NIST submissions

From PQC WIKI

FINALISTS

A. Public-key Encryption and Key-establishment Algorithms

OP ID Validity Proposal Variant Round Owner Type Description Assumption Functionality Public Key
(bytes)
Private Key
(bytes)
Data Size
(bytes)
Comments Security Type Challenge Notes Date Cmt_link Website
R3_02 1 Classic McEliece 2 R3_02 code Conservative Binary Goppa SDP KEM level 1: 261120, level 3: 524160, level 5: 1044992,level 5: 1047319, level 5: 1357824 level 1: 6492, level 3: 13608, level 5: 13932, level 5: 13948, level 5: 14120 level 1: 128, level 3: 188, level 5: 240, level 5: 226, level 5: 240 Merger of Classic McEliece and NTS-KEM IND-CCA2 Goppa-McEliece Challenge https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/$20Classic$20McEliece$20%09%7Csort:date/pqc-forum/PvkX7Ne_9qI/6C3iwP9zAAAJ https://classic.mceliece.org
R3_04 1 CRYSTALS-KYBER 2 R3_04 lattice Module-LWE MLWE KEM level 1: 1632, level 3: 2400, level 5: 3168 level 1: 800, level 3: 1184, level 5: 1568 level 1: 768, level 3: 1088, level 5: 1568 IND-CCA https://pq-crystals.org/
R3_14 1 NTRU 2 R3_14 lattice NTRU ,, Merger of NTRUEncrypt and NTRU-HRSS-KEM. https://ntru.org/
R3_40 0 NTRU-HPS 2 R3_14 lattice NTRU KEM level 1: 931, level 3: 1230 level 1: 1235, level 3: 1592 level 1: 931, level 3: 1230 IND-CCA (SXY) The evaluations are on non-local models. For local models, the evaluation increse from level 1 to 3, 3 to 5 h
R3_41 0 NTRU-HRSS 2 R3_14 lattice NTRU KEM level 3: 1138 level 3: 1452 level 3: 1138 IND-CCA (SXY) The evaluations are on non-local models. For local models, the evaluation increse from level 1 to 3, 3 to 5
R3_23 1 SABER 2 R3_23 lattice LWR MLWR KEM level 1: 672, level 3: 992, level 5: 1312 level 1: 1568 (992), level 3: 2304 (1344), level 5: 3040 (1760) level 1: 736, level 3: 1088, level 5: 1472 IND-CCA https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/official$20comment$20round$202%7Csort:date https://www.esat.kuleuven.be/cosic/pqcrypto/saber/

B. Digital Signature Algorithms

OP ID Validity Proposal Variant Round Owner Type Description Assumption Functionality Public Key
(bytes)
Private Key
(bytes)
Signature Size
(bytes)
Comments Security Type Challenge Notes Date Cmt_link Website
R3_03 1 CRYSTALS-DILITHIUM 2 R3_03 lattice Module-LWE MLWE, MSIS Signature level 2: 1312, level 3: 1952, level 5: 2592 level 2: 2420, level 3: 3293, level 5: 4595 SUF-CMA https://pq-crystals.org/dilithium/
R3_05 1 FALCON 2 R3_05 lattice NTRU NTRU Signature level 1: 897, level 3: -, level 5: 1793 level 1: 666, level 3: -, level 5: 280 EUF-CMA https://falcon-sign.info/
R3_19 1 Rainbow 2 R3_19 multivariate UOV
R3_49 0 Standard Rainbow 2 R3_19 multivariate MQ Signature level 1: 157800, level 3: 861400, level 5: 1885400 level 1: 101200, level 3: 611300, level 5: 1375700 level 1: 66, level 3: 164, level 5: 212 EUF-CMA
R3_49 0 CZ-Rainbow 2 R3_19 multivariate MQ Signature level 1: 58800, level 3: 258400, level 5: 523600 level 1: 101200, level 3: 611300, level 5: 1375700 level 1: 64, level 3: 156, level 5: 204 EUF-CMA
R3_50 0 Compressed Rainbow 2 R3_19 multivariate MQ Signature level 1: 58800, level 3: 258400, level 5: 523600 level 1: 60, level 3: 60, level 5: 60 level 1: 64, level 3: 156, level 5: 204 EUF-CMA


