615 1,246 512
NSS-HQC Quasi-cyclic syndrome decoding (Hamming) code NSS-HQC-128 3,713 3,777 5,185
NTRE NTRU + Ring-LWE (R-NTRU_eta, R-LWE_2eta) lattice NTRE-128 (NTRE-2593-648) 972 1,976 972
OAEP-NTRU NTRU + Ring-LWE lattice OAEP-NTRU-648 1,053 2,138 1,085
Polar-KEM Lattice Isomorphism Problem on polar lattices lattice PolarKEM-128 1,024 2,048 768
PolarLAC Module-LWE (with rejection sampling: MLWE_Rej) lattice PolarLAC-Light 530 1,570 608
QIMEN-PIKE Masked torsion-point supersingular isogeny problem isogeny NGCC-1 405 488 602
QCTM Quasi-cyclic twisted-Goppa (McEliece) decoding code QCTM128 167,987 192,545 640
QUBE Quasi-cyclic syndrome decoding, unbalanced multi-block code QUBE-128 3,294 3,326 3,287
Rudraksh2 Module-LWE lattice Rudraksh2-128-I 880 1,776 912
Scloud+ LWE (unstructured) lattice Scloud+-128 6,096 7,440 6,160
TRIKE Quasi-cyclic syndrome decoding (QC-MDPC) + RQCCF code TRIKE-1 1,304 4,220 2,592
TriQ-KEM Constrained-weight quasi-cyclic syndrome decoding code TriQ-KEM-128 2,054 2,102 4,086
UVW-KEM Decoding of generalized (U+V, U+W) codes over F_q code UVW128 208,013 35 1,032
Weaver Module-LWR + Shifted-MLWR lattice Weaver-640 752 1,776 816
YuanYang.KEM NTRU + Ring-LWE lattice YuanYang.KEM-512 736 1,536 656
ZEN NTRU + Ring-LWE (decisional) lattice ZEN-128 615 1,303 512

Assumptions in detail

Signatures

Aigis-Sig+

Aigis-Sig+ is the direct successor to Aigis-Sig and follows the Dilithium/ML-DSA Fiat-Shamir-with-aborts design. Key secrecy rests on AMLWE, a Module-LWE variant with two different error and secret widths, eta1 and eta2. Unforgeability rests on the infinity-norm AMSIS problem, a Module-SIS variant with asymmetric bounds beta1 and beta2. Both problems are defined over R_q = Z_q[X]/(X^512+1), with q = 4171777.

A C implementation with SHA3 and SM3 variants is available in OpenHiTLS PQCP.

BIT

BIT combines the ML-DSA/Dilithium Fiat-Shamir-with-aborts structure with BLISS-style bimodal rejection sampling and compression from NTRU+Sign. Key indistinguishability reduces to MLWE, while unforgeability reduces to MSIS / BimodalSelfTargetMSIS over R_q. The specification also describes an alternative based on decisional NTRU, but gives no parameter sets for it.

CEDRUS+C

CEDRUS+C is a stateless hash-based signature in the SPHINCS+/SLH-DSA family. It uses inhomogeneous WOTS_C one-time signatures and a FORS+C few-time signature. Its security rests only on the preimage, second-preimage, collision and PRF security of the SM3-derived hash and XOF used for F, H, PRF, T_l and H_MSG.

Reference and optimized C implementations are available for an earlier SHAKE-based version, whose parameters differ from the SM3-based candidate described here.

CEDRUSɑ

CEDRUSɑ follows the stateless SPHINCS+/SLH-DSA hash-based design, with inhomogeneous WOTS_alpha one-time signatures and a FORC (PORS-tree) few-time signature. Security rests only on the preimage, second-preimage, collision and PRF security of the SM3-derived hash and XOF used for F, H, PRF, T_l and H_MSG.

Reference and optimized C implementations are available for the SHA2, SHAKE, and Haraka versions, whose parameters differ from the SM3-based candidate described here.

Chinith

Chinith follows FAEST / FAEST-EM and uses VOLE-in-the-Head to prove knowledge of a block-cipher key k in zero knowledge. The relation is y = E_k(x), or y = E_x(k) XOR k for the Even-Mansour one-way function. It uses the Chinese block ciphers SM4, uBlock, Ballet and Vistrutah.

There is no structured or number-theoretic assumption. Security reduces to key recovery, one-wayness and PRP security of SM4, uBlock and Vistrutah, along with the ROM/QROM.

COMPASS-SIG

COMPASS-SIG modifies ML-DSA/Dilithium by removing the hint vector and compressing the public key more aggressively. Key recovery reduces to MLWE, and forgery reduces to inhomogeneous MSIS (MISIS) through a new SelfTargetMSIS_R assumption.

A refined Shell-MISIS / Shell-CVP analysis addresses the restricted-CVP structure of forgery vectors. The scheme works over R_q = Z_q[X]/(X^n+1), with n = 256 or 512.

CS

CS draws on ML-DSA/Dilithium and HAETAE, using bimodal Fiat-Shamir with aborts. Its security rests on decisional MLWE_{n,q,k,l,eta} for key recovery and on MSIS, including a bimodal BSTMSIS variant, for forgery. The underlying ring is Z_q[x]/(x^n+1).

DARTS

DARTS combines Dilithium/ML-DSA-style Fiat-Shamir with aborts and BLISS-style bimodal rejection sampling. Key recovery reduces to Module-LWE, and forgery reduces to Module-SIS over Z_q[x]/(x^n+1).

DOVE

DOVE is based on UOV (Unbalanced Oil and Vinegar), with pkc/skc compression in the style of UOV/MAYO. Security rests on DOVE-MQ, which asks for a solution to the public multivariate quadratic system built from a Double Vinegar x Vinegar UOV map over F_256. It also relies on the DOVE-UOV trapdoor-recovery problem, which asks for the hidden oil subspace.

Facto-DSA

Facto-DSA uses a multivariate/HFE-style trapdoor construction, with IP2 obfuscation as in traditional MQ schemes. It is not directly derived from an existing NIST candidate.

The inversion problem is a dense public system of homogeneous cubic equations over F_q, with q=65519. The trapdoor hides a quadratic map composed with polynomial multiplication in F_q[t], so inversion requires polynomial factorization. Recovering the structure is an Isomorphism-of-Polynomials (IP2) problem.

FlexTree

FlexTree generalizes the stateless SPHINCS+/SLH-DSA design to a hypertree whose layers can have different heights. It uses inhomogeneous WOTSC chains and PORS+FP few-time signatures, where FP stands for forced pruning.

Security reduces to preimage, second-preimage and collision resistance of the SM3-derived hash/XOF used for the WOTSC one-time signature, the XMSS/hypertree and PORS+FP.

Galas

Galas follows the FAEST VOLE-in-the-Head (VOLEitH) signature design, with Gala replacing AES as the underlying one-way function. The keyed function y = Gala_k(x) uses a wide-then-narrow construction, with four multiplicative inversions over F_{2^lambda} and public F_2-linear maps.

Security rests on Gala's one-wayness. A degree-3 QuickSilver constraint system provides authenticated checks inside VOLEitH, and Fiat-Shamir makes the proof non-interactive.

GreatWall

GreatWall uses FAEST-style VOLE-in-the-Head with one-tree BAVC and QuickSilver zero knowledge. Its dedicated symmetric one-way function, Pylon, works over F_2^n and combines an inverse-Mersenne power map with random dense linear layers and nested feed-forward.

EUF-CMA security reduces to Pylon's preimage resistance, or one-wayness, through a VOLE-in-the-Head/Fiat-Shamir NIZK in the (Q)ROM. No algebraic public-key assumption is used.

The earlier GreatWall implementation uses a different proof system and parameter sets.

Lynxer

Lynxer follows FAEST/VOLE-in-the-Head with Half-Tree BAVC and QuickSilver, and is comparable to Rainier/AIMer. Its symmetric primitive, Lynx, is designed for VOLEitH and works over F_2^lambda. It uses Kasami-type power maps and an extended truncation function with interleaved random linear layers.

Security rests only on Lynx's one-wayness, with one-time pseudorandomness also needed for the QROM/QICM proof. There is no structured public-key assumption.

Reference and optimized implementations are available, although their parameter sets differ from those listed here.

MORNING-ATLAS

MORNING-ATLAS follows the CRYSTALS-Dilithium/ML-DSA Fiat-Shamir-with-aborts design, replacing LWE with Saber-style LWR rounding. Key recovery rests on decisional Module Learning With Rounding, with power-of-two q and p and deterministic rounding error. Unforgeability rests on Module-SIS / SelfTargetMSIS.

Octarine

Octarine takes the CRYSTALS-Dilithium/ML-DSA Fiat-Shamir-with-aborts structure to the Mithril (ARCANE) radical ring:

S_{q,n,k} = (Z_q[y]/(y^n+1))[x]/(x^k-y-2) ~ Z_q[x]/((x^k-2)^n+1).

Key recovery reduces to RR-LWR, a Ring-LWR problem with coefficient-wise rounding in the transported monomial basis and power-of-two q and p. The rounding follows Saber/MLWRSign, and unforgeability reduces to the corresponding SIS problem.

NXP's C reference implementation covers all three security levels.

OPS

OPS is a CRYSTALS-Dilithium/ML-DSA variant with a different modulus, n=512/1024, 64-byte seeds and compressed hint encoding. It uses Fiat-Shamir with aborts over R_q = Z_q[X]/(X^n+1), with q = 2^26-2^12+1. Key recovery reduces to decisional MLWE, while strong unforgeability reduces to MSIS and SelfTargetMSIS in the (Q)ROM.

Origami

Origami reorganizes UOV into partitioned local zones, with a compact public key made of a seed and a residual part. Security rests on multi-target MQ inversion (MT-MQ) of the published, flattened quadratic map over F_16.

It also relies on the HP-OV hidden-structure indistinguishability assumption. This says that, after dense input and output mixing, the partitioned local Oil-and-Vinegar trapdoor is indistinguishable from a random MQ map.

Phoenix

Phoenix is a stateless signature based on the SPHINCS+/SLH-DSA hypertree. It adds a GWOTS+C one-time scheme and Transposed FORS with Octopus compression.

EU-CMA security reduces to one-wayness, second-preimage resistance, interleaved target-subset resilience and target-collision resistance of the tweakable hash, instantiated with SM3 or SHAKE. There is no structured number-theoretic assumption.

Qing Luan

Qing Luan is a CROSS-RSDP variant that uses SM3 and salted/eTCR commitments. Security reduces to the Restricted Syndrome Decoding Problem: given a random parity-check matrix H over F_p, with p=127, and a syndrome s, find e such that eH^T = s. Every coordinate of e must lie in the multiplicative subgroup E = <g> of order z, so e_i^z = 1.

An MPC-in-the-Head 5-pass Sigma protocol proves knowledge of the solution in zero knowledge, and Fiat-Shamir makes it non-interactive.

ReSolveD-ɑ

ReSolveD-ɑ follows ReSolveD and the FAEST-style VOLE-in-the-Head approach, using QuickSilver and BAVC. Its TCCR comes from AES/SHACAL-2, Keccak or NGCC SM3 pseudoXOF.

The one-way function is Regular Syndrome Decoding over F_2. The task is to find a weight-w noise vector that matches the public syndrome of a random [m,k] code and is split into w equal blocks of size l_bs = 6, with exactly one 1 per block. Knowledge of this RSD solution is proved with a QuickSilver/VOLE-in-the-Head NIZK made non-interactive by Fiat-Shamir.

Rhyme

Rhyme is a new design in the Dilithium/ML-DSA Fiat-Shamir family that borrows Hawk's Gram-matrix/module-LIP idea. It replaces rejection sampling with Convolution of Constant Count Sampling (3C) and compresses signatures with rANS.

EU-CMA security rests on a new Gram-Aided Module-LWE assumption. This assumes that Module-LWE remains pseudorandom even when an adversary receives a (sub)Gram matrix of a short unimodular matrix whose first column encodes the secret. The assumption is related to the module Lattice Isomorphism Problem used in Hawk, but is strictly weaker. Strong unforgeability also relies on Module-SIS.

The Rhyme-SHAKE repository includes reference and optimized C implementations of a revised construction, which differs from the submission described here.

Shuttle

Shuttle combines the ML-DSA/CRYSTALS-Dilithium assumptions with Gaertner's compact iterative Fiat-Shamir framework, deliberately avoiding the NTWE assumption. It uses asymmetric structural compression and a rejection-free iterative Gaussian sampler.

The Fiat-Shamir-with-aborts signature works over R_q = Z_q[X]/(X^n+1). Public-key pseudorandomness and zero knowledge rest on Module-LWE, while strong unforgeability rests on Module-SIS, the same assumptions as ML-DSA/Dilithium.

Sigurd

Sigurd uses a FAEST-style VOLE-in-the-Head system, replacing the GGM tree and SoftSpokenOT layer with a Reed-Solomon / DEEP-FRI vector commitment. A DEEP-quotient proof handles linear relations.

EUF-CMA security in the ROM reduces to Regular Syndrome Decoding over F_2, along with collision resistance of the hash. The decoding task is to recover e from y = He, where e is split into n = m/B blocks of size B = 6, each with Hamming weight exactly 1.

SQIsign2D²

SQIsign2D² belongs to the SQIsignHD family and builds on SQIsign / SQIsign2D-East. Security reduces to the Supersingular Endomorphism Problem: given a supersingular curve E/F_p^2, find a non-scalar, efficiently evaluable endomorphism. It also needs a zero-knowledge assumption about the distribution of auxiliary isogenies.

The prime has the form p = f*2^a*3^b - 1. The scheme uses both 2- and 3-power isogenies, along with dimension-2 (2,2)-isogenies.

A Julia implementation is available for the paper's NIST level 1, 3, and 5 parameter sets, which differ from the NGCC sets listed here.

SQIsign2D-push^(1/2)

SQIsign2D-push^(1/2) builds on Nakagawa-Onuki's SQIsign2DPush and the SQIsign v2.0.1 code base. A Sigma protocol proves knowledge of the endomorphism ring of a supersingular elliptic curve, and Fiat-Shamir makes it non-interactive. Hardness rests on the isogeny-path / endomorphism-ring problem for supersingular curves over F_p^2, with p = c*2^e1*3^e2 - 1.

SQIsignTriangle

SQIsignTriangle inherits its parameter sets and precomputation from the SQIsign v2 specification. EUF-CMA security is proved under the hardness of computing the endomorphism ring of a supersingular elliptic curve, equivalently the One Endomorphism Problem. Its Sigma protocol uses a prime-degree triangle challenge and dimension-2 (2,2)-isogenies over F_p^2, with p = c*2^f - 1.

The C and SageMath implementations currently use 192-, 288-, and 384-bit parameter sets, which differ from those listed here.

SYDO

SYDO uses the SDitH/FAEST VOLE-in-the-Head approach, with new syndrome-decoding modeling rather than a parameter change to either scheme. It proves knowledge of a low-weight solution x to Hx = y for a random binary parity-check matrix H in zero knowledge, then applies Fiat-Shamir to make the proof non-interactive. Regular syndrome decoding is used only as a modeling device, with a proved reduction back to unstructured binary SD.

Tins

Tins follows the Huth-Joux MPCitH/VOLEitH NSBC signatures and uses the Threshold-Computation-in-the-Head (TCitH) framework. SDitH, Mirath, RYDE and FAEST are points of comparison. It applies Fiat-Shamir to a proof of knowledge for Huth-Joux's Normalized Subfield Bilinear Collision problem.

Given u-hat and v-hat in F_{q^k}^n, the task is to find alpha and beta in F_q^{n-2} such that:

(<u,alpha>+u_{n-2})(<v,beta>+v_{n-1}) = (<u,beta>+u_{n-1})(<v,alpha>+v_{n-2}).

TRINE

TRINE belongs to the same family as ALTEQ (ATFE), MEDS (matrix code equivalence) and LESS, and uses the corank-one technique of Narayanan-Qiao-Tang. Given two trilinear forms phi, psi: F_q^n x F_q^n x F_q^n -> F_q known to be equivalent, the problem is to find A,B,C in GL(n,q) with psi = phi^{A,B,C}. A GMW-style Sigma identification protocol uses corank-one invariants, and Fiat-Shamir makes it non-interactive.

TSUOV

TSUOV is a tensor-structured UOV scheme that generalizes MAYO, QR-UOV and SNOVA. Its security rests on the MQ and MinRank problems for a UOV public map whose matrices are built from Kronecker, or tensor, products. This construction unifies the tensor structures used by those three schemes.

A SageMath implementation is available in the SNOVA repository. It uses SHAKE rather than the candidate's SM3 backend.

UVW signature

The UVW signature extends Wave with generalized (U+V, U+W) codes over F3. It relies on Computational Syndrome Decoding in the hard high-weight regime, where w is far above the Gilbert-Varshamov / easy interval. It also needs the GDP assumption that the generalized (U+V, U+W) parity-check matrices are indistinguishable from random ones, and DOOM for multi-target forgery.

VDOO

VDOO builds on UOV/Rainbow, adding a d-variable diagonal layer before two oil layers. The MQ problem concerns this layered oil-and-vinegar trapdoor, with one diagonal layer and two UOV layers. Concrete security is set by the simple MQ-solving attack, rectangular MinRank and rank attacks, and intersection and band-separation attacks.

YuanYang.DSA

YuanYang.DSA follows Falcon, Mitaka and Antrag with a DLP-style NTRU hash-and-sign design, an annular trapdoor and a hybrid sampler. In this GPV construction, key recovery is the NTRU search/decision problem for h = g/f mod q. Forgery reduces to t-R-ISIS, or ring inhomogeneous SIS relative to the NTRU trapdoor generator, and concrete security is estimated with core-SVP.

Key encapsulation

Aigis-Enc+

Aigis-Enc+ succeeds Aigis-Enc, a Kyber/ML-KEM-style asymmetric-MLWE KEM. It uses NEV-inspired 4-dimensional lattice plaintext encoding, q=3329 and the same fixed dimension-128 partial NTT as Kyber.

IND-CPA security of the underlying PKE is proved under decisional asymmetric Ring-LWE, ARLWE_{n,q,eta1,eta2}, with the secret and error drawn from two different centered-binomial distributions. It also relies on semi-ARLWE, a semi-uniform-seed variant in which the public ring element a is expanded from a short seed. An FO transform with implicit rejection produces the KEM, with proofs in both the ROM and QROM.

An ARM implementation is available in OpenHiTLS PQCP.

Amoeba

Amoeba follows the Kyber/NewHope Ring-LWE KEM design, with Nussbaumer + NTT multiplication over a cyclotomic ring whose degree is not a power of two. It uses a LAC-style error-correcting code, specifically an extended Hamming code [523,512], to lower the decryption-failure rate.

Security rests on decisional non-dual Ring-LWE over the m-th cyclotomic field, with elliptic-Gaussian/centered-binomial error. The ring has degree 288, q=3457 and k=2..8 blocks, giving ring dimensions of 576..2304. An FO transform provides IND-CCA2 security.

BAG-Loong

BAG-Loong builds on the rank-metric KEM Loong and the RQC/ROLLO approach to ideal rank-metric codes. It uses augmented Gabidulin codes G+_g as the decodable auxiliary code.

IND-CPA security reduces to two decisional 2-BRSL (blended-block rank support learning) instances. This generalizes rank syndrome decoding to error blocks with overlapping F_q-supports, described by a support-intersection matrix. An FO transform with implicit rejection gives the IND-CCA2 KEM.

BAG-Piglet

BAG-Piglet follows Piglet-1 / RQC-Block-MS-AG, in the ROLLO/RQC family of ideal-code rank-metric KEMs. Its decodable auxiliary code is an augmented Gabidulin code G+_g(n*n1, n', k, m).

IND-CPA security reduces to decisional (3,1)-IRSD and (4,2)-IRSL: pairwise-block ideal rank syndrome decoding and ideal rank support learning over F_{q^m}, with disjoint-support block errors. An FO transform with implicit rejection provides IND-CCA2 security.

BIKE-MLThre

BIKE-MLThre is based on the BIKE QC-MDPC KEM. Its 128-bit and 256-bit instances reuse the BIKE Level-1 and Level-5 reference parameters, and it also has an experimental 512-bit instance.

Recovering the constant-weight error pair from c0 = e0 + e1*h rests on quasi-cyclic syndrome decoding (QCSD). Recovering the sparse private pair (h0,h1) from h = h1*h0^-1 in F2[X]/(X^r-1) rests on quasi-cyclic codeword finding (QCCF). The machine-learning threshold selector in the BGF decoder adds no new hardness assumption.

