Paper 2025/2059

Compact, Efficient and Non-Separable Hybrid Signatures

Julien Devevey, ANSSI
Morgane Guerreau, PQShield
Maxime Roméas, ANSSI
Abstract

The transition to post-quantum cryptography involves balancing the long-term threat of quantum adversaries with the need for post-quantum algorithms and their implementations to gain maturity safely. Hybridization, i.e. combining classical and post-quantum schemes, offers a practical and safe solution. We introduce a new security notion for hybrid signatures, Hybrid EU-CMA, which captures cross-protocol, separability, and recombination attacks that may occur during the post-quantum transition, while encompassing standard unforgeability guarantees. Using this framework, we adapt the Fiat-Shamir (with or without aborts) transform to build hybrid signature schemes that satisfy our notion from two identification schemes. Compared to simple concatenation of signatures, our construction (i) has no separability issues, (ii) reduces signature size, (iii) runs faster, and (iv) remains easily implementable. As a concrete application, we propose Silithium, a hybrid signature combining the identification schemes underlying EC-Schnorr and ML-DSA. Implementing Silithium requires only an ML-DSA implementation supporting the ``external $\mu$'' option during verification and an elliptic curve library. In the security analysis, we show that our scheme can be safely used along with ML-DSA and either EC-Schnorr or ECDSA. A proof-of-concept OpenSSL implementation demonstrates its practicality, simplicity, and performance.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-Quantum TransitionHybrid SignaturesFiat-Shamir
Contact author(s)
julien devevey @ ssi gouv fr
morgane guerreau @ pqshield com
maxime romeas @ ssi gouv fr
History
2025-11-09: approved
2025-11-07: received
See all versions
Short URL
https://ia.cr/2025/2059
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2059,
      author = {Julien Devevey and Morgane Guerreau and Maxime Roméas},
      title = {Compact, Efficient and Non-Separable Hybrid Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2059},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2059}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.