ALTERNATE CANDIDATES

A. Public-key Encryption and Key-establishment Algorithms

OP ID Validity Proposal Variant Round Owner Type Description Assumption Functionality Public Key
(bytes)
Private Key
(bytes)
Data Size
(bytes)
Comments Security Type Challenge Notes Date Cmt_link Website
R3_01 1 BIKE 3a R3_01 code QC-MDPC QC-SD,QC-CF KEM level 1: 1540, level 3: 3082, level 5: 5099 level 1: 280, level 3: 418, level 5: 580 level 1: 1572, level 3: 3114, level 5: 5153 IND-CPA (BGF decoder),IND-CCA (low DFR) http://bikesuite.org/
R3_06 1 FrodoKEM 3a R3_06 lattice LWE LWE KEM level 1: 9616, level 3: 15632, level 5: 21520 level 1: 19888, level 3: 31296, level 5: 43088 level 1: 9720, level 3: 15744, level 5: 21632 IND-CCA https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/official$20comment$20round$202|sort:date/pqc-forum/_kBMTq3RM28/Zj2CpnEzBgAJ https://frodokem.org/
R3_08 1 HQC 3a R3_08 code QC random codes - no decoding Decision QC-SDP KEM level 1: 2249, level 3: 4522, level 5: 7245 level 1: 40, level 3: 40, level 5: 40 level 1: 4481, level 3: 9026, level 5: 14469 IND-CCA (HHK) https://pqc-hqc.org/
R3_15 1 NTRU Prime 3a R3_15 lattice NTRU Prime https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/official$20comment$20round$202|sort:date/pqc-forum/V1RNjpio5Ng/uzEDmsogAgAJ https://ntruprime.cr.yp.to
R3_42 0 Streamlined NTRUPrime 3a R3_15 lattice NTRU Prime KEM level 1: 994, level 2: 1158, level 3: 1322, level 4: 1349 , level 5: 2067 level 1: 1518, level 2: 1763, level 3: 1999, level 4: 1652, level 5: 3059 level 1: 897, level 2: 1039, level 3: 1184, level 4: 1477, level 5: 1847 IND-CCA2 https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/official$20comment$20round$202|sort:date/pqc-forum/V1RNjpio5Ng/uzEDmsogAgAJ https://ntruprime.cr.yp.to
R3_43 0 NTRU LPRime 3a R3_15 lattice NTRU Prime KEM level 1: 897, level 2: 1039, level 3: 1184, level 4: 1455 , level 5: 1847 level 1: 1125, level 2: 1294, level 3: 1463, level 4: 1773, level 5: 2231 level 1: 1025, level 2: 1167, level 3: 1312, level 4: 1583, level 5: 1975 IND-CCA2 https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/official$20comment$20round$202|sort:date/pqc-forum/V1RNjpio5Ng/uzEDmsogAgAJ https://ntruprime.cr.yp.to
R3_24 1 SIKE 3a R3_24 other Isogenies ,, ,, ,, https://groups.google.com/a/list.nist.gov/forum/#!searchin/pqc-forum/$20ROUND$202$20OFFICIAL$20COMMENT$3A$20SIKE%7Csort:date/pqc-forum/q4mEDtl6kt4/PF6P6XUpBwAJ http://sike.org/
R3_60 0 SIKE 3a R3_24 other SIDH KEM level 1: 330, level 2: 378, level 3: 462, level 5: 564 level 1: 374, level 2: 434, level 3: 524, level 5: 644 level 1: 346, level 2: 402, level 3: 486, level 5: 596 IND-CCA (HHK)
R3_61 0 SIKE_compressed 3a R3_24 other SIDH KEM level 1: 197, level 2: 225, level 3:274, level 5: 335 level 1: 350, level 2: 407, level 3:491, level 5: 602 level 1: 236, level 2: 280, level 3:336, level 5: 410 IND-CCA (HHK)

B. Digital Signature Algorithms

OP ID Validity Proposal Variant Round Owner Type Description Assumption Functionality Public Key
(bytes)
Private Key
(bytes)
Data Size
(bytes)
Comments Security Type Challenge Notes Date Cmt_link Website
R3_07 1 GeMSS 2 R3_07 multivariate Hidden Field Equations HFEv- Signature level 1: 352188, level 3: 1237963, level 5: 3040700 level 1: 16, level 3: 24, level 5: 32 level 1: 33, level 3: 52, level 5: 72 EUF-CMA All sizes taken from reference implementation. https://www-polsys.lip6.fr/Links/NIST/GeMSS.html
R3_17 1 Picnic 2 R3_17 hash Non-interactive Proof of Knowledge https://microsoft.github.io/Picnic/
R3_44 0 Picnic-FS 2 R3_17 other ZKB++ Signature level 1: 32, level 3: 48, level 5: 64 level 1: 16, level 3: 24, level 5: 32 level 1: 34032, level 3: 76772, level 5: 132856 SUF-CMA
R3_45 0 Picnic-UR 2 R3_17 other ZKB++ Signature level 1: 32, level 3: 48, level 5: 64 level 1: 16, level 3: 24, level 5: 32 level 1: 53961, level 3: 121845, level 5: 209506 SUF-CMA
R3_46 0 Picnic-full 2 R3_17 other ZKB++ Signature level 1: 34, level 3: 48, level 5: 66 level 1: 17, level 3: 24, level 5: 32 level 1: 320161, level 3: 71179, level 5: 126286 SUF-CMA
R3_46 0 Picnic3 2 R3_17 other ZKB++ Signature level 1: 34, level 3: 48, level 5: 66 level 1: 17, level 3: 24, level 5: 32 level 1: 13802, level 3: 29750, level 5: 54732 SUF-CMA
R3_25 1 SPHINCS+ 2 R3_25 hash Stateless XMSS ,, ,, ,, https://sphincs.org/
R3_62 0 SPHINCS+ Small 2 R3_25 hash PRF Signature level 1: 32, level 3: 48, level 5: 64 level 1: 64, level 3: 96, level 5: 128 level 1: 7856, level 3: 16224, level 5: 29792 EUF-CMA https://sphincs.org/
R3_63 0 SPHINCS+ Fast 2 R3_25 hash PRF Signature level 1: 32, level 3: 48, level 5: 64 level 1: 64, level 3: 96, level 5: 128 level 1: 17088, level 3: 35664, level 5: 49856 EUF-CMA https://sphincs.org/