BRA

BRA stands for Blockwise RQC with AG codes. It modifies RQC by replacing Gabidulin codes with augmented Gabidulin codes and homogeneous errors with blockwise errors. A Welch-Berlekamp-like algorithm decodes the AG codes during decryption.

IND-CCA2 security is tightly reduced to two decisional ideal blockwise rank syndrome decoding (IBRSD) assumptions over F_{q^m}, in the ring R = F_{q^m}[X]/<P(X)>. The error is split into blocks with independent F_q-supports, as in a sum-rank error model.

BRQC

BRQC, or Blockwise RQC, derives from the NIST PQC candidate RQC (Rank Quasi-Cyclic). IND-CCA2 security reduces to decisional ideal blockwise rank syndrome decoding, a blockwise-error variant of RSD/RD in the rank metric over GF(2^m). Gabidulin codes are used only for decoding.

BW-KEM

BW-KEM uses the ML-KEM/Kyber structure, including q=3329 and its NTT arithmetic. It replaces direct modulation with a scalable nested Barnes-Wall lattice code for error correction. An FO variant converts the MLWE-based IND-CPA PKE into an IND-CCA KEM.

CheetahKEM

CheetahKEM combines the Kyber/ML-KEM structure with NTRU-style decryption and shift-only compression. The IND-CPA PKE underlying this IND-CCA KEM reduces to decisional MLWE over Z_q[X]/(X^640+1), with q=7681. Cheetah128, the k=1 parameter set, is a Ring-LWE instance.

C-Multi-UR-AG

C-Multi-UR-AG means Compact Multi-UR-AG and derives from Multi-UR-AG, or Multiple-syndromes Unstructured RQC with Augmented Gabidulin codes (IEEE TIT 2024). IND-CCA2 security rests on random, unstructured Rank Syndrome Decoding (RSD) and Rank Support Learning (RSL) over GF(2^m). Augmented Gabidulin codes, decoded with a Berlekamp-Welch-like algorithm, are used only to encode and decode messages.

COMPASS-KEM

COMPASS-KEM follows the Lindner-Peikert/ML-KEM module-lattice approach and uses SABER-style rounding, with NTT-friendly prime moduli. IND-CPA security of its PKE reduces to decisional MLWR with prime moduli and a biased MLWR variant introduced by ciphertext compression. The FO transform gives IND-CCA security in the (Q)ROM.

CTL

CTL, short for Chase the Light (逐光), combines NTRU/Falcon-style trapdoor key generation with Ring-LWR encryption. Because key generation uses an NTRU trapdoor basis, key recovery rests on the NTRU assumption. Encapsulation uses Ring Learning With Rounding, with deterministic rounding and ciphertext compression.

DKEM

DKEM's CPA core, DKE, is a Ding-style reconciliation key exchange using the ML-KEM/Kyber ring, modulus and noise parameters. It works over Rq = Zq[X]/(X^n+1), and its IND-CPA security reduces to decisional Module-LWE. A tag-based Fujisaki-Okamoto transform with implicit rejection gives IND-CCA security.

Reference and Cortex-M4 implementations are available in NGCCM4.

DTRU

DTRU applies the Fujisaki-Okamoto transform to an NTRU-based PKE to obtain an IND-CCA KEM. It uses NEV-style vector decoding, extended with double-E8 / extended-Hamming [8,4] encoding.

Security rests on decisional NTRU and Ring-LWE over the tricyclotomic ring Zq[x]/(x^n - x^(n/2) + 1). There is also an LPPNF variant over Zq[x]/(x^n - x - 1) and a power-of-two cyclotomic variant.

An independent C implementation follows the paper version, whose parameter sets differ from this submission.

FLIT

FLIT builds an IND-CCA2 KEM by applying the FO transform to an NTRU-style PKE with c = h*r + e + ((q+1)/2)*Encode(m). Security is proved from decisional Ring-LWE and decisional NTRU. NEV-style vector decoding and repetition, or homomorphic, encoding suppress decryption failure.

HARE

HARE follows HQC, using a concatenated shortened Reed-Solomon / Reed-Muller code and a [51,41]_2 Kaikkonen-Rosendahl covering code for ciphertext compression. IND-CPA security rests on decisional unbalanced quasi-cyclic syndrome decoding, UQCSD(n, w0, w1), which the specification reduces to ordinary s-QCSD. FO/HHK with implicit rejection provides IND-CCA security.

HEP-QC

HEP-QC uses HQC's concatenated Reed-Solomon/Reed-Muller codes and FO transform with implicit rejection. It adds McEliece-style code-equivalence and puncturing masks. It hides the generator matrix as G = (T G')_tau.

Recovering the private key (T, tau) is the NP-complete Equivalent Punctured Code (EPC) problem. Message recovery rests on decisional 2- and 3-quasi-cyclic syndrome decoding, the same problems used in HQC.

LoongKEM

LoongKEM uses a Regev/Kyber-style CPA PKE with an FO transform. Its public matrix A = [[M_A1, M_A2],[M_A3, A4]] mixes structured blocks with a fully unstructured Zq block. The structured blocks are matrices of polynomials in Zq[X]/(X^N+1), with deliberately small N = 12..24.

Security rests on the authors' semi-structured LWE assumption. The design sits between FrodoKEM's plain, unstructured LWE and Kyber/ML-KEM's Module-LWE.

Lore

Lore follows the Kyber/ML-KEM module-lattice LPR KEM design, with LWR rounding, CRT compression and BCH/repetition error correction. IND-CPA security reduces to a Chinese-Remainder-Theorem variant of decisional Module Learning With Rounding over R_tq = Z_tq[x]/(x^n+1), where q = 257 and t is a small power of two. The specification further reduces this variant to standard MLWR/MLWE.

A C reference implementation is available on GitHub.

MAMBA-Frost

MAMBA-Frost follows the FrodoKEM/SCloud+ approach to unstructured-LWE KEMs, replacing explicit error sampling with public dithered quantization and using an E8 lattice code. Security rests on plain, unstructured Learning With Quantization (LWQ). The specification gives a tight reduction from this formulation to standard unstructured LWE with an explicitly characterized noise distribution.

MAMBA-Viper

MAMBA-Viper draws on ML-KEM/Kyber and Saber, with public dithered quantization and an E8 lattice code. It is based on Module Learning With Quantization (MLWQ) over R_q = Z_q[x]/(x^256+1), with power-of-two q.

The specification maps MLWQ directly to standard MLWE through an explicit error correspondence. Here the quantization uses public dither, unlike MLWR, whose rounding error depends on the secret.

Mithril

Mithril follows Saber's KEM structure, including power-of-two moduli, LWR rounding and the FO transform. It replaces Module-LWR with Radical Ring Learning With Rounding (RR-LWR).

This Ring-LWR variant works over a radical number field S_{q,n,k} with coefficient-wise rounding. It is intended as an alternative to Module-LWR that still allows flexible parameter scaling through k.

NXP's C reference implementation covers all three security levels.

Mito

Mito generalizes HQC's Hamming-metric design from quasi-cyclic codes to 2^l-adic/dyadic algebras over F_2, using codes with a quasi-dyadic structure. It uses concatenated duplicated-Reed-Muller and shortened-Reed-Solomon decoding.

Security reduces to decisional syndrome decoding with parity and truncation for linear codes with this algebraic structure. These assumptions generalize HQC's quasi-cyclic DQCSD-P / DQCSD-PT assumptions, with concrete hardness set by ISD cost.

MORNING-Scabbard

MORNING-Scabbard draws on Saber, the Scabbard suite (Florete-Espada-Sable) and Rudraksh. It uses an MLWR-based Saber-style PKE with an FO transform.

IND-CCA2 security rests on Module Learning With Rounding over Z_q[x]/(x^n+1), with power-of-two moduli q > p > t. Errors come from deterministic rounding rather than explicit sampling.

NEV

NEV is an FO-transformed NTRU KEM based on NTRU Encryption with Vector decoding (Asiacrypt 2023). Security rests on decisional NTRU over Z_q[x]/(x^n+1), with h = g/f and f = v*f'+1, together with Ring-LWE. The vector-decoding plaintext encoding also uses a new subset-sum parity RLWE variant, sspRLWE.

OpenHiTLS PQCP includes a C implementation of all twelve parameter sets, with SM3 and SHA3 variants.

NSS-HQC

NSS-HQC reduces HQC's bandwidth through ciphertext quantization and soft-information decoding with Reed-Solomon and duplicated codes. IND-CCA2 security reduces to the decisional quasi-cyclic syndrome decoding (DQCSD) family in the Hamming metric, exactly as in HQC. The additional quantization step is explicitly not treated as a source of hardness.

NTRE

NTRE belongs to the NTRU, NTRU+ and NTRU-A family, with an FO-style PKE-to-KEM transform and SM3/KDF-SM3 symmetric primitives. IND-CCA2 security of NTRE.CCAKEM rests on the R-NTRU_eta and R-LWE_2eta assumptions over R_q = Z_q[X]/(X^n - X^(n/2) + 1).

OAEP-NTRU

OAEP-NTRU uses NTRU with a new OAEP-dagger transform in place of Fujisaki-Okamoto, and is compared against Kyber and NTRU+. Security relies on the NTRU assumption that h = g*(p*f'+1)^-1 is indistinguishable from uniform. It also relies on computational and decisional Ring-LWE over R = Z_q[X]/(X^n - X^(n/2) + 1).

Polar-KEM

Polar-KEM uses LIP-based cryptography and Construction-D polar lattices, with an FO transform and implicit rejection. It shares a methodology with HAWK, but is explicitly not a HAWK analogue.

Its polar-LIP assumption says that, given a basis of O*Lambda for a random polar lattice Lambda and a random orthogonal matrix O, it is hard to recover any isometry. Decryption uses successive-cancellation decoding in the secret, easy-to-decode polar lattice.

PolarLAC

PolarLAC moves LAC from Ring-LWE to Module-LWE and replaces BCH/D2 error correction with polar codes and soft-decision SC decoding. Security rests on MLWE_Rej over R_q = Z_q[x]/(x^n+1), where frequency-domain rejection sampling filters the samples. The specification gives a polynomial-time reduction from standard Module-LWE to MLWE_Rej.

A C implementation is available, but its current secret-key encoding differs from the one summarized here.

QIMEN-PIKE

QIMEN-PIKE builds on PIKE, which in turn builds on POKE, and its implementation derives from the SQIsign C library. Security rests on a masked supersingular isogeny problem with torsion-point information, specifically the images of a torsion basis masked by the group Gamma. The specification bounds this problem above by the supersingular endomorphism-ring problem.

QCTM

QCTM draws on Classic McEliece and BIG QUAKE (quasi-cyclic Goppa), with twisted Goppa codes. Security relies on syndrome decoding of a quasi-cyclic twisted binary Goppa code. It also assumes that the hybrid systematic public matrix is indistinguishable from a random matrix, hiding the twisted-Goppa structure.

QUBE

QUBE generalizes HQC to multiple blocks and unbalanced blockwise error weights. IND-CPA security reduces to computational and decisional (s,t)-QCSD problems, a (3,1)/(3,2)-index generalization of the quasi-cyclic syndrome decoding problems underlying HQC.

Rudraksh2

Rudraksh2 is a lightweight successor to Rudraksh that follows the Kyber/ML-KEM Module-LWE design. Security of its IND-CPA PKE rests on Module-LWE with centered-binomial secrets and Kyber-style ciphertext compression. The FO transform gives an IND-CCA2 KEM.

Scloud+

Scloud+ is the direct successor to Scloud and Scloud+-SSR, following FrodoKEM's unstructured-LWE approach. The IND-CPA PKE relies on plain LWE, with Bernoulli-Difference ternary secrets and noise, and uses Barnes-Wall lattice coding for error correction. An FO transform with implicit rejection produces the IND-CCA2 KEM.

The Scloud+ repository includes reference and optimized C implementations for all five security levels.

TRIKE

TRIKE combines BIKE's QC-MDPC bit-flipping approach with ideas from HQC, using index-3 quasi-cyclic codes. Security reduces to (2,3)-Quasi-Cyclic Syndrome Decoding and a new Ratio Quasi-Cyclic Codeword Finding (RQCCF) problem. RQCCF in turn reduces to the well-studied 3-QCCF (quasi-cyclic codeword finding) problem. Decoding uses a BIKE-style bit-flipping decoder.

TriQ-KEM

TriQ-KEM follows HQC, with an RS+RM concatenated (RSRM) decoder and the FO transform with implicit rejection. Key recovery is a 2-CW-QCSD instance over binary quasi-cyclic codes in the Hamming metric. Recovering ciphertext randomness is a 3-CW-QCSD instance conditioned on bounded density.

UVW-KEM

UVW-KEM follows the Classic McEliece approach and the (U+V, U+W) PKE of Yang-Zhang (ePrint 2025/1149), which generalizes the (U, U+V) construction. The codes are built from Reed-Solomon codes and decoded with the Guruswami-Sudan list decoder.

Security rests on general/syndrome decoding (GD/SD) over F_q, along with a code-distinguishing (CD) assumption for the generalized (U+V, U+W) construction.

Weaver

Weaver follows Kyber/ML-KEM with an NTT-friendly prime-modulus module lattice and an FO transform with implicit rejection. It uses BCH and 4-way repetition error correction.

Security rests on decisional Module Learning With Rounding over Z_q[X]/(X^n+1), plus a Shifted-MLWR variant introduced to justify the embed-then-round ciphertext. A randomized lifting map keeps the decompressed public key uniform, and the design targets MLWE-to-MLWR reductions.

YuanYang.KEM

YuanYang.KEM uses NTRU encryption with Gaussian-sampled f,g, and shares its key pair with the companion signature YuanYang.DSA. The public key h = g/f is an NTRU instance over Z_q[X]/(X^d+1), while the ciphertext mask hs+e is a Ring-LWE instance. Concrete security is estimated against the best NTRU key-recovery and Ring-LWE message-recovery attacks in the Core-SVP model.

ZEN

ZEN derives from DAWN's zero-divisor-encoded NTRU construction and belongs to the NTRU/NEV family. Security rests on decisional NTRU, which asks whether h = g*f^-1 is distinguishable from uniform in Z_q[X]/(X^n+1), and on decisional Ring-LWE for the encryption mask. Messages use DAWN-style zero-divisor double encoding with x^(n/2)+1 and x^(n/4)+1.

Reference and Cortex-M4 implementations are available in NGCCM4.

Appendix A: parameter sets

Signatures

Aigis-Sig+

Parameter set Claimed level Public key Secret key Signature
PARAMS I (Aigis-Sig+-I) >=128-bit classical / >=80-bit quantum 928 2,800 2,015
PARAMS II (Aigis-Sig+-II) >=256-bit classical / >=128-bit quantum 1,824 4,976 4,533
PARAMS III (Aigis-Sig+-III) >=512-bit classical / >=256-bit quantum 4,672 8,800 9,134

PARAMS I (Aigis-Sig+-I) has a secret key of the form rho//K//tr//s1//s2//t0, so it contains tr = CRH(pk) but not the full public key. The signature size is the maximum because the hint encoding has a variable length. The specification does not list the secret-key size.

PARAMS II (Aigis-Sig+-II) lists the maximum packed signature size.

PARAMS III (Aigis-Sig+-III) lists the maximum packed signature size.

BIT

Parameter set Claimed level Public key Secret key Signature
BiT-128 128-bit (Core-SVP: MLWE 129 classical / 118 quantum; MSIS SUF 128) 1,048 1,864 1,504
BiT-256 256-bit (Core-SVP: MLWE 256 classical / 234 quantum; MSIS SUF 256) 2,144 4,160 3,456
BiT-512 512-bit (Core-SVP: MLWE 512 classical / 465 quantum; MSIS SUF 512) 5,056 9,024 6,695
BiT-192 192-bit (Core-SVP: MLWE 192 classical / 176 quantum; MSIS SUF 192) 1,293 Not stated 2,242
BiT-384 384-bit (Core-SVP: MLWE 392 classical / 359 quantum; MSIS SUF 384) 2,435 Not stated 5,251
BiT-80 80-bit (Core-SVP: MLWE 101 classical / 93 quantum; MSIS SUF 80) 505 Not stated 1,057

BiT-128 uses q=26881, d=256, (n,m)=(3,3). The secret key has the form seed//b1//seed//tr//(s0,e)//b0 and includes the packed public key b1 and tr = H(pk).

BiT-256 uses q=119297, d=512, (n,m)=(3,3).

BiT-512 uses q=520193, d=1024, (n,m)=(3,3).

BiT-192 uses d=1024, (n,m)=(1,1), q=15361. No secret-key size is stated, and no implementation is included.

BiT-384 uses d=2048, (n,m)=(1,1), q=40961. No secret-key size is stated, and no implementation is included.

BiT-80 uses d=512, (n,m)=(1,1), q=3329. No secret-key size is stated, and no implementation is included. Only BiT-128, BiT-256, and BiT-512 have implementations.

CEDRUS+C

Parameter set Claimed level Public key Secret key Signature
CEDRUS+C-160s 160-bit classical / 80-bit quantum 40 80 9,460
CEDRUS+C-160f 160-bit classical / 80-bit quantum 40 80 19,812
CEDRUS+C-256s 256-bit classical / 128-bit quantum 64 128 24,104
CEDRUS+C-256f 256-bit classical / 128-bit quantum 64 128 43,548
CEDRUS+C-384s 384-bit classical / 192-bit quantum 96 192 61,572
CEDRUS+C-384f 384-bit classical / 192-bit quantum 96 192 75,988
CEDRUS+C-512s 512-bit classical / 256-bit quantum 128 256 98,212
CEDRUS+C-512f 512-bit classical / 256-bit quantum 128 256 121,520

CEDRUS+C-160s uses n=20, h=67, d=9, a=12, k=13. The public key is 2n = (PK.seed, PK.root), and the secret key is 2n + pk = 4n, so it includes the public key.

CEDRUS+C-160f uses n=20, h=66, d=17, a=7, k=30. The f variant is optimized for speed.

CEDRUS+C-256s uses n=32, h=65, d=9, a=13, k=22.

CEDRUS+C-256f uses n=32, h=66, d=14, a=8, k=44.

CEDRUS+C-384s uses n=48, h=67, d=8, a=13, k=33.

CEDRUS+C-384f uses n=48, h=64, d=12, a=10, k=55.

CEDRUS+C-512s uses n=64, h=65, d=8, a=14, k=44.

CEDRUS+C-512f uses n=64, h=67, d=11, a=11, k=59.

CEDRUSɑ

Parameter set Claimed level Public key Secret key Signature
CEDRUSɑ-160s 160-bit classical / 80-bit quantum 40 80 10,300
CEDRUSɑ-160f 160-bit classical / 80-bit quantum 40 80 19,420
CEDRUSɑ-256s 256-bit classical / 128-bit quantum 64 128 25,568
CEDRUSɑ-256f 256-bit classical / 128-bit quantum 64 128 43,296
CEDRUSɑ-384s 384-bit classical / 192-bit quantum 96 192 60,672
CEDRUSɑ-384f 384-bit classical / 192-bit quantum 96 192 76,176
CEDRUSɑ-512s 512-bit classical / 256-bit quantum 128 256 98,048
CEDRUSɑ-512f 512-bit classical / 256-bit quantum 128 256 127,488

CEDRUSɑ-160s uses n=20, h=68, d=9, a=10, k=16, len=30. The public key is 2n = (PK.seed, PK.root), and the secret key is 2n + pk = 4n, so it includes the public key.

CEDRUSɑ-160f uses n=20, h=66, d=17, a=7, k=28, len=40.

CEDRUSɑ-256s uses n=32, h=67, d=9, a=12, k=23, len=48.

CEDRUSɑ-256f uses n=32, h=65, d=14, a=8, k=45, len=63.

CEDRUSɑ-384s uses n=48, h=65, d=8, a=12, k=38, len=88.

CEDRUSɑ-384f uses n=48, h=65, d=12, a=10, k=51, len=80.

CEDRUSɑ-512s uses n=64, h=65, d=8, a=13, k=47, len=101.

CEDRUSɑ-512f uses n=64, h=66, d=11, a=10, k=66, len=109.

Chinith

Parameter set Claimed level Public key Secret key Signature
SM4th-EM-d2-128s-lo 128-bit classical / 80-bit quantum (loose) 32 32 3,818
SM4th-EM-d2-128f-lo 128-bit classical / 80-bit quantum (loose) 32 32 4,932
SM4th-d3-128s-lo 128-bit classical / 80-bit quantum (loose, multi-key interpretation of Qsig=2^80) 32 32 5,056
SM4th-d3-128f-lo 128-bit classical / 80-bit quantum (loose) 32 32 6,724
SM4th-EM-d2-128s-ti 128-bit classical / 80-bit quantum (tight) 32 32 7,556
SM4th-d3-128s-ti 128-bit classical / 80-bit quantum (tight, single-key Qsig=2^80) 32 32 9,176
SM4th-EM-d2-128f-ti 128-bit classical / 80-bit quantum (tight) 32 32 9,450
SM4th-d3-128f-ti 128-bit classical / 80-bit quantum (tight) 32 32 11,864
uBlockith-EM-d3-256s 256-bit classical / 128-bit quantum 64 64 19,056
uBlockith-d3-256s 256-bit classical / 128-bit quantum 64 64 24,144
uBlockith-EM-d3-256f 256-bit classical / 128-bit quantum 64 64 25,028
uBlockith-d3-256f 256-bit classical / 128-bit quantum 64 64 31,556
Vistrutith-d3-512s 512-bit classical / 256-bit quantum 128 128 83,004
Vistrutith-d3-512f 512-bit classical / 256-bit quantum 128 128 106,788

SM4th-EM-d2-128s-lo uses an Even-Mansour one-way function with ell=1024, tau=11, d=2. It has the smallest signature in the family.

SM4th-EM-d2-128f-lo uses an Even-Mansour one-way function with tau=16, d=2.

SM4th-d3-128s-lo has pk = (x,y) = 2*lambda bits = 32 B and sk = (x,k) = 2*lambda bits = 32 B. The other parameters are lambda_F=128, ell=1808, tau=11, d=3.

SM4th-d3-128f-lo uses tau=16, T_open=110.

SM4th-EM-d2-128s-ti uses Even-Mansour with tau=14, d=2.

SM4th-d3-128s-ti is the tight variant, with lambda_F=160 and lambda_iv=256. It uses Ballet as its PRG.

SM4th-EM-d2-128f-ti uses Even-Mansour with tau=21, d=2.

SM4th-d3-128f-ti uses tau=21, T_open=138.

uBlockith-EM-d3-256s uses Even-Mansour uBlock with ell=3072, tau=22.

uBlockith-d3-256s uses the uBlock one-way function with lambda_F=256, ell=4608, tau=22, d=3.

uBlockith-EM-d3-256f uses Even-Mansour uBlock with tau=32.

uBlockith-d3-256f uses tau=32, T_open=246.

Vistrutith-d3-512s uses the Vistrutah one-way function with lambda_F=512, ell=6912, tau=44, w_grind=5.

Vistrutith-d3-512f uses the Vistrutah one-way function with tau=64, w_grind=8.

COMPASS-SIG

Parameter set Claimed level Public key Secret key Signature
COMPASS-SIG-128 128 bits 1,664 960 2,080
COMPASS-SIG-256 256 bits 3,616 2,144 4,080
COMPASS-SIG-384 384 bits 5,792 3,136 7,344
COMPASS-SIG-512 512 bits 7,648 4,608 9,024

COMPASS-SIG-128 uses q=2081281, n=256, (k,l)=(3,4), d=4, gamma1=2^15, tau=30. The secret key consists of two seeds, a 64-byte tr, and s + e + t0. It stores tr = H(pk) but not the full public key. The signature has no hint vector: it contains only the 32-byte c_tilde and z.

COMPASS-SIG-256 uses q=2081281, n=256, (k,l)=(7,7), d=5, gamma1=2^17, tau=60, c_tilde=48 B.

COMPASS-SIG-384 uses q=8380417, n=512, (k,l)=(5,6), d=5, gamma1=2^18, tau=78, c_tilde=48 B.

COMPASS-SIG-512 uses q=8380417, n=512, (k,l)=(7,7), gamma1=2^19, tau=120, c_tilde=64 B. The specification gives d=5, but the implementation uses D=6. The public- and secret-key sizes in the specification work only with d=6, which suggests that d=5 is a typo.

CS

Parameter set Claimed level Public key Secret key Signature
CS-128 ~128-bit classical core-SVP (primal 131.4 classical / 115.3 quantum) 976 1,888 1,548
CS-256 ~256-bit classical core-SVP (primal 285.6 classical / 250.7 quantum) 1,760 3,968 3,164
CS-512 ~512-bit classical core-SVP (primal 518.9 classical / 455.5 quantum) 4,288 7,808 5,975

CS-128 uses n=256, q=32257, (k,l)=(3,3). The public key consists of a 16-byte seed and the compressed t1.

CS-256 uses n=512, q=64513, (k,l)=(3,3).

CS-512 uses n=512, q=64513, (k,l)=(6,5).

DARTS

Parameter set Claimed level Public key Secret key Signature
DARTS-128 128 bits (SIS core-SVP 137 classical / 120 quantum) 1,120 1,536 1,449
DARTS-256 256 bits (SIS core-SVP 261 classical / 230 quantum) 2,208 2,880 2,489
DARTS-512 512 bits (SIS core-SVP 535 classical / 470 quantum) 4,672 6,016 5,851

DARTS-128 uses n=512, q=130817, (k,l)=(1,2), d=10. The secret key includes the public key. The signature is entropy-coded, so its length varies. The table gives its maximum size, including the maximum encoded payload.

DARTS-256 uses n=512, q=130817, (k,l)=(2,3), d=9. The secret key includes the public key. The table gives the maximum signature size.

DARTS-512 uses n=1024, q=260609, (k,l)=(2,3), d=10. The secret key includes the public key. The table gives the maximum signature size.

DOVE

Parameter set Claimed level Public key Secret key Signature
DOVE_pkc_skc_128 ICCS level 1 / 128-bit classical (80-bit quantum) 43,576 24 136
DOVE_classic_128 ICCS level 1 / 128-bit classical (80-bit quantum); best attack 128 bits (Wedge-Intersection) 191,646 192,990 136
DOVE_pkc_skc_256 ICCS level 2 / 256-bit classical (128-bit quantum) 446,992 40 296
DOVE_classic_256 ICCS level 2 / 256-bit classical (128-bit quantum); best attack 263 bits 2,050,352 1,925,976 296
DOVE_pkc_skc_512 ICCS level 3 / 512-bit classical (256-bit quantum) 5,062,192 72 648
DOVE_classic_512 ICCS level 3 / 512-bit classical (256-bit quantum); best attack 522 bits 22,833,052 20,181,508 648

DOVE_pkc_skc_128 is the compressed variant. The secret key is just the 24-byte master seed sk_seed, while the public key has size pk_seed_bytes(16) + ceil(m*o(o+1)/2 * r/8) = 16 + 43560.

DOVE_classic_128 uses o=m=44, n=112, q=256 and a 24-byte salt. The classic variant stores the fully expanded public and secret keys.

DOVE_pkc_skc_256 uses a 40-byte seed as its secret key.

DOVE_classic_256 uses o=m=96, n=256, q=256 and a 40-byte salt.

DOVE_pkc_skc_512 uses a 72-byte seed as its secret key.

DOVE_classic_512 uses o=m=216, n=576, q=256 and a 72-byte salt.

Facto-DSA

Parameter set Claimed level Public key Secret key Signature
Facto-DSA-128 128-bit classical target / 80-bit quantum target 40,040 3,094 40
Facto-DSA-256 256-bit classical target / 128-bit quantum target 456,960 11,662 68
Facto-DSA-512 512-bit classical target / 256-bit quantum target 5,674,240 61,922 128

Facto-DSA-128 uses q=65519, n=10, r=20, D=19, m=13, s=6, Rmax=512. The public key has size 2m*C(r+2,3) = 2*13*1540 = 40040 bytes, and the signature has a fixed size of 2r bytes. The secret key includes a 32-byte public-key digest.

Facto-DSA-256 uses q=65519, n=17, r=34, D=33, m=32, s=1, Rmax=1024. The public key has size 2*32*C(36,3) = 456960 bytes.

Facto-DSA-512 uses q=65519, n=32, r=64, D=63, m=62, s=1, Rmax=2048. The public key has size 2*62*C(66,3) = 5674240 bytes.

FlexTree

Parameter set Claimed level Public key Secret key Signature
FlexTree-160s 160-bit classical / 80-bit quantum (NICCS Category I) 40 80 9,580
FlexTree-160f 160-bit classical / 80-bit quantum (NICCS Category I) 40 80 18,672
FlexTree-256s 256-bit classical / 128-bit quantum (NICCS Category II) 64 128 25,420
FlexTree-256f 256-bit classical / 128-bit quantum (NICCS Category II) 64 128 46,856
FlexTree-384s 384-bit classical / 192-bit quantum (optional NICCS level) 96 192 60,180
FlexTree-384f 384-bit classical / 192-bit quantum (optional NICCS level) 96 192 73,396
FlexTree-512s 512-bit classical / 256-bit quantum (NICCS Category III) 128 256 94,948
FlexTree-512f 512-bit classical / 256-bit quantum (NICCS Category III) 128 256 117,296

FlexTree-160s uses n=20, h=67, d=9, t=42429, k=15, mMAX=160, len=26. The public key has size 2n, and the secret key has size 4n = 2n + pk. The signature length is fixed because the octopus opening is padded with zeros to mMAX*n.

FlexTree-160f uses n=20, h=67, d=17, t=4721, k=27, mMAX=155, len=40.

FlexTree-256s uses n=32, h=67, d=10, t=81271, k=25, mMAX=280, len=42.

FlexTree-256f uses n=32, h=68, d=17, t=16900, k=35, mMAX=270, len=64.

FlexTree-384s uses n=48, h=67, d=8, t=250491, k=35, mMAX=398, len=94.

FlexTree-384f uses n=48, h=64, d=12, t=71828, k=53, mMAX=486, len=77.

FlexTree-512s uses n=64, h=66, d=8, t=429271, k=48, mMAX=560, len=101.

FlexTree-512f uses n=64, h=66, d=11, t=181922, k=57, mMAX=586, len=102.

Galas

Parameter set Claimed level Public key Secret key Signature
Galas-160S 128-bit classical / 80-bit quantum (field size lambda=160) 40 20 4,812
Galas-160F 128-bit classical / 80-bit quantum (field size lambda=160) 40 20 5,964
Galas-256S 256-bit classical / 128-bit quantum (lambda=256) 64 32 12,114
Galas-256F 256-bit classical / 128-bit quantum (lambda=256) 64 32 15,950
Galas-384S 384-bit classical / 192-bit quantum (lambda=384) 96 48 27,784
Galas-384F 384-bit classical / 192-bit quantum (lambda=384) 96 48 33,384
Galas-512S 512-bit classical / 256-bit quantum (lambda=512) 128 64 49,516
Galas-512F 512-bit classical / 256-bit quantum (lambda=512) 128 64 59,416

Galas-160S uses tau=14, w_grind=7, Topen=132, ktree=11. The public key is x//y, or 2*lambda bits, and the secret key is k, or lambda bits. The signature length is fixed because the BAVC opening is padded to Topen seed slots.

Galas-160F uses tau=20, w_grind=8, Topen=144, ktree=8. The F profile is faster but has a larger signature.

Galas-256S uses tau=21, w_grind=7, Topen=218, ktree=12.

Galas-256F uses tau=35, w_grind=12, Topen=232, ktree=7.

Galas-384S uses tau=32, w_grind=6, Topen=336, ktree=12.

Galas-384F uses tau=48, w_grind=6, Topen=332, ktree=8.

Galas-512S uses tau=42, w_grind=8, Topen=456, ktree=13.

Galas-512F uses tau=64, w_grind=6, Topen=445, ktree=8.

GreatWall

Parameter set Claimed level Public key Secret key Signature
GreatWall-128S additional variant (128-bit classical / 68-bit quantum; initially labeled Level 1) 36 36 2,758
GreatWall-128F additional variant (128-bit classical / 68-bit quantum) 36 36 3,396
GreatWall-192S NGCC Level 1 (192-bit classical / 80-bit quantum) 50 50 6,804
GreatWall-192F NGCC Level 1 (192-bit classical / 80-bit quantum) 50 50 8,012
GreatWall-256S NGCC Level 2 (256-bit classical / 128-bit quantum) 66 66 12,236
GreatWall-256F NGCC Level 2 (256-bit classical / 128-bit quantum) 66 66 14,260
GreatWall-512S NGCC Level 3 (512-bit classical / 256-bit quantum) 132 132 50,012
GreatWall-512F NGCC Level 3 (512-bit classical / 256-bit quantum) 132 132 57,812

GreatWall-128S uses Pylon-128 with n=137 and (tau,w,T_open)=(11,7,100). The S profile has shorter signatures. The public key is (iv_owf, ct), with size 2*ceil(137/8) bytes. The specification does not list secret-key sizes; the table uses the implementation sizes.

GreatWall-128F uses (tau,w,T_open)=(16,8,108). The F profile signs and verifies faster.

GreatWall-192S uses Pylon-192 with n=197 and (tau,w,T_open)=(16,8,183).

GreatWall-192F uses (tau,w,T_open)=(24,8,184).

GreatWall-256S uses Pylon-256 with n=263 and (tau,w,T_open)=(22,6,246).

GreatWall-256F uses (tau,w,T_open)=(32,7,248).

GreatWall-512S uses Pylon-512 with n=521 and (tau,w,T_open)=(44,0,512).

GreatWall-512F uses (tau,w,T_open)=(64,0,512).

Lynxer

Parameter set Claimed level Public key Secret key Signature
Lynxer-160s 128-bit classical / 80-bit quantum NGCC level (targeted conservatively as 160-bit classical Lynx) 40 40 4,607
Lynxer-160f 128-bit classical / 80-bit quantum NGCC level 40 40 5,801
Lynxer-256s 256-bit classical / 128-bit quantum 64 64 12,191
Lynxer-256f 256-bit classical / 128-bit quantum 64 64 15,097
Lynxer-384s 384-bit classical / 192-bit quantum (optional NGCC level) 96 96 27,495
Lynxer-384f 384-bit classical / 192-bit quantum 96 96 34,109
Lynxer-512s 512-bit classical / 256-bit quantum 128 128 48,879
Lynxer-512f 512-bit classical / 256-bit quantum 128 128 61,091

Lynxer-160s uses lambda=160, tau=14, w_grind=6, T_open=129. The 40-byte secret-key size comes from the implementation. The public key is iv_owf//ct, with size 2*20 bytes.

Lynxer-160f uses tau=21, w_grind=8, T_open=139 and is optimized for speed.

Lynxer-256s uses lambda=256, tau=22, w_grind=12, T_open=224.

Lynxer-256f uses tau=35, w_grind=8, T_open=223.

Lynxer-384s uses lambda=384, tau=34, w_grind=10, T_open=332.

Lynxer-384f uses tau=53, w_grind=9, T_open=336.

Lynxer-512s uses lambda=512, tau=46, w_grind=6, T_open=439.

Lynxer-512f uses tau=72, w_grind=8, T_open=447.

MORNING-ATLAS

Parameter set Claimed level Public key Secret key Signature
ATLAS-128 128-bit classical / 80-bit quantum 1,328 2,128 2,081
ATLAS-192 192-bit classical / 96-bit quantum 2,112 3,152 3,365
ATLAS-256 256-bit classical / 128-bit quantum 2,848 4,016 4,656
ATLAS-512 512-bit classical / 256-bit quantum 6,688 7,920 10,081
ATLAS-384 (optional, unimplemented) 384-bit classical (optional NGCC level) Not stated Not stated Not stated

ATLAS-128 uses n=128, (q,p)=(2^23,2^18), (k,l)=(9,6), eta=16, kappa=31, pkdrop=10.

ATLAS-192 uses n=128, (q,p)=(2^23,2^19), (k,l)=(13,10), eta=8, kappa=69. The specification agrees with the parameter definitions, but the optimized API gives a 3,056-byte secret key and a 3,496-byte signature.

ATLAS-256 uses n=256, (q,p)=(2^23,2^20), (k,l)=(8,7), eta=4, kappa=60. The specification agrees with the parameter definitions, but the optimized API gives a 5,552-byte secret key.

ATLAS-512 uses n=512, (q,p)=(2^25,2^22), (k,l)=(8,7), eta=4, kappa=60.

ATLAS-384 (optional, unimplemented) has no implementation or stated key and signature sizes. The specification gives only security estimates and the lattice parameters n=256, k=13, l=10, q=2^25, p=2^21, eta=8, kappa=133, omega=168.

Octarine

Parameter set Claimed level Public key Secret key Signature
Octarine-128 128-bit classical / >=80-bit quantum 1,344 2,432 2,564
Octarine-256 256-bit classical / >=128-bit quantum 2,368 4,608 5,449
Octarine-512 512-bit classical / >=256-bit quantum 5,184 11,776 14,713

Octarine-128 uses n=1024, k=1, log2 q=24, log2 p=21, eta=4, d=11, tau=16, gamma1=2^18, gamma2=2^17, omega=79. The size formulas are pk=64+(log2 p-d)kn/8, sk=256+(2log2(2eta)+d)kn/8, and sig=lambda/4+log2(2gamma1)kn/8+10(omega+k)/8.

Octarine-256 uses n=1024, k=2, log2 p=22, eta=2, d=13, tau=36, gamma1=2^19, gamma2=2^18, omega=210.

Octarine-512 uses n=1024, k=5, log2 p=22, eta=2, d=14, tau=87, gamma1=2^21, gamma2=2^20, omega=399.

OPS

Parameter set Claimed level Public key Secret key Signature
Level-1 Level-1 (128-bit classical / 80-bit quantum) 2,560 3,840 4,349
Level-3 Level-3 (256-bit classical / 128-bit quantum) 3,392 5,056 5,540
Level-5 Level-5 (512-bit classical / 256-bit quantum) 6,720 9,920 12,021

Level-1 uses n=512, q=67104769, (k,l)=(3,3), eta=2, gamma1=2^21, gamma2=(q-1)/32, d=13, tau=39, omega=80. The secret key stores (rho, tr, s1, s2, t0), while the public key is (rho, t1).

Level-3 uses n=512, (k,l)=(4,4), eta=3, gamma1=2^20, gamma2=(q-1)/96, tau=45, omega=85, ctilde=64 B.

Level-5 uses n=1024, (k,l)=(4,4), eta=2, gamma1=2^22, gamma2=(q-1)/48, tau=90, omega=90, ctilde=128 B.

Origami

Parameter set Claimed level Public key Secret key Signature
Origami-128 128-bit classical / 64-bit quantum 2,996 16 116
Origami-256 256-bit classical / 128-bit quantum 14,968 32 516
Origami-384 384-bit classical / 192-bit quantum 27,940 48 948
Origami-512 512-bit classical / 256-bit quantum 35,924 64 1,220

Origami-128 uses q=16, (d,k)=(3,2), (N,M)=(200,104), mu_red=49, with 16-byte seeds and salt. The secret key is a 16-byte master seed. The public key contains a 4-byte param_id, a 16-byte seed_pk, and a 2,976-byte residual R_pk. The signature size is ceil(N/2) + salt. The specification uses KB to mean 1,000 bytes, so its 2.996 KB public key is 2,996 bytes.

Origami-256 uses (d,k)=(6,5), (N,M)=(968,488) and /I_res/=29864, giving a 14,932-byte R_pk. The seeds and salt are 32 bytes, and the secret key is a seed.

Origami-384 uses (d,k)=(8,7), (N,M)=(1800,904) and a 27,888-byte R_pk. The seeds and salt are 48 bytes.

Origami-512 uses (d,k)=(9,8), (N,M)=(2312,1160) and a 35,856-byte R_pk. The seeds and salt are 64 bytes.

Phoenix

Parameter set Claimed level Public key Secret key Signature
Phoenix-128s 128-bit classical / 64-bit quantum (NGCC target: toy example) 32 64 6,258
Phoenix-128f 128-bit classical / 64-bit quantum (NGCC target: toy example) 32 64 13,670
Phoenix-192s 192-bit classical / 96-bit quantum (NGCC-128) 48 96 13,356
Phoenix-192f 192-bit classical / 96-bit quantum (NGCC-128) 48 96 30,766
Phoenix-256s 256-bit classical / 128-bit quantum (NGCC-256) 64 128 24,618
Phoenix-256f 256-bit classical / 128-bit quantum (NGCC-256) 64 128 44,906
Phoenix-384s 384-bit classical / 192-bit quantum (NGCC-384) 96 192 54,726
Phoenix-384f 384-bit classical / 192-bit quantum (NGCC-384) 96 192 88,442
Phoenix-512s 512-bit classical / 256-bit quantum (NGCC-512) 128 256 98,476
Phoenix-512f 512-bit classical / 256-bit quantum (NGCC-512) 128 256 138,454

Phoenix-128s uses n=16, h=70, d=10, a=9, k=14, k'=16. The public key is 2n=(PK.seed,PK.root), and the secret key is 4n=(SK.seed,SK.prf,PK.seed,PK.root), so it includes the public key. The signature length varies because it uses Octopus-compressed TFORS and GWOTS+C counters. The listed signature size was measured with the SM3 reference implementation. The SHAKE reference size is 6,252 bytes, and the SM3-AVX2 size is 6,270 bytes.

Phoenix-128f uses n=16, h=68, d=17, a=7, k=19, k'=32. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 13,668 bytes, and the SM3-AVX2 size is 13,690 bytes.

Phoenix-192s uses n=24, h=63, d=9, a=12, k=19, k'=32. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 13,290 bytes.

Phoenix-192f uses n=24, h=68, d=17, a=8, k=29, k'=32. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 30,880 bytes.

Phoenix-256s uses n=32, h=66, d=11, a=12, k=24, k'=32. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 26,624 bytes.

Phoenix-256f uses n=32, h=64, d=16, a=8, k=47, k'=64. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 47,464 bytes.

Phoenix-384s uses n=48, h=66, d=11, a=12, k=37, k'=64. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 54,724 bytes.

Phoenix-384f uses n=48, h=68, d=17, a=11, k=39, k'=64. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 88,440 bytes.

Phoenix-512s uses n=64, h=64, d=8, a=12, k=57, k'=64. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 98,308 bytes.

Phoenix-512f uses n=64, h=68, d=17, a=11, k=58, k'=64. The signature length varies, and the table gives the SM3 reference size. The SHAKE reference size is 121,961 bytes. The document does not explain the large difference from SM3.

Qing Luan

Parameter set Claimed level Public key Secret key Signature
Qingluan-128 128-bit classical security 77 32 18,720
Qingluan-256 256-bit classical security 153 64 74,248
Qingluan-384 384-bit classical security 227 96 164,940
Qingluan-512 512-bit classical security 302 128 292,816

Qingluan-128 has a public key consisting of a 32-byte Seed_pk and a 45-byte pack(s). The secret key is a single 32-byte seed. It uses t=256 rounds and w=212, leaving 44 type-0 rounds. The size formula gives a fixed-length signature.

Qingluan-256 has a 64 + 89-byte public key and a single 64-byte seed as its secret key.

Qingluan-384 has a 96 + 131-byte public key and a single 96-byte seed as its secret key.

Qingluan-512 has a 128 + 174-byte public key and a single 128-byte seed as its secret key.

ReSolveD-ɑ

Parameter set Claimed level Public key Secret key Signature
ReSolveD-α-160s NGCC 128-bit classical / 80-bit quantum 121 40 5,307
ReSolveD-α-160f NGCC 128-bit classical / 80-bit quantum 121 40 6,851
ReSolveD-α-256s NGCC 256-bit classical / 128-bit quantum 194 64 13,973
ReSolveD-α-256f NGCC 256-bit classical / 128-bit quantum 194 64 17,932
ReSolveD-α-384s NGCC 384-bit classical / 192-bit quantum 288 96 31,575
ReSolveD-α-384f NGCC 384-bit classical / 192-bit quantum 288 96 40,469
ReSolveD-α-512s NGCC 512-bit classical / 256-bit quantum 385 128 56,239
ReSolveD-α-512f NGCC 512-bit classical / 256-bit quantum 385 128 72,611

ReSolveD-α-160s uses RSD parameters (m,k,w,l_bs) = (1860,1056,310,6) and VOLEitH parameters l_vole=1056, tau=14, w_grind=6, T_open=129. It is optimized for size. The public key and signature together use 5,428 bytes.

ReSolveD-α-160f uses the same RSD instance as 160s, with tau=21, w_grind=8, T_open=139. It is optimized for speed. The public key and signature together use 6,972 bytes.

ReSolveD-α-256s uses RSD parameters (m,k,w,l_bs) = (2988,1698,498,6) and l_vole=1687, tau=22, w_grind=12, T_open=224. The public key and signature together use 14,167 bytes.

ReSolveD-α-256f uses tau=35, w_grind=8, T_open=223. The public key and signature together use 18,126 bytes.

ReSolveD-α-384s uses RSD parameters (m,k,w,l_bs) = (4452,2532,742,6) and l_vole=2510, tau=34, w_grind=10, T_open=332. The public key and signature together use 31,863 bytes.

ReSolveD-α-384f uses tau=53, w_grind=9, T_open=336. The public key and signature together use 40,757 bytes.

ReSolveD-α-512s uses RSD parameters (m,k,w,l_bs) = (5940,3378,990,6) and l_vole=3343, tau=46, w_grind=6, T_open=439. The public key and signature together use 56,624 bytes.

ReSolveD-α-512f uses tau=72, w_grind=8, T_open=447. The public key and signature together use 72,996 bytes.

Rhyme

Parameter set Claimed level Public key Secret key Signature
Rhyme-128 128-bit classical (NGCC); forgery 130.25 classical / 91.75 quantum, key recovery 132.84 / 96.64, LIP 133.15 / 120.84 800 11,072 1,483
Rhyme-256 256-bit classical (NGCC); forgery 257.99 classical / 208.68 quantum 1,824 22,336 3,258
Rhyme-384 384-bit classical (NGCC); forgery 384.94 classical / 324.59 quantum 2,720 45,760 4,743
Rhyme-512 512-bit classical (NGCC); forgery 518.97 classical / 446.67 quantum 3,872 44,864 7,002

Rhyme-128 uses n=256, q=3329, (k,l)=(2,3), D=10, tau=30, eta=2. The secret key includes the public key: sk = pk + d*D*n bytes of int8 basis + 32-byte seed = 800+10240+32. The signature uses rANS compression, so its length varies. The expected size is 1,483 bytes at a compression rate of 0.75-0.85, while the implementation reserves a padded worst-case buffer of 5,156 bytes.

Rhyme-256 uses n=512, q=9473, (k,l)=(2,3), D=10, tau=58, eta=4. The secret key includes the public key. The table gives the average rANS-compressed signature size; the implementation reserves a 10,308-byte buffer.

Rhyme-384 uses n=512, q=11777, (k,l)=(3,4), D=14, tau=113, eta=5. The secret key includes the public key. The table gives the average rANS-compressed signature size; the implementation reserves a 14,436-byte buffer.

Rhyme-512 uses n=1024, q=18433, (k,l)=(2,3), D=10, tau=115, eta=6. The secret key includes the public key. The table gives the average rANS-compressed signature size; the implementation reserves a 20,612-byte buffer.

Shuttle

Parameter set Claimed level Public key Secret key Signature
SUF-128 (SHUTTLE-128) target security level 128; MLWE 138.0 classical / 123.4 quantum, MSIS-sUF 165.3 / 145.5 (Core-SVP) 1,264 2,288 1,183
SUF-256 (SHUTTLE-256) target security level 256; MLWE 279.7 classical / 252.0 quantum, MSIS-sUF 266.3 / 234.4 1,952 3,680 2,417
SUF-512 (SHUTTLE-512) target security level 512; MLWE 625.0 classical / 553.4 quantum, MSIS-sUF 522.4 / 459.8 3,648 7,104 5,001

SUF-128 (SHUTTLE-128) uses n=256, q=15361, (l,m)=(3,3), tau=42, alpha_h=1024, alpha_b=2. The public key consists of seedA and the compressed b. The secret key includes seedA, the compressed public-key body, and K, tr, s1, s2. The signature is a fixed-size rANS packet. The public key and signature together use 2,447 bytes.

SUF-256 (SHUTTLE-256) uses n=512, q=61441, (l,m)=(3,2), tau=58, alpha_h=1024, alpha_b=2. The public key and signature together use 4,369 bytes.

SUF-512 (SHUTTLE-512) uses n=1024, q=59393, (l,m)=(3,2), tau=115, alpha_h=2048, alpha_b=4. The public key contains a 64-byte seed and a 3,584-byte body. The public key and signature together use 8,649 bytes.

Sigurd

Parameter set Claimed level Public key Secret key Signature
NGCC-128 (Sigurd-128) 128-bit claimed classical / 80-bit claimed quantum (best classical attack 128.20, best quantum 104.02 bits) 112 80 25,108
NGCC-256 (Sigurd-256) 256-bit claimed classical / 128-bit claimed quantum (best classical 256.38, best quantum 202.92 bits) 212 128 74,756
NGCC-512 (Sigurd-512) 512-bit claimed classical / 256-bit claimed quantum (best classical 512.23, best quantum 387.24 bits) 435 256 282,692

NGCC-128 (Sigurd-128) uses RSD parameters (m,k)=(1302,738), B=6, n=217, tower degrees (iota,tau)=(16,10), and t_Sigma=10, Q_VC=160, N_VC=1568, with RS rate 1/4. The public key contains the 320-bit seed_H and a packed syndrome; the secret key contains two 320-bit seeds. The signature size is approximate: the specification reports a sample encoded length, and the actual length varies with the opening.

NGCC-256 (Sigurd-256) uses RSD parameters (m,k)=(2748,1564), B=6, n=458, tower degrees (iota,tau)=(16,16), and t_Sigma=16, Q_VC=171, N_VC=5208, with RS rate 1/8. The signature size is an approximate sample encoded length.

NGCC-512 (Sigurd-512) uses RSD parameters (m,k)=(5676,3230), B=6, n=946, tower degrees (iota,tau)=(16,32), and t_Sigma=32, Q_VC=256, N_VC=19824, with RS rate 1/16. The signature size is an approximate sample encoded length.

SQIsign2D²

Parameter set Claimed level Public key Secret key Signature
Level1-eff Level1: 128-bit classical / 64-bit quantum 65 240 168
Level1-sec Level1: 135-bit classical / 67-bit quantum 69 257 178
Level2-eff Level2: 160-bit classical / 80-bit quantum 81 298 208
Level2-sec Level2: 166-bit classical / 83-bit quantum 85 315 218
Level3-eff Level3: 256-bit classical / 128-bit quantum 129 468 326
Level3-sec Level3: 262-bit classical / 131-bit quantum 133 489 338
Level5-eff Level5: 512-bit classical / 256-bit quantum 257 936 648
Level5-sec Level5: 535-bit classical / 268-bit quantum 269 982 678

Level1-eff uses compressed encoding and p = 2^131*3^78-1. Without compression, the public key is 64 bytes, the secret key is 488 bytes, and the signature is 200 bytes. The compressed public key is one byte larger because it includes a basis hint.

Level1-sec uses compressed encoding and p = 2^137*3^84-1. Without compression, the public key is 68 bytes, the secret key is 521 bytes, and the signature is 212 bytes.

Level2-eff uses compressed encoding and p = 61*2^161*3^96-1. Without compression, the public key is 80 bytes, the secret key is 610 bytes, and the signature is 248 bytes.

Level2-sec uses compressed encoding and p = 11*2^168*3^101-1. Without compression, the public key is 84 bytes, the secret key is 643 bytes, and the signature is 260 bytes.

Level3-eff uses compressed encoding and p = 2^263*3^156-1. Without compression, the public key is 128 bytes, the secret key is 976 bytes, and the signature is 392 bytes.

Level3-sec uses compressed encoding and p = 2^264*3^163-1. Without compression, the public key is 132 bytes, the secret key is 1009 bytes, and the signature is 404 bytes.

Level5-eff uses compressed encoding and p = 11*2^514*3^319-1. Without compression, the public key is 256 bytes, the secret key is 1952 bytes, and the signature is 776 bytes.

Level5-sec uses compressed encoding and p = 17*2^536*3^334-1. Without compression, the public key is 268 bytes, the secret key is 2046 bytes, and the signature is 812 bytes.

SQIsign2D-push^(1/2)

Parameter set Claimed level Public key Secret key Signature
Level-1 lambda=128: 128-bit classical (64-bit quantum) 64 518 150
Level-2 lambda=160: 160-bit classical / 80-bit quantum (used as the 128-bit-classical/80-bit-quantum set) 96 768 218
Level-3 lambda=256: 256-bit classical / 128-bit quantum 128 1,024 293
Level-4 lambda=512: 512-bit classical / 256-bit quantum 262 2,096 593

Level-1 uses p = 2^131*3^78-1. The submitters withdrew this set because it does not reach 80-bit quantum security.

Level-2 uses p = 2^191*3^118-1.

Level-3 uses p = 2^263*3^156-1.

Level-4 uses p = 2^527*3^324-1.

SQIsignTriangle

Parameter set Claimed level Public key Secret key Signature
lvl1 (lambda=128) 128-bit classical / 64-bit quantum - labelled an Implementation/Performance-Evaluation set, not a recommended set 65 353 204
lvl2 (lambda=160) 160-bit classical / 80-bit quantum (recommended set for the 128-bit-classical tier) 81 437 255
lvl5 (lambda=256) 256-bit classical / 128-bit quantum 129 701 408
lvl6 (lambda=512) 512-bit classical / 256-bit quantum 257 1,409 816

lvl1 (lambda=128) uses p = 5*2^248-1. The public key contains the curve and a one-byte basis hint.

lvl2 (lambda=160) uses p = 9*2^309-1.

lvl5 (lambda=256) uses p = 27*2^500-1.

lvl6 (lambda=512) uses p = 113*2^1016-1.

SYDO

Parameter set Claimed level Public key Secret key Signature
SYDO-160s 160-bit classical / 80-bit quantum 80 174 5,428
SYDO-160f 160-bit classical / 80-bit quantum 80 174 6,724
SYDO-256s 256-bit classical / 128-bit quantum 128 278 14,444
SYDO-256f 256-bit classical / 128-bit quantum 128 278 17,604
SYDO-512s 512-bit classical / 256-bit quantum 246 534 56,672
SYDO-512f 512-bit classical / 256-bit quantum 246 534 67,716

SYDO-160s uses N=2^11, tau=14, w_grind=8, T_open=132. Its RSD parameters are n=16461, n-k=480, w=59. The secret key contains the public key and the witness. The signature has the fixed length shown in the table.

SYDO-160f is the fast variant, with N=2^8, tau=20, w_grind=2, T_open=138.

SYDO-256s uses N=2^11, tau=23, w_grind=5, T_open=225. Its RSD parameters are n=26226, n-k=768, w=94.

SYDO-256f is the fast variant, with N=2^8, tau=32, w_grind=2, T_open=236.

SYDO-512s uses N=2^11, tau=46, w_grind=8, T_open=445. Its RSD parameters are n=49941, n-k=1456, w=179.

SYDO-512f is the fast variant, with N=2^8, tau=64, w_grind=2, T_open=446.

Tins

Parameter set Claimed level Public key Secret key Signature
Tins-128 lambda=128; spec claims 137-bit classical and 128-bit quantum security 51 32 3,284
Tins-256 lambda=256; spec claims 261-bit classical and 256-bit quantum security 98 64 13,012
Tins-512 lambda=512; spec claims 521-bit classical and 512-bit quantum security 195 128 51,187

Tins-128 uses k=276, n=140, N=4096, tau=12, T_open=125, omega=6. The secret key contains two 16-byte seeds, and the public key contains a 16-byte seed and a 35-byte field element.

Tins-256 uses k=528, n=268, N=4096, tau=24, T_open=255, omega=4.

Tins-512 uses k=1044, n=524, N=4096, tau=47, T_open=510, omega=6.

TRINE

Parameter set Claimed level Public key Secret key Signature
Balanced TRINE-128 128.0-bit classical (quantum estimate 105 bits) 16,004 32 3,124
ShortSig TRINE-128 128.2-bit classical (quantum estimate 105 bits) 63,920 32 1,620
Balanced TRINE-256 256.0-bit classical (quantum estimate 180 bits) 96,064 64 11,648
ShortSig TRINE-256 256.1-bit classical (quantum estimate 180 bits) 384,064 64 5,904
Balanced TRINE-512 512.1-bit classical (quantum estimate 348 bits) 797,290 128 46,437
ShortSig TRINE-512 512.0-bit classical (quantum estimate 348 bits) 3,188,774 128 23,544

Balanced TRINE-128 uses (n,q,r,K,X) = (22,4093,138,52,1). The secret key is a 2*lambda-bit seed. The public key contains X trilinear forms and a 2*lambda-bit seed. The implementation expects a 3,156-byte signature, which includes a 32-byte salt omitted from the specification formula.

ShortSig TRINE-128 uses (n,q,r,K,X) = (22,4093,61,36,4). The implementation expects a 1,652-byte signature, including a 32-byte salt omitted from the specification.

Balanced TRINE-256 uses (n,q,r,K,X) = (40,4093,271,104,1). The implementation expects an 11,712-byte signature, including a 64-byte salt omitted from the specification.

ShortSig TRINE-256 uses (n,q,r,K,X) = (40,4093,116,76,4). The implementation expects a 5,968-byte signature, including a 64-byte salt omitted from the specification.

Balanced TRINE-512 uses (n,q,r,K,X) = (81,4093,534,211,1). The implementation expects a 46,565-byte signature, including a 128-byte salt omitted from the specification.

ShortSig TRINE-512 uses (n,q,r,K,X) = (81,4093,232,149,4). The implementation gives a 3,188,776-byte public key, which is two bytes larger than the specification formula. It expects a 23,672-byte signature, including a 128-byte salt omitted from the specification.

TSUOV

Parameter set Claimed level Public key Secret key Signature
TSUOV 128 ICCS level 128 (security_strength_category 1) 778 32 896
TSUOV 256 ICCS level 256 (security_strength_category 3) 2,170 64 2,412
TSUOV 512 ICCS level 512 (security_strength_category 5) 21,319 128 2,939

TSUOV 128 uses q=31, l=2, n=64, o=4, m1=61, k=11, m2=88. The implementation gives a 779-byte public key. The specification formula gives 5*m1*l*o(o+1)/2 bits + 128-bit seed = 6228 bits = 778.5 B, which rounds up to 779 bytes. The specified 778-byte value appears to have been rounded down. The secret key consists of two seeds, or 2*lambda bits, and the public key contains seed_pk.

TSUOV 256 uses q=31, l=2, n=119, o=5, m1=114, k=16, m2=160. The secret key consists of two seeds.

TSUOV 512 uses q=31, l=2, n=230, o=12, m1=218, k=10, m2=240. The secret key consists of two seeds.

UVW signature

Parameter set Claimed level Public key Secret key Signature
UVW128 (Level 1) 128-bit (classical 133.7 msg / 304.5 key; quantum 80.8 / 179.5) 5,897,612 40 1,244
UVW256 (Level 2) 256-bit (classical 257.7 msg / 603.1 key; quantum 156.6 / 352.7) 23,040,012 40 2,444
UVW512 (Level 3) 512-bit (classical 517.4 msg / 1226.1 key; quantum 315.2 / 714.5) 95,160,012 72 4,956

UVW128 (Level 1) uses (q,n,k,k1,k2,w) = (3,9700,4850,3250,1600,8633). The listed sizes describe the serialized keys and signatures. The specification also gives theoretical sizes of 4.44 MB for the public key and 977 bytes for the signature, using information-theoretic trit packing. The implementation stores four trits per byte, which explains the larger stored sizes.

The secret key contains a 32-byte master seed and four two-byte nonces.

UVW256 (Level 2) uses (q,n,k,k1,k2,w) = (3,19200,9600,6433,3167,17088). The specification gives theoretical sizes of 17.41 MB for the public key and 1,934 bytes for the signature. The secret key contains a seed and nonces, totaling 40 bytes as in Level 1.

UVW512 (Level 3) uses (q,n,k,k1,k2,w) = (3,39000,19500,13066,6434,34710). The specification gives theoretical sizes of 71.85 MB for the public key and 3,928 bytes for the signature. The secret key contains a 64-byte seed and four two-byte nonces.

VDOO

Parameter set Claimed level Public key Secret key Signature
VDOO-128 128-bit classical / 64-bit quantum 330,855 232,145 85
VDOO-256 256-bit classical / 128-bit quantum 4,289,250 3,613,669 316
VDOO-512 512-bit classical / 256-bit quantum 20,229,300 16,264,060 471

VDOO-128 uses (q,v,d,o1,o2) = (16,67,16,14,40), n=137, m=70 and a 16-byte salt. The specification gives a 323.1 KB public key and a 226.7 KB secret key, using 1,024 bytes per KB. The public-key formula is /PK/ = m*n(n+1)/2 field elements, with two F16 elements per byte. This gives exactly 330,855 bytes, or 323.10 KB. The secret key contains /S/+/T/+/F/ free field elements, giving 232,145 bytes, or 226.70 KB.

Multiplying the rounded 226.7 KB figure by 1,024 would instead give 232,141 bytes.

VDOO-256 uses (q,v,d,o1,o2) = (256,205,10,17,68), n=300, m=95, a 16-byte salt, and one byte per F256 element. The specification gives a 4,188.7 KB public key; the formula gives 4,289,250 bytes, or 4,188.72 KB. It gives a 3,529.0 KB secret key; the formula gives 3,613,669 bytes, or 3,528.97 KB. Multiplying the rounded secret-key figure by 1,024 would instead give 3,613,696 bytes.

VDOO-512 uses (q,v,d,o1,o2) = (256,260,10,10,175), n=455, m=195 and a 16-byte salt. The specification gives a 19,755.2 KB public key; the formula gives 20,229,300 bytes, or 19,755.18 KB. It gives a 15,882.9 KB secret key; the formula gives 16,264,060 bytes, or 15,882.87 KB. Multiplying the rounded secret-key figure by 1,024 would instead give 16,264,090 bytes.

YuanYang.DSA

Parameter set Claimed level Public key Secret key Signature
YuanYang.DSA-512 128-bit classical (core-SVP key recovery 128 C / 116 Q, forgery 128 C / 116 Q) 738 15,584 561
YuanYang.DSA-1024 256-bit classical (core-SVP key recovery 266 C / 242 Q, forgery 293 C / 266 Q) 1,570 31,264 1,150
YuanYang.DSA-2048 512-bit classical (core-SVP key recovery 545 C / 494 Q, forgery 651 C / 591 Q) 3,330 62,720 2,364

YuanYang.DSA-512 uses d=512, q=2689 and a 26-byte salt (lambda+80 = 208 bits). The public key contains a two-byte q prefix and 736 bytes of packed h. The signature contains the salt and a 535-byte rANS-compressed payload. The secret key is the expanded signing key h // f,g,F,G (8-bit coeffs) // u_hat // A_hat // Sigma_delta, rather than a seed.

YuanYang.DSA-1024 uses d=1024, q=4481 and a 42-byte salt (336 bits). The public-key size is 2 + 1568 bytes, and the signature size is 42 + 1108 bytes. It uses the same expanded secret-key format as YuanYang.DSA-512.

YuanYang.DSA-2048 uses d=2048, q=7681 and a 72-byte salt, listed as 592 bits in the source. The public-key size is 2 + 3328 bytes, and the signature size is 72 + 2292 bytes. It uses the same expanded secret-key format as YuanYang.DSA-512.

Key encapsulation

Aigis-Enc+

Parameter set Claimed level Public key Secret key Ciphertext
Aigis-Enc+-512 128-bit classical / 80-bit quantum (primal 130C/114Q, MATZOV 130C/108Q) 656 16 896
Aigis-Enc+-1024 256-bit classical / 128-bit quantum (primal 273C/240Q, MATZOV 266C/217Q) 1,312 32 1,664
Aigis-Enc+-2048 512-bit classical / 256-bit quantum (primal 572C/503Q, MATZOV 516C/420Q) 2,624 64 3,584

Aigis-Enc+-512 uses n=512, q=3329, k=1, (chi_alpha,chi_beta)=(B5,B6), (dt,du,dv)=(10,10,4). The specification lists the 16-byte secret-key seed. The reference, AVX2, and NEON implementations store a 1,456-byte expanded secret key, containing the public key, a hash, and an implicit-rejection seed. The shared secret is 16 bytes, and the DFR is 2^-145.

Aigis-Enc+-1024 uses n=1024, q=3329, k=1, (B2,B6), (10,10,3). The specification lists a 32-byte seed, while the expanded secret key uses 2,912 bytes. The shared secret is 32 bytes, and the DFR is 2^-145.

Aigis-Enc+-2048 uses n=2048, q=3329, k=1, (B2,B3), (10,10,4). The specification lists a 64-byte seed, while the expanded secret key uses 5,824 bytes. The shared secret is 64 bytes, and the DFR is 2^-157.

Amoeba

Parameter set Claimed level Public key Secret key Ciphertext
Amoeba-576 128-bit classical (Core-SVP 128.4 classical / 112.5 quantum) 784 1,712 1,047
Amoeba-864 192-bit classical (Core-SVP 198.3 classical / 173.8 quantum) 1,144 2,504 1,581
Amoeba-1152 256-bit classical (Core-SVP 266.5 classical / 233.5 quantum) 1,648 3,440 1,833
Amoeba-1728 384-bit classical (Core-SVP 423.8 classical / 371.4 quantum) 2,440 5,096 2,769
Amoeba-2304 512-bit classical (Core-SVP 585.3 classical / 512.9 quantum) 3,520 7,040 3,914

Amoeba-576 uses q=3457, n=288, k=2, ECC length 523, eta1=eta2=2, (d0,d1,d2)=(10,10,5). The DFR is 2^-133.3, and the shared secret is 64 bytes. The table gives the CCA secret key, which contains an 864-byte CPA secret key, a 784-byte public key, and a 64-byte seed. The specification also describes regenerating the private key when needed from a seed of about 64 bytes.

Amoeba-864 uses k=3, eta1=1, eta2=2, (10,11,6). The DFR is 2^-208.6. The shared secret is 64 bytes.

Amoeba-1152 uses k=4, eta1=eta2=1, (11,10,6). The DFR is 2^-267.9. The shared secret is 64 bytes.

Amoeba-1728 uses k=6, eta1=eta2=1, (11,11,6). The DFR is 2^-229.3, which does not meet DFR < 2^-lambda. The specification argues that 2^-200 is low enough.

Amoeba-2304 uses k=8, eta1=eta2=1, (12,12,7). The DFR is 2^-205.3, which does not meet DFR < 2^-lambda.

BAG-Loong

Parameter set Claimed level Public key Secret key Ciphertext
BAG-Loong-128 128-bit classical / 80-bit quantum 2,500 16 3,055
BAG-Loong-256 256-bit classical / 128-bit quantum 6,597 32 8,384
BAG-Loong-384 384-bit classical / 192-bit quantum 12,152 48 15,096
BAG-Loong-512 512-bit classical / 256-bit quantum 19,043 64 21,644

BAG-Loong-128 uses q=2, n=42, m=47, n'=46, n1=n2=10, eps=33, k=3. The specification lists a 2,500-byte public key, a 16-byte seed, a 3,055-byte ciphertext, and a 16-byte shared key. The secret key (X,seed1) comes from a lambda/8 = 16-byte seed, but its serialized form in the implementation uses 5,064 bytes. The specification gives the PKE ciphertext size; the KEM ciphertext adds a 16-byte salt, bringing it to 3,071 bytes.

BAG-Loong-256 uses n=65, m=67, n'=67, n1=12, n2=13, eps=51, k=4. The implementation stores a 13,258-byte secret key and an 8384 + 16 = 8400-byte KEM ciphertext, including the salt. The shared key is 32 bytes.

BAG-Loong-384 uses n=83, m=83, n'=83, n1=14, n2=15, eps=66, k=5. The implementation stores a 24,368-byte secret key and a 15,112-byte KEM ciphertext. The shared key is 48 bytes.

BAG-Loong-512 uses n=104, m=97, n'=97, n1=15, n2=15, eps=73, k=6. The implementation stores a 38,150-byte secret key and a 21,660-byte KEM ciphertext. The shared key is 64 bytes.

BAG-Piglet

Parameter set Claimed level Public key Secret key Ciphertext
BAG-Piglet-128 128-bit classical / 80-bit quantum 522 16 1,011
BAG-Piglet-256 256-bit classical / 128-bit quantum 1,573 32 3,081
BAG-Piglet-384 384-bit classical / 192-bit quantum 2,778 48 5,459
BAG-Piglet-512 512-bit classical / 256-bit quantum 4,158 64 8,188

BAG-Piglet-128 uses q=2, m=47, n=43, n'=43, n1=2, eps=30, k=3 and f(X)=X^47+X^5+1. The specification instead prints n=47, n'=43, m=43, swapping m and n. The public-key size is ceil(2mn/8)+lambda/8 = 506+16 bytes, and the secret key is a lambda/8 = 16-byte seed. The specification gives a 1,011-byte CPA-PKE ciphertext, while the KEM ciphertext adds a 16-byte salt for a total of 1,027 bytes.

The shared key is 16 bytes, and the DFR is 2^-130.

BAG-Piglet-256 uses m=79, n=78, n'=78, n1=2, eps=54, k=4. The KEM ciphertext contains a 3,081-byte body and a 16-byte salt, totaling 3,097 bytes. The shared key is 32 bytes, and the DFR is 2^-273.

BAG-Piglet-384 uses m=103, n=106, n'=103, n1=2, eps=77, k=4. The KEM ciphertext contains a 5,459-byte body and a 16-byte salt, totaling 5,475 bytes. The shared key is 48 bytes, and the DFR is 2^-394.

BAG-Piglet-512 uses m=131, n=125, n'=130, n1=2, eps=92, k=4. The KEM ciphertext contains an 8,188-byte body and a 16-byte salt, totaling 8,204 bytes. The shared key is 64 bytes, and the DFR is 2^-520.

BIKE-MLThre

Parameter set Claimed level Public key Secret key Ciphertext
BIKE_MLThre-128 128-bit security target 1,541 281 1,573
BIKE_MLThre-256 256-bit security target 5,122 580 5,154
BIKE_MLThre-512 512-bit security target (experimental) 18,751 1,293 18,815

BIKE_MLThre-128 uses r=12323, w=142, t=134, with a 256-bit (32-byte) shared secret and a target DFR of <= 2^-128. The specification gives sizes in bits: 2,244 for the private key, 12,323 for the public key, and 12,579 for the ciphertext. The byte sizes above round each of these up using ceil(bits/8). This set is identical to BIKE Level-1. The implementation keeps the secret key in a C structure that is much larger than the 281-byte compact encoding.

BIKE_MLThre-256 uses r=40973, w=274, t=264, with a 256-bit (32-byte) shared secret and a target DFR of <= 2^-256. The specification gives sizes in bits: 4,640 for the secret key, 40,973 for the public key, and 41,229 for the ciphertext. This set is identical to BIKE Level-5.

BIKE_MLThre-512 uses r=150001, w=546 (D=273 per block), and t=524, with a 512-bit (64-byte) shared secret and a target DFR of <= 2^-512. The specification gives sizes in bits: 10,340 for the secret key, 150,001 for the public key, and 150,513 for the ciphertext. The implementers describe this as a functional evaluation profile with a 512-bit width, not a claim of proven 512-bit classical security.

BRA

Parameter set Claimed level Public key Secret key Ciphertext
BRA-128 128-bit classical / 80-bit quantum target (claimed strengths: 2^189 classical, 2^94 quantum) 1,078 98 2,092
BRA-256 256-bit classical / 128-bit quantum target (claimed strengths: 2^304 classical, 2^152 quantum) 1,735 106 3,406
BRA-512 512-bit classical / 256-bit quantum target (claimed strengths: 2^556 classical, 2^278 quantum) 3,573 144 7,082

BRA-128 uses q=2, m=67, n=121, t=67, k=4, (wx,wy,wr1,wr2,we)=(4,5,5,5,8), r=53, P(X)=X^121+X^18+1. The seed-and-sigma secret-key form uses ceil(mk/8)+64 = 34+64 bytes. The implementation also stores the public key, giving 64+34+1078 = 1176 bytes. The public-key size is ceil(mn/8)+64 = 1014+64, and the ciphertext size is 2*ceil(mn/8)+64. The shared key is 64 bytes, and the DFR is 2^-130.

BRA-256 uses m=83, n=161, t=83, k=4, (5,5,6,6,8), r=68. The implementation stores a 1,841-byte secret key containing the seed, sigma, and public key. The shared key is 64 bytes, and the DFR is 2^-262.

BRA-512 uses m=127, n=221, t=127, k=5, (6,6,7,8,8), r=98. The implementation stores a 3,717-byte secret key containing the seed, sigma, and public key. The shared key is 64 bytes, and the DFR is 2^-523.

BRQC

Parameter set Claimed level Public key Secret key Ciphertext
BRQC-128 128-bit security (classical 2^181, quantum 2^90) 1,954 112 3,844
BRQC-256 256-bit security (classical 2^295, quantum 2^147) 3,345 126 6,626
BRQC-512 512-bit security (classical 2^566, quantum 2^283) 6,562 150 13,060

BRQC-128 uses q=2, m=127, n=119, k=3, with a 64-byte shared key and a DFR of zero. The specification gives the seed-form secret-key size as ceil(mk/8)+64 = 112 bytes. The implementation also stores the public key, so its expanded secret key uses 112 + 1954 = 2066 bytes.

BRQC-256 uses m=163, n=161, k=3 and a 64-byte shared key. The implementation stores a 126 + pk = 3471-byte secret key.

BRQC-512 uses m=229, n=227, k=3 and a 64-byte shared key. The implementation stores a 150 + pk = 6712-byte secret key.

BW-KEM

Parameter set Claimed level Public key Secret key Ciphertext
BW-KEM-c128 128-bit (core-SVP classical 131, quantum 119) 784 1,585 768
BW-KEM-c128-s 128-bit (core-SVP classical 131, quantum 119) 784 1,585 928
BW-KEM-c256 256-bit (core-SVP classical 267, quantum 242) 1,568 3,169 1,440
BW-KEM-c256-s 256-bit (core-SVP classical 267, quantum 242) 1,568 3,169 1,600
BW-KEM-c512 512-bit (core-SVP classical 556, quantum 504) 3,136 6,337 2,944
BW-KEM-c512-s 512-bit (core-SVP classical 556, quantum 504) 3,136 6,337 3,264
BW-KEM-c384 384-bit (core-SVP classical 403, quantum 365) 2,368 Not stated 2,176
BW-KEM-c384-s 384-bit (core-SVP classical 403, quantum 365) 2,368 Not stated 2,432

BW-KEM-c128 uses the BW8 lattice with N=256, l=2, (du,dv)=(10,4). The shared secret is 16 bytes, and the DFR is 2^-138.14.

BW-KEM-c128-s is the strengthened variant, with (du,dv)=(11,5) and DFR 2^-188.01. The specification does not list its secret-key size, but the size formula is independent of du and dv, giving the same 1,585 bytes as c128. No implementation is included.

BW-KEM-c256 uses the BW32 lattice with N=256, l=4, (du,dv)=(10,5). The shared secret is 32 bytes, and the DFR is 2^-209.94.

BW-KEM-c256-s uses (du,dv)=(11,6) and has DFR 2^-277.92. The secret-key size equals c256 because it does not depend on du or dv. No implementation is included.

BW-KEM-c512 uses the BW32 lattice with N=512, l=4, (du,dv)=(10,6). The shared secret is 64 bytes, and the DFR is 2^-232.71.

BW-KEM-c512-s uses (du,dv)=(11,7) and has DFR 2^-308.56. The secret-key size equals c512, and no implementation is included.

BW-KEM-c384 uses the BW32 lattice with N=512, l=3, (du,dv)=(10,4). The shared secret is 64 bytes, and the DFR is 2^-216.26. Its secret-key size is not stated, and no implementation is included; only c128, c256, and c512 have implementations.

BW-KEM-c384-s uses (du,dv)=(11,5) and has DFR 2^-370.79. Its secret-key size is not stated, and no implementation is included.

CheetahKEM

Parameter set Claimed level Public key Secret key Ciphertext
Cheetah128 128-bit classical 832 1,936 864
Cheetah256 256-bit classical 1,648 3,808 1,728
Cheetah384 384-bit classical 2,704 5,920 2,832
Cheetah512 512-bit classical 3,600 7,872 4,032

Cheetah128 uses Ring-LWE with N=640, k=1, q=7681, eta=5, (db,du,dv)=(10,10,4). The DFR is 2^-129. The shared key is 16 bytes. The secret key contains a 1,040-byte noise polynomial vector, the 832-byte public key, a 32-byte hash, and a 32-byte seed.

Cheetah256 uses N=640, k=2, eta=4, (10,10,4). The DFR is 2^-176. The shared key is 32 bytes.

Cheetah384 uses N=640, k=3, eta=3, (11,11,4). The DFR is 2^-189. The shared key is 48 bytes.

Cheetah512 uses N=640, k=4, eta=2, (11,11,8). The DFR is 2^-243. The shared key is 64 bytes.

C-Multi-UR-AG

Parameter set Claimed level Public key Secret key Ciphertext
Level-128 128-bit security (classical 2^170, quantum 2^85) 3,866 94 7,332
Level-256 256-bit security (classical 2^276, quantum 2^138) 10,780 112 15,304
Level-512 512-bit security (classical 2^530, quantum 2^265) 28,866 155 40,926

Level-128 uses q=2, m=79, n=35, k=3, N1=11, N2=16, w1=8, w2=9, with a 64-byte shared key and DFR 2^-148. The specification gives the seed-form secret-key size as ceil(mk/8)+64 = 94 bytes. The implementation also stores the public key, giving 94 + 3866 = 3960 bytes.

Level-256 uses m=127, n=45, k=3, N1=15, N2=16 and has DFR 2^-268. The implementation stores a 112 + pk = 10892-byte secret key.

Level-512 uses m=181, n=67, k=4, N1=19, N2=21 and has DFR 2^-598. The implementation stores a 155 + pk = 29021-byte secret key.

COMPASS-KEM

Parameter set Claimed level Public key Secret key Ciphertext
COMPASS-KEM-128 (Level 1) 128 bit 672 1,504 768
COMPASS-KEM-256 (Level 2) 256 bit 1,312 2,912 1,472
COMPASS-KEM-384 (Level 3) 384 bit 2,144 4,704 2,432
COMPASS-KEM-512 (Level 4) 512 bit 2,848 6,240 3,264

COMPASS-KEM-128 (Level 1) uses n=256, q=3329, p=832, k*l=2x2, eta_s=3, (d,d1,d2)=(2,2,8). The DFR is 2^-189.27. The shared key is 32 bytes. The secret key contains k*polybytes = 768 bytes of secret polynomials, the 672-byte public key, and two 32-byte values.

COMPASS-KEM-256 (Level 2) uses n=256, q=3329, p=832, 4x4, eta_s=2, (2,2,6). The DFR is 2^-181.13.

COMPASS-KEM-384 (Level 3) uses n=512, q=7681, p=1920, 3x3, eta_s=3, (2,2,8). The DFR is 2^-404.51.

COMPASS-KEM-512 (Level 4) uses n=512, q=7681, p=1920, 4x4, eta_s=4, (2,2,6). The DFR is 2^-250.31.

CTL

Parameter set Claimed level Public key Secret key Ciphertext
CTL-128 (CTL-257-512) 128-bit security (classical 2^137.6 key recovery, quantum 2^122.3) 521 2,953 473
CTL-256 (CTL-769-1024) 256-bit security (classical 2^256.3 key recovery, quantum 2^227.2) 1,230 6,030 1,006
CTL-512 (CTL-3329-2048) 512-bit security (classical 2^512.5 key recovery, quantum 2^452.5) 3,009 15,617 2,353

CTL-128 (CTL-257-512) uses n=512, (b,k,q)=(128,2,257), q'=64513. The DFR is 2^-196. The shared secret is 16 bytes. The table gives the long private-key format used by the implementation. The specification also gives a 417-byte short format. The specification lists the sizes with direct, uncompressed encoding: a 576-byte public key and a 480-byte ciphertext.

CTL-256 (CTL-769-1024) uses n=1024, (b,k,q)=(192,4,769). The DFR is 2^-308. The shared secret is 32 bytes. The short private-key format is 801 bytes. With direct encoding, the public key is 1,280 bytes and the ciphertext is 1,056 bytes. The implementation labels this set as 192 bits rather than 256.

CTL-512 (CTL-3329-2048) uses n=2048, (b,k,q)=(416,8,3329). The DFR is 2^-426.1. The shared secret is 48 bytes. The short private-key format is 3,105 bytes. The Chinese specification and implementation documentation give a 2,353-byte ciphertext, while the English specification gives 2,305 bytes. The table above uses 2,353 bytes.

With direct encoding, the public key is 3,072 bytes and the ciphertext is 2,368 bytes. The implementation labels this set as 256 bits rather than 512.

DKEM

Parameter set Claimed level Public key Secret key Ciphertext
DKEM-128 NGCC level 1 (NIST equivalent ML-KEM-512, 128-bit) 800 1,600 800
DKEM-256 NGCC level 2 (NIST equivalent ML-KEM-1024, 256-bit) 1,568 3,136 1,600
DKEM-512 NGCC level 3 (no NIST equivalent; 512-bit target) 3,392 6,784 3,136

DKEM-128 uses n=256, q=3329, k=2, eta=3, l=4, dA=12, dB=10. The shared secret is 32 bytes. The failure probability is 2^-132.7. The secret key has the form CPA_sk // pk // z, without a cached H(pk).

DKEM-256 uses n=256, q=3329, k=4, eta=2, l=5, dA=12, dB=11. The shared secret is 32 bytes. The failure probability is 2^-181.2.

DKEM-512 uses n=512, q=7681, k=4, eta=3, l=4, dA=13, dB=11. The shared secret is 64 bytes. The seeds are also 64 bytes. The failure probability is 2^-167.0.

DTRU

Parameter set Claimed level Public key Secret key Ciphertext
DTRU-Light 128 bits 640 864 512
DTRU-648 128 bits (footnote: targets 128-bit quantum security) 972 1,328 729
DTRU-768 192 bits 1,152 1,568 960
DTRU-1024 256 bits 1,536 2,080 1,280
DTRU-Prime 256 bits 1,495 1,935 1,359
DTRU-1536 384 bits 2,304 3,136 1,920
DTRU-2048 512 bits 3,072 3,904 2,560

DTRU-Light uses n=512, q=769, q2=2^8 over a power-of-two cyclotomic ring, with a classical security estimate of 132 bits. The specification also gives a compressed variant for reference, with a 615-byte public key and an 839-byte secret key, but no compressed Light implementation is included. The secret key contains 192 bytes for f at three bits per coefficient, the public key, and a 32-byte z.

DTRU-648 uses n=648, q=3457, q2=2^9, with a classical security estimate of 164 bits. Optional lossless public-key compression gives a 954-byte public key and a 1,310-byte secret key. The secret key contains the public key and a 32-byte FO rejection seed z.

DTRU-768 uses n=768, q=3457, q2=2^10, with a classical security estimate of 195 bits, matching Kyber-768. Compression gives a 1,130-byte public key and a 1,546-byte secret key.

DTRU-1024 uses n=1024, q=3457, q2=2^10, with a classical security estimate of 270 bits. Compression gives a 1,506-byte public key and a 2,050-byte secret key.

DTRU-Prime uses n=1087, q=2017, q2=2^10 over the LPPNF ring Zq[x]/(x^n - x - 1), with a classical security estimate of 280 bits. There is no compressed variant because q is close to a power of two. The packed sizes are rounded up to whole bytes: 1087*11/8 = 1494.6 becomes 1,495, and 1087*10/8 = 1358.75 becomes 1,359.

DTRU-1536 uses n=1536, q=3457, q2=2^10, with a classical security estimate of 411 bits and 64-byte seeds and shared key. Compression gives a 2,259-byte public key and a 3,091-byte secret key.

DTRU-2048 uses n=2048, q=3457, q2=2^10, with a classical security estimate of 567 bits and 64-byte seeds and shared key. Compression gives a 3,012-byte public key and a 3,844-byte secret key.

FLIT

Parameter set Claimed level Public key Secret key Ciphertext
Flit128 128-bit (MATZOV: RLWE 134.0 classical / 129.7 quantum, NTRU 139.4 / 133.7) 615 839 512
Flit256 256-bit (MATZOV: RLWE 269.5 / 253.2, NTRU 281.2 / 261.1) 1,229 1,581 1,024
Flit512 512-bit (MATZOV: RLWE 529.1 / 488.5, NTRU 554.3 / 506.9) 3,072 3,776 2,304

Flit128 uses N=512, n=256, q=769, d=8, delta=2^-187.5, with 32-byte seeds and shared secret. The public key uses compact packing below log2(q) bits per coefficient by taking advantage of the gap between q=769 and 1,024. The specification and implementation disagree on the secret-key size.

Flit256 uses N=1024, n=256, q=769, d=8, delta=2^-176.1, with 32-byte seeds and shared secret.

Flit512 uses N=2048, n=512, q=3329, d=9, delta=2^-195.5, with 64-byte seeds and shared secret. The public key uses N*12/8 bytes at full width; there is no compact packing for q=3329.

HARE

Parameter set Claimed level Public key Secret key Ciphertext
HARE-1 128-bit classical / 64-bit quantum (aligned with NIST level 1) 2,025 2,073 3,608
HARE-2 (implementation dir 'HARE-128') 128-bit classical / 80-bit quantum 2,629 2,677 4,688
HARE-3 192-bit classical / 96-bit quantum (aligned with NIST level 3) 4,106 4,178 7,386
HARE-5 (implementation dir 'HARE-256') 256-bit classical / 128-bit quantum (aligned with NIST level 5) 6,580 6,676 11,790
HARE-7 (implementation dir 'HARE-384') 384-bit classical / 192-bit quantum 13,157 13,301 23,693
HARE-9 (implementation dir 'HARE-512') 512-bit classical / 256-bit quantum 21,812 22,004 39,294

HARE-1 uses n=16067, k=128, w=66, wr=we=105, n1=41, n2=384, alpha=7. The DFR is < 2^-128. The shared secret is 16 bytes, as are the seed and K; the salt is eight bytes. These sizes follow the classical security level. The table gives the expanded secret key dkKEM = ekKEM // dkPKE // sigma // seedKEM, which includes the public key. A seed-only secret key would be 16 bytes.

No implementation is included for this set.

HARE-2 (implementation dir 'HARE-128') uses n=20899, k=128, w=79, wr=we=145, n1=32, n2=640, alpha=11. The DFR is < 2^-130. The shared secret is 16 bytes. The implementation calls this set HARE-128-kr.

HARE-3 uses n=32653, k=192, w=100, wr=we=163, n1=51, n2=640, alpha=11. The DFR is < 2^-194. The shared secret is 24 bytes. No implementation is included for this set.

HARE-5 (implementation dir 'HARE-256') uses n=52379, k=256, w=131, wr=we=224, n1=81, n2=640, alpha=9. The DFR is < 2^-258. The shared secret is 32 bytes.

HARE-7 (implementation dir 'HARE-384') uses n=104869, k=384, w=193, wr=we=361, n1=91, n2=1152, alpha=15. The DFR is < 2^-384 under Model 1. The shared secret is 48 bytes.

HARE-9 (implementation dir 'HARE-512') uses n=173981, k=512, w=259, wr=we=449, n1=151, n2=1152, alpha=13. The DFR is < 2^-519 under Model 1. The shared secret is 64 bytes.

HEP-QC

Parameter set Claimed level Public key Secret key Ciphertext
HEP-QC-1 128 (security level 1) 285,889 285,969 4,433
HEP-QC-3 192 (security level 3) 866,210 866,298 8,978
HEP-QC-5 256 (security level 5) 1,852,485 1,852,581 14,421
HEP-QC-7 512 (security level 7) 12,644,449 12,644,577 49,297

HEP-QC-1 uses n1=46, n2=384, n=17669, k=128, omega=66, omega_r=omega_e=75. The DFR is < 2^-128. The seed and shared key are 32 bytes each, and the salt is 16 bytes. The encapsulation-key size is ek = /seed/ + ceil(n/8) + 8k*ceil(n/64), with the masked generator matrix accounting for most of it. The decapsulation-key size is dk = ek + 2/seed/ + ceil(k/8).

The 4,433-byte ciphertext has the same size as HQC-128.

HEP-QC-3 uses n1=56, n2=640, n=35851, k=192, omega=100, omega_r=omega_e=114. The DFR is < 2^-192. The 8,978-byte ciphertext has the same size as HQC-192.

HEP-QC-5 uses n1=90, n2=640, n=57637, k=256, omega=131, omega_r=omega_e=149. The DFR is < 2^-256. The 14,421-byte ciphertext has the same size as HQC-256.

HEP-QC-7 uses n1=220, n2=896, n=197123, k=512, omega=261, omega_r=omega_e=297. The DFR is < 2^-512.

LoongKEM

Parameter set Claimed level Public key Secret key Ciphertext
Loong128 128-bit classical (lambda = 128) 1,472 1,832 1,512
Loong256 256-bit classical (lambda = 256) 3,248 3,888 3,520
Loong384 384-bit classical (lambda = 384) 6,444 7,365 6,680
Loong512 512-bit classical (lambda = 512) 10,640 11,864 10,848

Loong128 uses q=8191=2^13-1, N=12, (k1,k2)=(48,4), eta=5, (db,du,dv)=(10,10,4), delta=2^-141. The shared key is 16 bytes. The seed is 32 bytes. The public key contains the seed for A, of size lambda/8 + 16 bytes, and the compressed b. The implementation uses a 312 + 1472 + 32 + 32 = 1848-byte secret key, containing the noise polynomial, public key, hash, and seed.

This is 16 bytes larger than the specification value of 1,832 bytes, which corresponds to a 16-byte hash.

Loong256 uses q=8191, N=16, (k1,k2)=(64,6), eta=4, (db,du,dv)=(10,10,10), delta=2^-161. The shared key is 32 bytes. The seed is 48 bytes. The secret-key size is 560+3248+32+48 = 3888 bytes.

Loong384 uses q=8191, N=20, (k1,k2)=(72,8), eta=3, (db,du,dv)=(11,11,6), delta=2^-190. The shared key is 48 bytes. The seed is 64 bytes. The implementation gives a secret-key size of 800+6444+32+64 = 7340 bytes. Using a 48-byte hash instead gives 7,356 bytes, which suggests that the specification value of 7,365 has two digits transposed.

Loong512 uses q=8191, N=24, (k1,k2)=(80,10), eta=2, (db,du,dv)=(11,11,4), delta=2^-260. The shared key is 64 bytes. The seed is 80 bytes. The implementation gives a secret-key size of 1080+10640+32+80 = 11832 bytes. The specification value of 11,864 bytes corresponds to a 64-byte hash: 1080+10640+64+80.

Lore

Parameter set Claimed level Public key Secret key Ciphertext
Lore-128 (Lore-L1) 128-bit classical (97.4-bit quantum), n=512 k=1 t=2 545 821 641
Lore-256 (Lore-L2) 256-bit classical (220.5-bit quantum), n=512 k=2 t=2 1,058 1,942 1,153
Lore-384 (Lore-L3) 384-bit classical (329.5-bit quantum), n=512 k=3 t=4 1,763 3,704 1,921
Lore-512 (Lore-L4) 512-bit classical (509.5-bit quantum), n=768 k=3 t=4 2,626 5,373 2,886

Lore-128 (Lore-L1) has larger stored sizes in the reference, AVX, and NEON implementations than those listed in the specification: a 610-byte public key, a 706-byte ciphertext, and a 2,108-byte KEM secret key, including a 1,434-byte PKE secret key. The implementations store Z_257 coefficients as one byte plus one bit, while the specification assumes an 8.008-bit lossless encoding.

The listed secret key appears to be the PKE key, containing a sparse fixed-weight t polynomial and a dense q polynomial. The KEM secret key also stores the public key and two 32-byte values.

Lore-256 (Lore-L2) has a 1,186-byte public key, a 1,282-byte ciphertext, and a 4,518-byte KEM secret key in the implementation. The latter includes a 3,268-byte PKE secret key.

Lore-384 (Lore-L3) has a 1,954-byte public key, a 2,114-byte ciphertext, and a 7,736-byte KEM secret key in the implementation. The latter includes a 5,718-byte PKE secret key.

Lore-512 (Lore-L4) has a 2,914-byte public key, a 3,170-byte ciphertext, and an 11,432-byte KEM secret key in the implementation. The latter includes an 8,454-byte PKE secret key. All Lore sets use a 32-byte shared secret.

MAMBA-Frost

Parameter set Claimed level Public key Secret key Ciphertext
Frost-128 128 (MATZOV 131.85, Core-SVP C/Q 107.75/98.58) 5,152 6,736 5,192
Frost-192 192 (MATZOV 197.65, Core-SVP C/Q 175.27/161.13) 9,712 11,528 9,760
Frost-256 256 (MATZOV 257.08, Core-SVP C/Q 236.36/216.55) 16,776 19,416 15,552
Frost-384 384 (MATZOV 393.79, Core-SVP C/Q 376.83/345.16) 25,096 29,032 37,736
Frost-CC-384 384 (same estimates as Frost-384) 37,628 43,492 25,204
Frost-512 512 (MATZOV 512.97, Core-SVP C/Q 498.68/456.47) 36,432 41,728 72,944
Frost-CC-512 512 (same estimates as Frost-512) 72,832 83,328 36,544

Frost-128 uses n=m=512, (l_r,l_s)=(8,8), q=2^15, eta=(2,2), (t_pk,t_u,t_v)=(10,10,5). The shared secret is 16 bytes. The secret key contains the packed PKE secret matrix, the public key, a 32-byte public-key hash, and the rejection string.

Frost-192 uses n=m=880, q=2^16, (t_pk,t_u,t_v)=(11,11,6). The shared secret is 24 bytes.

Frost-256 uses n=m=1288, q=2^16, (t_pk,t_u,t_v)=(13,12,8). The shared secret is 32 bytes.

Frost-384 uses n=m=1928, (l_r,l_s)=(8,12), q=2^16, (t_pk,t_u,t_v)=(13,13,9). The shared secret is 48 bytes.

Frost-CC-384 is the compact-ciphertext variant, with (l_r,l_s) swapped to (12,8). It uses the same assumption and FO transform. The public key and ciphertext still total 62,832 bytes, but the ciphertext is 33.2% smaller.

Frost-512 uses n=m=2600, (l_r,l_s)=(8,16), q=2^16, (t_pk,t_u,t_v)=(14,14,7). The shared secret is 64 bytes.

Frost-CC-512 is the compact-ciphertext variant, with (l_r,l_s) swapped to (16,8). The public key and ciphertext still total 109,376 bytes, but the ciphertext is 49.9% smaller.

MAMBA-Viper

Parameter set Claimed level Public key Secret key Ciphertext
MAMBA-Viper-128 128 (MATZOV 141.9, Core-SVP C/Q 118.6/108.7) 608 1,424 736
MAMBA-Viper-192 192 (MATZOV 199.4, Core-SVP C/Q 177.5/162.1) 992 2,200 1,088
MAMBA-Viper-256 256 (MATZOV 266.0, Core-SVP C/Q 246.2/225.3) 1,312 2,912 1,472
MAMBA-Viper-384 384 (MATZOV 410.2, Core-SVP C/Q 393.7/361.1) 2,496 5,488 2,656
MAMBA-Viper-512 512 (MATZOV 564.6, Core-SVP C/Q 549.5/521.0) 3,200 7,040 3,456

MAMBA-Viper-128 uses n=256, q=2^12, k=2, (eta_s,eta_r)=(2,2), (t_pk,t_u,t_v)=(9,9,4). The shared secret is 16 bytes. The secret key contains the uncompressed packed PKE secret at log2(q) bits per coefficient, the public key, a 32-byte public-key hash, and a fallback string.

MAMBA-Viper-192 uses n=256, q=2^12, k=3, eta=(3,3), (t_pk,t_u,t_v)=(10,9,6). The shared secret is 24 bytes.

MAMBA-Viper-256 uses n=256, q=2^12, k=4, eta=(3,3), (t_pk,t_u,t_v)=(10,10,5). The shared secret is 32 bytes.

MAMBA-Viper-384 uses n=256, q=2^13, k=7, eta=(1,1), (t_pk,t_u,t_v)=(11,11,5). The shared secret is 48 bytes.

MAMBA-Viper-512 uses n=256, q=2^13, k=9, eta=(1,1), (t_pk,t_u,t_v)=(11,11,8). The shared secret is 64 bytes.

Mithril

Parameter set Claimed level Public key Secret key Ciphertext
Mithril-128 128-bit classical / >=80-bit quantum (Core-SVP C/Q 129/117) 944 1,136 928
Mithril-256 256-bit classical / >=128-bit quantum (Core-SVP C/Q 257/233) 1,648 2,000 1,680
Mithril-512 512-bit classical / >=256-bit quantum (Core-SVP C/Q 526/478) 3,056 3,728 3,504

Mithril-128 uses n=128, k=5, l=1, (eps_q,eps_p,eps_t)=(13,11,3). The DFR is 2^-603. The shared secret is 16 bytes. The KEM secret key contains the 160-byte PKE secret key, the public key, a 16-byte public-key hash, and a 16-byte fallback value z.

Mithril-256 uses n=128, k=9, l=2, (eps_q,eps_p,eps_t)=(13,11,3). The DFR is 2^-280. The shared secret is 32 bytes.

Mithril-512 uses n=128, k=17, l=4, (eps_q,eps_p,eps_t)=(13,11,8). The DFR is 2^-230. The shared secret is 64 bytes.

Mito

Parameter set Claimed level Public key Secret key Ciphertext
Mito1-E-128 lambda=128 classical / 80 quantum 3,720 3,864 5,512
Mito1-128 lambda=128 classical / 80 quantum 3,908 4,052 5,796
Mito2-E-128 lambda=128 classical / 80 quantum 5,192 5,336 6,440
Mito1-E-256 lambda=256 classical / 128 quantum 8,130 8,290 12,130
Mito1-256 lambda=256 classical / 128 quantum 8,522 8,682 12,714
Mito2-E-256 lambda=256 classical / 128 quantum 10,828 10,988 13,484
Mito1-E-512 lambda=512 classical / 256 quantum 25,674 25,866 38,442
Mito1-512 lambda=512 classical / 256 quantum 26,630 26,822 39,878
Mito2-E-512 lambda=512 classical / 256 quantum 32,712 32,904 40,840

Mito1-E-128 uses a 2-adic construction with distance-informed erasure decoding. Its parameters are n=14621, n'=14592, and its DFR is 2^-167.99.

Mito1-128 uses a 2-adic construction with classical RSRM concatenated decoding. Its parameters are n=15373, n'=15360, and its DFR is 2^-173.34. The public key is the encapsulation key ek, and the secret key is the decapsulation key dk. The latter comes from a single 64-byte master seed and has size dk = ek + 2*64 + lambda/8 bytes. All Mito sets use a 64-byte shared secret.

Mito2-E-128 uses a 2^2-adic construction designed for multiple cores, with erasure decoding. Its parameters are n=10253, n'=10240, and its DFR is 2^-181.39.

Mito1-E-256 uses n=32261, n'=32256. The DFR is 2^-265.48.

Mito1-256 uses n=33827, n'=33792. The DFR is 2^-272.79.

Mito2-E-256 uses n=21523, n'=21504. The DFR is 2^-269.97.

Mito1-E-512 uses n=102437, n'=102400. The DFR is 2^-517.00.

Mito1-512 uses n=106261, n'=106240. The DFR is 2^-516.22.

Mito2-E-512 uses n=65293, n'=65280. The DFR is 2^-547.37.

MORNING-Scabbard

Parameter set Claimed level Public key Secret key Ciphertext
Scabbard-128 >=128-bit classical / >=80-bit quantum 736 1,056 760
Scabbard-256 >=256-bit classical / >=128-bit quantum 1,616 2,256 1,648
Scabbard-512 >=512-bit classical / >=256-bit quantum 2,880 4,032 3,072

Scabbard-128 uses l=9, n=64, q=2^14, p=2^10, t=2^3, kappa=16, eta=2, with four-bit encoding and B=2 message bits per coefficient. The shared secret is 16 bytes. The decapsulation key contains the 288-byte PKE secret packed at four bits per coefficient, the public key, and another 2*kappa bytes.

Scabbard-256 uses l=9, n=128, q=2^13, p=2^11, t=2^2, kappa=32. The shared secret is 32 bytes.

Scabbard-512 uses l=8, n=256, q=2^13, p=2^11, t=2^6, kappa=64. The shared secret is 64 bytes.

NEV

Parameter set Claimed level Public key Secret key Ciphertext
NEV-C1* (NEV-C1-c, n=512, q=769, compressed) >=128-bit classical / >=80-bit quantum; core-SVP NTRU (132,116), RLWE (135,118) 615 1,246 512
NEV-C1 (n=512, q=769, uncompressed) >=128-bit classical / >=80-bit quantum 615 1,246 615
NEV-R1 (n=512, q=1409) >=128-bit classical / >=80-bit quantum; core-SVP NTRU (135,119), RLWE (135,119) 672 1,360 672
NEV-D1 (n=512, q=3329) >=128-bit classical / >=80-bit quantum; core-SVP NTRU (135,118) 768 1,552 768
NEV-C2* (NEV-C2-c, n=1024, q=769, compressed) >=256-bit classical / >=128-bit quantum; core-SVP NTRU (266,234), RLWE (300,264) 1,229 2,490 1,024
NEV-C2 (n=1024, q=769, uncompressed) >=256-bit classical / >=128-bit quantum 1,229 2,490 1,229
NEV-R2 (n=1024, q=1409) >=256-bit classical / >=128-bit quantum; core-SVP NTRU (284,250) 1,344 2,720 1,344
NEV-D2 (n=1024, q=3329) >=256-bit classical / >=128-bit quantum; core-SVP NTRU (280,246) 1,536 3,104 1,536
NEV-C3* (NEV-C3-c, n=2048, q=769, compressed) >=512-bit classical / >=256-bit quantum; core-SVP NTRU (546,480), RLWE (610,537) 2,458 4,980 2,048
NEV-C3 (n=2048, q=769, uncompressed) >=512-bit classical / >=256-bit quantum 2,458 4,980 2,458
NEV-R3 (n=2048, q=1409) >=512-bit classical / >=256-bit quantum; core-SVP NTRU (583,513) 2,688 5,440 2,688
NEV-D3 (n=2048, q=3329) >=512-bit classical / >=256-bit quantum; core-SVP NTRU (572,503) 3,072 6,208 3,072

NEV-C1* (NEV-C1-c, n=512, q=769, compressed) uses the implementation secret-key size because the specification does not list one. Its ciphertext is compressed from R_769 to R_256, using a rounding-based assumption.

NEV-C1 (n=512, q=769, uncompressed) is the uncompressed variant, with a ciphertext the same size as the public key.

NEV-R1 (n=512, q=1409) is a recommended set.

NEV-D1 (n=512, q=3329) is designed around its DFR.

NEV-C2* (NEV-C2-c, n=1024, q=769, compressed) uses the implementation secret-key size because the specification does not list one.

NEV-C2 (n=1024, q=769, uncompressed) is the uncompressed variant, with a ciphertext the same size as the public key.

NEV-R2 (n=1024, q=1409) is a recommended set.

NEV-D2 (n=1024, q=3329) is designed around its DFR.

NEV-C3* (NEV-C3-c, n=2048, q=769, compressed) uses the implementation secret-key size because the specification does not list one.

NEV-C3 (n=2048, q=769, uncompressed) is the uncompressed variant, with a ciphertext the same size as the public key.

NEV-R3 (n=2048, q=1409) is a recommended set.

NEV-D3 (n=2048, q=3329) is designed around its DFR.

NSS-HQC

Parameter set Claimed level Public key Secret key Ciphertext
NSS-HQC-128 128-bit classical / 80-bit quantum 3,713 3,777 5,185
NSS-HQC-256 256-bit classical / 128-bit quantum 6,844 6,908 9,084
NSS-HQC-384 384-bit classical / 192-bit quantum 15,371 15,467 18,571
NSS-HQC-512 512-bit classical / 256-bit quantum 27,302 27,430 31,462

NSS-HQC-128 includes the full KEM ciphertext ct//salt, consisting of a 5,153-byte PKE body and a 32-byte salt. The secret key is seed_sk // sigma // pk, so it includes the public key. An optional expanded cache uses 4,069 bytes. The shared secret is 32 bytes.

NSS-HQC-256 has a ciphertext containing a 9,052-byte PKE body and a 32-byte salt. The secret key includes the public key; an expanded cache uses 7,376 bytes. The shared secret is 32 bytes.

NSS-HQC-384 has a ciphertext containing an 18,523-byte PKE body and a 48-byte salt. The secret key includes the public key; an expanded cache uses 16,211 bytes. The shared secret is 48 bytes.

NSS-HQC-512 has a ciphertext containing a 31,398-byte PKE body and a 64-byte salt. The secret key includes the public key; an expanded cache uses 28,479 bytes. The shared secret is 64 bytes.

NTRE

Parameter set Claimed level Public key Secret key Ciphertext
NTRE-128 (NTRE-2593-648) NGCC level 1; 132-bit classical / 118-bit quantum 972 1,976 972
NTRE-256 (NTRE-2917-1296) NGCC level 2; 290-bit classical / 259-bit quantum 1,944 3,920 1,944
NTRE-512 (NTRE-3457-2304) NGCC level 3; 584-bit classical / 513-bit quantum 3,456 6,944 3,456

NTRE-128 (NTRE-2593-648) uses n=648, q=2593. The DFR is 2^-549. The shared secret is 64 bytes. The secret key stores f and h plus a 32-byte seed.

NTRE-256 (NTRE-2917-1296) uses n=1296, q=2917. The DFR is 2^-370. The shared secret is 64 bytes.

NTRE-512 (NTRE-3457-2304) uses n=2304, q=3457. The DFR is 2^-298. The shared secret is 64 bytes.

OAEP-NTRU

Parameter set Claimed level Public key Secret key Ciphertext
OAEP-NTRU-648 >=128-bit classical / >=80-bit quantum (target); estimated 141 classical / 135 quantum 1,053 2,138 1,085
OAEP-NTRU-1296 >=256-bit classical / >=128-bit quantum (target); estimated 262 classical / 246 quantum 2,430 4,924 2,494
OAEP-NTRU-2592 >=512-bit classical / >=256-bit quantum (target); estimated 512 classical / 468 quantum 4,860 9,848 4,988

OAEP-NTRU-648 uses n=648, q=7129, with a 32-byte encapsulated key and correctness error 2^-159. The ciphertext contains a 1,053-byte polynomial and a 32-byte key-confirmation tag. The secret-key size is 2*1053 + 32 bytes.

OAEP-NTRU-1296 uses n=1296, q=17497, with a 32-byte encapsulated key and correctness error 2^-978. The ciphertext size is 2430 + 64 bytes, and the secret-key size is 2*2430 + 64 bytes.

OAEP-NTRU-2592 uses n=2592, q=28513, with a 64-byte encapsulated key and correctness error 2^-652. The ciphertext size is 4860 + 128 bytes, and the secret-key size is 2*4860 + 128 bytes.

Polar-KEM

Parameter set Claimed level Public key Secret key Ciphertext
PolarKEM-128 NIST level 1; ~150-bit classical / ~134-bit quantum (primal BKZ) 1,024 2,048 768
PolarKEM-256 NIST level 3; ~296-bit classical / ~269-bit quantum (primal BKZ) 2,048 4,096 1,280
PolarKEM-512 NIST level 5; ~618-bit classical / ~561-bit quantum (primal BKZ) 4,096 8,192 2,304

PolarKEM-128 uses N=512, q=12289, L=5. The DFR is < 2^-128. The shared secret is 16 bytes. The secret key contains a 32-byte implicit-rejection seed and the public key. In the implementation, the public key itself contains a 16-byte header, a 32-byte seed, and 976 bytes of zero padding.

PolarKEM-256 uses N=1024, q=12289, L=5. The DFR is < 2^-256. The shared secret is 32 bytes. The ciphertext contains an N*d/8 = 1152-byte payload, a 32-byte tag, a 16-byte header, and padding.

PolarKEM-512 uses N=2048, q=18433, L=6. The DFR is < 2^-512. The shared secret is 64 bytes.

PolarLAC

Parameter set Claimed level Public key Secret key Ciphertext
PolarLAC-Light 121.6-bit classical / 111.7-bit quantum (core-SVP); 143.8 / 138.8 (refined BKZ) 530 1,570 608
PolarLAC-128 132.5-bit classical / 122.6-bit quantum (core-SVP); 154.5 / 148.1 (refined BKZ) 530 1,570 640
PolarLAC-256 261.6-bit classical / 240.8-bit quantum (core-SVP); 280.8 / 263.4 (refined BKZ) 1,060 3,140 1,280
PolarLAC-512 512.1-bit classical / 482.5-bit quantum (core-SVP); 527.3 / 499.3 (refined BKZ) 2,116 6,276 2,560
PolarLAC-512* (POLARLAC-512-Star) 527.1-bit classical / 484.7-bit quantum (core-SVP); 540.1 / 500.3 (refined BKZ) 2,522 6,682 2,970

PolarLAC-Light uses k=2, n=256, q=257, d1=8, d2=3, lv=256. The DFR is 2^-159. The shared secret is 16 bytes. The secret key contains a 1,024-byte NTT-domain secret vector, the 530-byte public key, and a 16-byte implicit-rejection seed.

PolarLAC-128 uses k=2, n=256, q=257, d1=8, d2=4, lv=256. The DFR is 2^-146. The shared secret is 16 bytes. sk includes a copy of the pk.

PolarLAC-256 uses k=2, n=512, q=257, d1=8, d2=4, lv=512. The DFR is 2^-265. The shared secret is 32 bytes. sk includes a copy of the pk.

PolarLAC-512 uses k=2, n=1024, q=257, d1=8, d2=4, lv=1024. The DFR is 2^-324. The shared secret is 64 bytes. This set is recommended only for settings with a bounded number of queries.

PolarLAC-512* (POLARLAC-512-Star) uses k=2, n=1024, q=769, d2=4, lv=1024, with CRT packing averaging d1=9.6 bits per coefficient. The DFR is 2^-545. The shared secret is 64 bytes. This set is recommended for unrestricted query counts.

QIMEN-PIKE

Parameter set Claimed level Public key Secret key Ciphertext
NGCC-1 128-bit classical / 80-bit quantum 405 488 602
NGCC-2 256-bit classical / 128-bit quantum 595 737 882
NGCC-3 512-bit classical / 256-bit quantum 1,201 1,500 1,746

NGCC-1 uses compressed encoding. Without compression, the public key is 641 bytes, the ciphertext is 800 bytes, and the secret key is 724 bytes. The KEM secret key stores the PKE secret key, the public key, H(pk), and the implicit-rejection fallback z.

NGCC-2 uses compressed encoding. Without compression, the public key is 961 bytes, the ciphertext is 1184 bytes, and the secret key is 1,103 bytes.

NGCC-3 uses compressed encoding. Without compression, the public key is 1921 bytes, the ciphertext is 2368 bytes, and the secret key is 2,220 bytes.

QCTM

Parameter set Claimed level Public key Secret key Ciphertext
QCTM128 128-bit classical (estimated 150.87 bits after the quasi-cyclic discount) 167,987 192,545 640
QCTM256 256-bit classical (estimated 272.90 bits) 595,662 641,942 1,153
QCTM512 512-bit classical (estimated 530.30 bits) 2,374,727 2,467,243 2,264

QCTM128 uses m=18, n=10070, l=19, t=285, k=4957, w=142. The stored secret key is pk // Gamma' // s, so it includes the public key. The bare key material uses ceil((n+t)m/8) = 23,299 bytes. The shared secret is 32 bytes.

QCTM256 uses m=18, n=19000, l=19, t=513, k=9783, w=256. The bare private-key material uses 43,905 bytes. The stored secret key also includes the public key. The shared secret is 32 bytes.

QCTM512 uses m=18, n=38000, l=19, t=1007, w=503. The bare private-key material uses 87,766 bytes. The stored secret key also includes the public key. The shared secret is 64 bytes.

QUBE

Parameter set Claimed level Public key Secret key Ciphertext
QUBE-128 128-bit classical / >80-bit quantum 3,294 3,326 3,287
QUBE-192 192-bit classical (reference-only set, marked * in the spec) 6,364 6,412 6,362
QUBE-256 256-bit classical / >128-bit quantum 10,446 10,510 10,423
QUBE-384 384-bit classical / >192-bit quantum 20,738 20,834 20,633
QUBE-512 512-bit classical / >256-bit quantum 34,028 34,156 33,846

QUBE-128 uses r=13109 and concatenates shortened RS [34,16,19] with duplicated RM [384,8,192]. The secret key is sk_PKE // pk // rho_k, so it includes the public key. The shared secret is 16 bytes, and the ciphertext includes a 16-byte salt.

QUBE-192 uses r=25357. The specification includes this extra set for comparison with HQC, outside the four target sets. The shared secret is 24 bytes.

QUBE-256 uses r=41651. The shared secret is 32 bytes.

QUBE-384 uses r=82757. The shared secret is 48 bytes.

QUBE-512 uses r=135851. The shared secret is 64 bytes.

Rudraksh2

Parameter set Claimed level Public key Secret key Ciphertext
Rudraksh2-128-I 128-bit classical / 80-bit quantum 880 1,776 912
Rudraksh2-256-I 256-bit classical / 128-bit quantum 1,760 3,552 1,728
Rudraksh2-512-I 512-bit classical / 256-bit quantum 3,392 6,848 3,552
Rudraksh2-128-II 128-bit classical / 80-bit quantum Not stated Not stated Not stated
Rudraksh2-256-II 256-bit classical / 128-bit quantum Not stated Not stated Not stated
Rudraksh2-512-II 512-bit classical / 256-bit quantum Not stated Not stated Not stated

Rudraksh2-128-I uses l=9, n=64, q=3329, p=2^12, t=2^6, eta=2, lenK=128. The DFR is 2^-100. The secret key is s // pk // H(pk) // z, so it includes the public key. The shared secret is 16 bytes.

Rudraksh2-256-I uses l=9, n=128, q=3329, p=2^11, t=2^9, eta=1, lenK=256. The DFR is 2^-161. The secret key includes the public key. The shared secret is 32 bytes.

Rudraksh2-512-I uses l=8, n=256, q=7681, p=2^13, t=2^7, eta=2, lenK=512. The DFR is 2^-160. The secret key includes the public key. The shared secret is 64 bytes.

Rudraksh2-128-II uses l=9, n=64, q=4001, p=2^9, t=2^7, eta=1. No sizes are stated, and no implementation is included for any II variant. Applying the specification packing rules would give an 880-byte public key, a 1,776-byte secret key, and a 704-byte ciphertext; these are calculated sizes, not published values.

Rudraksh2-256-II uses l=9, n=128, q=4001, p=2^11, t=2^5, eta=1. No sizes are stated. The packing rules would give a 1,760-byte public key, a 3,552-byte secret key, and a 1,664-byte ciphertext; these are calculated sizes, not published values.

Rudraksh2-512-II uses l=9, n=256, q=4001, p=2^12, t=2^8, eta=1. No sizes are stated. The packing rules would give a 3,520-byte public key, a 7,104-byte secret key, and a 3,712-byte ciphertext; these are calculated sizes, not published values.

Scloud+

Parameter set Claimed level Public key Secret key Ciphertext
Scloud+-128 128-bit classical 6,096 7,440 6,160
Scloud+-192 192-bit classical 11,456 13,872 12,645
Scloud+-256 256-bit classical 16,296 19,680 17,925
Scloud+-384 384-bit classical 33,296 40,144 33,600
Scloud+-512 512-bit classical 48,016 57,872 48,320

Scloud+-128 uses (m,n)=(608,608), (mbar,nbar)=(8,8), q=2^10 and the BW32 coding lattice. The serialized secret key includes the public key and has size m*nbar*t + n*nbar*2 + 128 + 2h bits, with h=512. The shared secret is 16 bytes.

Scloud+-192 uses (m,n)=(832,832), (mbar,nbar)=(12,11), q=2^10, BW128, h=512. The secret key includes the public key. The shared secret is 24 bytes.

Scloud+-256 uses (m,n)=(1184,1184), (mbar,nbar)=(12,11), q=2^10, RBW128, h=512. The secret key includes the public key. The shared secret is 32 bytes.

Scloud+-384 uses (m,n)=(1664,1664), (mbar,nbar)=(16,16), q=2^10, BW128, h=768. The secret key includes the public key. The shared secret is 48 bytes.

Scloud+-512 uses (m,n)=(2400,2400), (mbar,nbar)=(16,16), q=2^10, RBW128, h=1024. The secret key includes the public key. The shared secret is 64 bytes.

TRIKE

Parameter set Claimed level Public key Secret key Ciphertext
TRIKE-1 128-bit classical / 64-bit quantum (NIST level 1; defined but NOT shipped) 1,304 4,220 2,592
TRIKE-2 128-bit classical / 80-bit quantum (ICCS set; submitted) 1,980 6,328 3,928
TRIKE-3 192-bit classical / 96-bit quantum (NIST level 3; defined but NOT shipped) 2,783 8,812 5,534
TRIKE-5 256-bit classical / 128-bit quantum (ICCS set; also NIST level 5; submitted) 4,453 13,988 8,874
TRIKE-7 384-bit classical / 192-bit quantum (ICCS set; submitted) 8,776 27,260 17,488
TRIKE-9 512-bit classical / 256-bit quantum (ICCS set; submitted) 14,320 44,228 28,576

TRIKE-1 uses r=10301, w=81, t=201, l=128. The DFR is 2^-128. The specification gives the sizes, but no implementation is included for this set.

TRIKE-2 uses r=15581, w=105, t=263, l=256. The DFR is 2^-128. The public-key size is ceil(r/8)+ceil(l/8), and the ciphertext size is 2*ceil(r/8)+ceil(l/8). The secret-key size is 4w + 3*ceil(r/8) + 2*ceil(l/8) in the expanded form intended for speed. The secret key can also be stored as a seed or as lists of positions.

TRIKE-3 uses r=22003, w=123, t=319, l=256. The DFR is 2^-192. The specification gives the sizes, but no implementation is included for this set.

TRIKE-5 uses r=35363, w=165, t=429, l=256. The DFR is 2^-256.

TRIKE-7 uses r=69691, w=249, t=659, l=512. The DFR is 2^-384.

TRIKE-9 uses r=114043, w=333, t=877, l=512. The DFR is 2^-512.

TriQ-KEM

Parameter set Claimed level Public key Secret key Ciphertext
TriQ-KEM-128 128-bit classical / 80-bit quantum (claimed ISD 146.67, Q-Prange 95.18) 2,054 2,102 4,086
TriQ-KEM-256 256-bit classical / 128-bit quantum (claimed ISD 277.04, Q-Prange 163.49) 6,328 6,424 12,472
TriQ-KEM-384 384-bit classical / 192-bit quantum (claimed ISD 404.13, Q-Prange 229.43) 12,255 12,399 24,335
TriQ-KEM-512 512-bit classical / 256-bit quantum (claimed ISD 532.06, Q-Prange 294.84) 19,768 19,960 39,320

TriQ-KEM-128 uses a 16-byte shared secret. The decapsulation key is dk_KEM = ek_KEM + dk_PKE(seed) + k/8 + seed, so it includes the encapsulation key and uses seed-based key material.

TriQ-KEM-256 uses a 32-byte shared secret, and the secret key includes the public key.

TriQ-KEM-384 uses a 48-byte shared secret, and the secret key includes the public key.

TriQ-KEM-512 uses a 64-byte shared secret, and the secret key includes the public key.

UVW-KEM

Parameter set Claimed level Public key Secret key Ciphertext
UVW128 128-bit classical / 80-bit quantum (Level 1) 208,013 35 1,032
UVW256 256-bit classical / 128-bit quantum (Level 2) 911,645 35 2,199
UVW512 512-bit classical / 256-bit quantum (Level 3) 4,001,850 67 4,820

UVW128 uses q=433, n=860, k=430, k1=k2=215, w=116, m=256. The private key is a seed and three indices, (seed, i1, i2, i3), totaling 35 bytes. The session key is 64 bytes, and the public key is the systematic-form matrix T.

UVW256 uses q=857, n=1708, k=854, k1=k2=427, w=232, m=256. The private key uses a seed, and the session key is 64 bytes.

UVW512 uses q=1709, n=3412, k=1706, k1=k2=853, w=463, m=512. The private key uses a seed, and the session key is 64 bytes.

Weaver

Parameter set Claimed level Public key Secret key Ciphertext
Weaver-640 Level 1 (Core-SVP 153 classical / 137 quantum) 752 1,776 816
Weaver-1024 Level 3 (Core-SVP 264 classical / 237 quantum) 1,312 3,072 1,536
Weaver-2048 Level 5 (Core-SVP 527 classical / 473 quantum) 2,880 6,400 3,392

Weaver-640 uses n=128, k=5, q=3329, (dt,du,dv)=(9,9,6) and a 128-bit shared secret. The secret key contains the 960-byte packed CPA secret, the full 752-byte public key, a 32-byte H(pk), and a 32-byte implicit-rejection seed z.

Weaver-1024 uses n=256, k=4, q=7681, (dt,du,dv)=(10,10,8) and a 256-bit shared secret.

Weaver-2048 uses n=512, k=4, q=7681, (dt,du,dv)=(11,11,9) and a 512-bit shared secret.

YuanYang.KEM

Parameter set Claimed level Public key Secret key Ciphertext
YuanYang.KEM-512 128 bits (Core-SVP: key recovery 129 classical / 117 quantum; message recovery 128/116) 736 1,536 656
YuanYang.KEM-1024 256 bits (Core-SVP: key recovery 267 classical / 243 quantum; message recovery 256/232) 1,568 3,168 1,344
YuanYang.KEM-2048 512 bits (Core-SVP: key recovery 546 classical / 496 quantum; message recovery 520/472) 3,328 6,528 2,880

YuanYang.KEM-512 uses d=512, q=2689, k=3 and has DFR 2^-130.5. The shared secret is d/32 = 16 bytes. The specification does not list a secret-key size, but the reference implementation stores f, finvint, H(pk), K', and a full public-key copy.

YuanYang.KEM-1024 uses d=1024, q=4481, k=4 and has DFR 2^-270.2. The shared secret is 32 bytes. The secret key in the reference implementation includes the public key.

YuanYang.KEM-2048 uses d=2048, q=7681, k=4 and has DFR 2^-531.5. The shared secret is 64 bytes. The secret key in the reference implementation includes the public key.

ZEN

Parameter set Claimed level Public key Secret key Ciphertext
ZEN-128 128-bit classical / 80-bit quantum (CoreSVP 128) 615 1,303 512
ZEN-256 256-bit classical / 128-bit quantum (CoreSVP 257) 1,229 2,605 1,024
ZEN-512 512-bit classical / 256-bit quantum (CoreSVP 519) 2,458 5,210 2,048
ZEN-light compact option at the 128-bit target; CoreSVP 118 (spec notes this is below the 128-bit cutoff, so it is not the claimed level-1 row) 615 Not stated 448
ZEN-256-backup 256-bit classical / 128-bit quantum (CoreSVP 257) 1,229 Not stated 1,229
ZEN-512-backup 512-bit classical / 256-bit quantum (CoreSVP 519) 2,458 Not stated 2,458

ZEN-128 uses n=512, q=769 and compresses from 769 to 256. It has log2(DFR) = -128 and a 16-byte shared secret. The specification does not list a secret-key size. The table gives the implementation size, which includes the public key.

ZEN-256 uses n=1024, q=769 and compresses from 769 to 256. It has log2(DFR) = -175 and a 32-byte shared secret. The secret key in the implementation includes the public key.

ZEN-512 uses n=2048, q=769 and compresses from 769 to 256. It has log2(DFR) = -179 and a 64-byte shared secret. The secret key in the implementation includes the public key.

ZEN-light uses n=512, q=769 and compresses from 769 to 128, with log2(DFR) = -135. No implementation or secret-key size is available for this set. It shares n=512 and the 615-byte public key with ZEN-128; only ZEN-128, ZEN-256, and ZEN-512 have implementations.

ZEN-256-backup keeps the ciphertext uncompressed (769->769) to meet the stricter 2^-256 DFR target, with log2(DFR) = -256. It uses the same n, q, and public key as ZEN-256. No separate implementation or secret-key size is provided; the ZEN-256 layout would use 2,605 bytes.

ZEN-512-backup keeps the ciphertext uncompressed (769->769) to meet the stricter 2^-320 DFR target, with log2(DFR) = -339. No separate implementation or secret-key size is provided.

Appendix B: differences and missing information

Signatures

Aigis-Sig+

The specification does not list secret-key sizes, so the table uses the implementation's sizes. The specification gives conflicting totals for the public key and signature: 928 + 2014 = 2942 bytes in one place, but a 2,015-byte signature elsewhere, bringing the total to 2,943 bytes. The sizes listed here use the 2,015-byte signature.

BIT

Only the 128-, 256-, and 512-bit sets have implementations and secret-key sizes. The 80-, 192-, and 384-bit sets are described only in the specification. There is also an NTRU variant, but it has no parameter sets.

For the 80-bit set, the specification gives conflicting combined public-key and signature sizes of 1,563 bytes and 505 + 1057 = 1562 bytes. The sizes listed here add up to 1,562 bytes.

CEDRUS+C

The specification treats the SM3-derived primitives as ideal and warns that structural attacks on SM3's Merkle-Damgard construction may keep them from reaching the stated security levels. The claimed classical security is 8n bits.

CEDRUSɑ

As with CEDRUS+C, the security claims assume ideal SM3-derived primitives, and the specification warns that SM3's structure may weaken those claims.

Chinith

Chinith includes three schemes: SM4th, uBlockith, and Vistrutith. Each parameter set has a fixed signature length. The grinding and BAVC retry loop does not change that length.

COMPASS-SIG

The specification gives d=5 for the 512-bit set, while the reference implementation uses D=6. Only D=6 gives the published public-key and secret-key sizes of 7,648 and 4,608 bytes, so the specified d=5 is likely a typo.

CS

Signatures use rANS entropy coding, so the listed signature size is the maximum allocated size.

DOVE

Signatures contain n bytes plus a salt, giving a fixed total length.

Facto-DSA

The submission does not include public-key compression or private keys expanded from a seed.

FlexTree

The specification warns that the SM3-derived hash and XOF required by NICCS may fall short of the stated security targets because of Merkle-Damgard weaknesses in SM3. Category I targets 160-bit classical security rather than 128 bits.

Galas

Galas-160 uses lambda=160 but claims 128-bit classical security. A public key can be used for at most 2^80 messages.

GreatWall

The specification initially assigns 128 and 192 to L1, 256 to L3, and 512 to L5. A later clarification assigns 192 to Level 1, 256 to Level 2, and 512 to Level 3, with 128 as an extra variant. The table follows that clarification.

The specification does not give secret-key sizes. The listed sizes come from the implementation and equal the public-key sizes.

Lynxer

The team also mentions an unadopted Lynxer-128 set for the lowest level but gives no sizes for it.

MORNING-ATLAS

For ATLAS-192 and ATLAS-256, the optimized implementation declares secret-key and signature sizes that disagree with both its parameter definitions and the specification. The table uses the specification's sizes.

The 384-bit set has parameters but no published sizes.

OPS

The specification says the reference implementation supports only Level-1, although parameter definitions exist for all three levels.

Origami

The secret key is a master expansion seed, so signing requires rebuilding the hidden structure. The public key contains a seed and a stored residual coefficient vector rather than a dense MQ map.

The specification uses 1 KB = 1000 B; the sizes here are in bytes.

Phoenix

Signature length varies because of Octopus TFORS and the counter search. The listed sizes are measured averages, and reference and AVX2 builds differ by a few bytes.

The specification gives only signature sizes. Public keys are 2n bytes and secret keys are 4n bytes, as in SPHINCS+. Each of the ten parameter sets has both SHAKE and SM3 versions.

Qing Luan

The secret key contains only a seed of 32, 64, 96, or 128 bytes. It does not include the public key.

ReSolveD-ɑ

There is also a non-recommended variant, ReSolveD-alpha', with signatures 8-11% smaller. That variant is not part of the submission and is omitted here.

The public key contains a public seed and a syndrome. The secret key contains 2*lambda/8 bytes of seed material, and signatures have a fixed length for each parameter set.

Rhyme

Signature sizes are averages for a variable-length rANS encoding. The specification uses compression rates of 0.75-0.85, while the implementation reserves much larger maximum lengths of 5,156, 10,308, 14,436, and 20,612 bytes.

Shuttle

The secret key includes the public-key body.

Sigurd

The specification gives signature sizes of approximately 25,108, 74,756, and 282,692 bytes. These are sample encoded lengths, not maximum sizes.

For NGCC-128, the public-key formula gives 40 + 71 = 111 bytes, but the table lists 112. For NGCC-512, it gives 128 + 306 = 434 bytes, but the table lists 435. NGCC-256 agrees at 64 + 148 = 212 bytes. The listed sizes use 112, 212, and 435 bytes for the public keys.

The claimed quantum security levels are 80, 128, and 256 bits, below the conservative quantum RSD estimates of 104, 203, and 387 bits given elsewhere in the specification.

SQIsign2D²

The specification gives conflicting sizes for Level1-eff: a 64-byte public key and a 154-byte compressed signature in one place, but 65 and 168 bytes elsewhere. The sizes here use the latter figures, with compressed sizes in the main table and uncompressed sizes in the notes.

The submitters later assigned 128-bit classical and 80-bit quantum security to Level2, 256/128 to Level3, and 512/256 to Level5, without listing Level1. This conflicts with the original Level2 claim of 160-bit classical and 80-bit quantum security.

SQIsign2D-push^(1/2)

Four instances were implemented, but the submitters later withdrew Level-1.

SYDO

The printed secret-key formula, lambda + (n-k) + w*sum(eta_j), does not give the listed secret-key sizes. The reason for the difference is unclear.

Tins

The specification gives quantum attack costs of 2^128, 2^256, and 2^512 for the three sets. Those claims equal lambda and sit only about nine bits below the classical claims. The table preserves the specification's claims.

TRINE

The implementation prepends a salt that the specified size formula leaves out. Its signatures are therefore 2*lambda/8 bytes larger than the specified sizes, a difference of 32, 64, or 128 bytes. Signature length is fixed for each parameter set.

ShortSig-512 also has a 3,188,776-byte public key in the implementation, compared with 3,188,774 bytes in the specification. The main table uses the specification's sizes, with implementation sizes in the notes.

TSUOV

The specification gives TSUOV 128 a 778-byte public key, but its formula gives 778.5 bytes, which rounds up to 779. The implementation uses 779 bytes. The other sizes agree, and the hash and XOF are based on SM3.

UVW signature

The specification gives information-theoretic sizes, including signatures of 977, 1,934, and 3,928 bytes. The listed sizes describe the actual serialized keys and signatures. Public keys range from 5.6 MB to 90 MB.

VDOO

The specification gives key sizes in KB to one decimal place, using 1 KB = 1024 B. The specification's formulas give exact public-key byte counts, but secret-key sizes are approximate to within about 30 bytes because they depend on which free parameters of S and T are stored.

The specification gives conflicting signature sizes of 96 and 85 bytes at the 128-bit level. The sizes listed here use 85 bytes. The 96-byte figure appears to come from the original VDOO paper.

YuanYang.DSA

The signature payload has a tunable rANS budget. For example, a 535-byte budget at d=512 gives a 0.862% rejection rate. The listed signature size is the fixed maximum serialized length, not an average.

YuanYang.DSA and YuanYang.KEM are designed to share one NTRU key.

Key encapsulation

Aigis-Enc+

The specification lists secret-key seeds of 16, 32, and 64 bytes, while the implementations store secret keys of 1,456, 2,912, and 5,824 bytes.

The abstract's reference to NEV and 698 bytes appears to be left over from the NEV paper. It disagrees with the listed 656-byte public key.

BAG-Loong

The listed secret-key size is the seed used to regenerate the key. The implementation stores 5,064, 13,258, 24,368, or 38,150 bytes instead.

The implementation's KEM ciphertext adds a 16-byte salt to the PKE ciphertext listed in the specification.

BAG-Piglet

The listed secret key is a seed of lambda/8 bytes. The ciphertext size is for PKE; the KEM implementation adds a 16-byte salt at every level.

For BAG-Piglet-128, the specification gives n=47, m=43, while the implementation uses m=47, n=43, consistent with the specification's own f(X)=X^47+X^5+1. This swap does not affect byte sizes because the size formula depends on m*n. The other three rows agree with the code.

BIKE-MLThre

The specification gives sizes in bits, so the byte counts are rounded up. Its 12,323-, 12,579-, 40,973-, 41,229-, 150,001-, and 150,513-bit values become 1,541, 1,573, 5,122, 5,154, 18,751, and 18,815 bytes. Secret keys of 2,244, 4,640, and 10,340 bits become 281, 580, and 1,293 bytes.

The submitters label the 512-bit set experimental.

BRA

The specification lists compact seed-based secret keys of 98, 106, and 144 bytes. The implementation stores 1,176, 1,841, and 3,717 bytes because its secret key includes the public key.

BRQC

The specification lists compact seed-based private keys. The implementation stores expanded secret keys that also include the public key.

BW-KEM

The specification defines four recommended sets and four strengthened -s sets, but the implementation covers only c128, c256, and c512. Only those three have tabulated secret-key sizes. The listed -s secret-key sizes are calculated from the implementation's formula, while c384 secret-key sizes are unavailable.

C-Multi-UR-AG

The listed secret-key sizes describe compact seed-based keys. The implementation stores sk_seed + sigma + pk, including the public key.

CTL

The Chinese specification and the implementation documentation give a 2,353-byte ciphertext for CTL-512, while the English specification gives 2,305 bytes. The implementation documentation also claims 128-, 192-, and 256-bit security, while the specification claims 128, 256, and 512 bits.

The listed sizes use the compressed, encoded FO-KEM format.

DTRU

Each parameter set supports an uncompressed encoding and an optional lossless compressed encoding. The listed sizes use the uncompressed encoding.

The specification also gives exploratory DTRU-Light sets with sparse noise: n=1024 has a 1,024-byte ciphertext and 1,280-byte public key, while n=2048 has a 2,048-byte ciphertext and 2,560-byte public key. The authors do not recommend these sets, so they are omitted from the main table.

FLIT

The specification gives secret-key sizes of 839, 1,581, and 3,776 bytes, but the implementation uses 1,351, 2,605, and 6,336 bytes. The listed sizes follow the specification's smaller values.

The specification's sizes fit sk = pk + N/4 + 3*seed_bytes, with f packed at two bits per coefficient. This gives 615 + 128 + 96, 1229 + 256 + 96, and 3072 + 512 + 192 bytes, accounting for f^-1 in Z2[X]/(X^n+1), the FO seed, and the public-key hash. However, the prose says f is stored in uncompressed NTT form, which agrees with the implementation's larger sizes.

Flit128 and Flit256 also have SHAKE versions with the same sizes.

HARE

The specification defines HARE-1, 2, 3, 5, 7, and 9, while the implementation has four sets named for classical security: HARE-128 is HARE-2, HARE-256 is HARE-5, HARE-384 is HARE-7, and HARE-512 is HARE-9. HARE-1 and HARE-3 are comparison points against HQC at NIST levels 1 and 3 and have no implementation.

The listed secret-key sizes are for expanded decapsulation keys that include the full public key. The six seed-only sizes are 16, 16, 24, 32, 48, and 64 bytes.

HEP-QC

Public keys range from 0.28 MB to 12.6 MB because they include the masked generator matrix.

LoongKEM

The specification gives secret-key sizes of 1,832, 3,888, 7,365, and 11,864 bytes. The implementation uses 1,848, 3,888, 7,340, and 11,832 bytes. The main table follows the specification.

Most of the difference comes from the hash field: the specification's sizes fit 16-, 32-, 48-, and 64-byte fields, while the implementation always uses 32 bytes. Even with that adjustment, Loong384 gives 7,356 bytes rather than the published 7,365.

Lore

The specification disagrees with the implementation by 60-90 bytes for public keys and ciphertexts, and by a factor of about two to three for secret keys. The specification's secret-key formula, k*(2+512) + TotalHWT*2, also fails to give its stated values for L3 and L4.

MAMBA-Frost

The CC-128, CC-192, and CC-256 implementations have the same sizes as the corresponding non-CC profiles because l_r = l_s = 8 in those builds. They are not listed as separate parameter sets.

NEV

The scheme has nine main parameter sets plus three uncompressed C variants, giving twelve implementations. Names ending in -c identify compressed C variants, while NEV-C1, NEV-C2, and NEV-C3 are the uncompressed versions.

The specification gives no secret-key sizes, so the table uses the implementation's sizes. Shared secrets are 16, 32, and 64 bytes at the 128-, 256-, and 512-bit levels.

NSS-HQC

The specified ciphertext sizes of 5,153, 9,052, 18,523, and 31,398 bytes describe the PKE body without a salt. The KEM ciphertext sizes used here include the salt.

The implementation labels the parameters as provisional.

OAEP-NTRU

OAEP-NTRU-1296 has a 32-byte shared secret. The implementation's separate 64-byte value is the key-confirmation or hash field appended to the ciphertext.

Polar-KEM

The specification gives pk = (N^2/2)*ceil(log2 q) bits, about 57 KB at N=512. Elsewhere, the specification and implementation give public keys of 1,024, 2,048, and 4,096 bytes.

In the smallest set, the public key contains a 16-byte header, a 32-byte seed, and 976 bytes of zero padding. The secret key likewise contains a header, a 32-byte z, a copy of the public key, and padding. These round power-of-two sizes come from padding rather than the stated formulas.

The parameter names 128, 256, and 512 do not match the claimed NIST levels 1, 3, and 5.

PolarLAC

All five sets have SM3 and SHAKE versions with the same sizes. The security claims use both core-SVP and refined BKZ estimates, and the table includes both.

QIMEN-PIKE

Both compressed and uncompressed encodings are defined. The listed sizes use compressed encoding. The shared secret is 2*lambda bits.

QCTM

The specification gives public-key sizes of 167,919, 595,541, and 2,374,489 bytes. Its own size formula instead gives 167,987, 595,662, and 2,374,727 bytes, which are the values used here.

The secret-key difference has a separate explanation. The smaller sizes of 23,299, 43,905, and 87,766 bytes equal ceil((n+t)m/8). The larger serialized form includes the public key and the n-bit rejection seed s, giving pk + ceil((n+t)m/8) + ceil(n/8) bytes. The main table uses that serialized form.

QUBE

The reference implementation matches the specification, while some optimized sets use different parameters. For example, optimized qube-4 uses n=82757, n1=96, and n2=896, while the specification's QUBE-384 uses n1=128 and n2=640. The table follows the specification and reference implementation.

Rudraksh2

The specification defines three -I sets and three -II sets, but gives sizes and implementations only for the -I sets. The -II sizes remain unavailable.

Scloud+

The specification does not tabulate secret-key sizes. The listed sizes follow the secret-key length of m*nbar*t + n*nbar*2 + 128 + 2h bits.

TRIKE

The specification says it proposes five parameter sets but lists six: TRIKE-1, 2, 3, 5, 7, and 9. Only TRIKE-2, 5, 7, and 9 have implementations and known-answer tests. TRIKE-1 and TRIKE-3 are included in the table because the specification gives their sizes.

Secret-key size depends on whether the key is stored as a seed, a position list, or an expanded key. The sizes here use the expanded form, as do the implementations.

The formula sk = 4w + 3*ceil(r/8) + 2*ceil(l/8) gives 8,809 bytes for TRIKE-3 and 13,987 for TRIKE-5, while the specification gives 8,812 and 13,988. The listed sizes follow the specified values. The formula agrees for TRIKE-1, 2, 7, and 9.

Weaver

The submission contains two conflicting specifications. The older document, dated April 29, 2026, calls the sets Weaver-512, Weaver-1024, and Weaver-2048, uses n=256, k=2, and gives public-key/ciphertext sizes of 608/704, 1,184/1,312, and 2,336/2,688 bytes.

The table follows the newer design document, dated June 30, 2026, which matches the implementation. Each set has SHAKE and SM3 versions with identical sizes.

YuanYang.KEM

The specification does not give secret-key sizes, so the table uses the reference implementation's sizes.

ZEN

The specification defines six sets, but only ZEN-128, ZEN-256, and ZEN-512 have implementations and known-answer tests. ZEN-light and the two backup sets appear only in the specification and have no stated secret-key sizes.

According to the specification, power-of-two cyclotomic rings make the 192-bit and 384-bit levels impractical, so there are no sets for those levels.

Appendix C: key exchange candidates

The nine key exchange candidates are ADKEX (Authenticated Ding Key Exchange), AFS-KEX, CreTAKE, DKEX (Ding Key Exchange), Loom, MAMBA-NIKE, NEV-AKE, NIIKE, and TriQ-KEX.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment