M4 / Signatures

SLH-DSA and FN-DSA

FoundationsPractitionerAdvisor

After this lesson you can

  • State the size/speed trade-off between SLH-DSA's (FIPS 205) 's' and 'f' variants and the real signature budget
  • Explain in the right frame, with its live-verified current status, why FN-DSA (FIPS 206, draft) is still at the draft stage

Before thisML-DSA (FIPS 204)

Mental model

In M2 you saw that hash-based signatures (stateful LMS/XMSS and stateless SLH-DSA) rest on a different trust model (hash function preimage resistance). In this lesson we make the general-purpose, stateless member of that family, SLH-DSA, concrete with FIPS 205’s own size table, and get to know the third lattice-based signature family, FN-DSA (Falcon), with its real (pre-draft) status today.

SLH-DSA: ‘s’ or ‘f’, a real trade-off

FIPS 205 defines 12 parameter sets; each is a hash family (SHA2/SHAKE), a security parameter, and a choice of ‘s’ (small signature) or ‘f’ (fast signing). Even within the same category the choice makes a big difference: SLH-DSA-SHA2-128s has a public key of 32 BSOURCED and a signature of 7856 BSOURCED, while SLH-DSA-SHA2-128f in the same category (category 1) has a signature of 17088 BSOURCED, more than twice as large. What you get for that price is faster signing; the ‘s’ variant does more computation while signing to keep the signature small, and the ‘f’ variant does the opposite. The same pattern repeats in the other two categories: 192s pk 48 BSOURCED/sig 16224 BSOURCED (category 3SOURCED), 256s pk 64 BSOURCED/sig 29792 BSOURCED (category 5SOURCED).

Remember XMSS’s hard ceiling of 2^20 signatures from M2: once the OTS keys ran out, a new key was needed. Because SLH-DSA is stateless it does not carry that limit; FIPS 205’s own footnote makes this concrete: the parameter sets were designed for up to 2^64SOURCED signatures, and “even if you signed 10 billion times per second, using up this number would take more than 58 years.” That is the concrete counterpart of the state discussion in M2: the price of choosing SLH-DSA is size (larger signatures than LMS/XMSS), and the gain is that the state management risk disappears entirely.

FN-DSA: the smallest signature, but not even a draft yet

The third signature family, FN-DSA, is based on the Falcon algorithm NIST selected and will be defined in FIPS 206. The summary of NIST’s own 2025 status presentation (Ray Perlner, Computer Security Division) is clear: “FN-DSA has very small signatures and public keys but is difficult to implement… significantly smaller than ML-DSA (FIPS 204)… Operations in KeyGen and Signing need floating-point arithmetic. This can lead to challenges for validation and side-channel protection.” So the price of FN-DSA’s small size is that signing requires floating-point arithmetic, which makes writing a constant-time, side-channel-safe implementation a much harder engineering problem than for ML-DSA or SLH-DSA. NIST’s own presentation devotes a long section to this difficulty (floating point, validation, side channels) and mentions a consultation process with the Falcon team lasting “a few years”. It is a reasonable inference that this difficulty contributed to FIPS 206 arriving much later than the other three FIPS (203/204/205), but the presentation does not state it explicitly as the single, direct cause.

Status, live-verified: the same presentation says “We expect to release an Initial Public Draft soon… It’s basically written, awaiting approval” (2025). If you check directly today (September 2026) (csrc.nist.gov/pubs/fips/206/ipd), the address still returns 404, so the IPD has not been published. FN-DSA is SELECTED2022-07-05 with not even a draft. The figures in falcon-sign.info’s own original specification (Falcon-512 pk 897 BSOURCED/sig 666 BSOURCED, Falcon-1024 pk 1793 BSOURCED/sig 1280 BSOURCED) are the only concrete reference available today, but they are not FIPS 206’s own text. When someone tells an architect “we support FN-DSA”, the question to ask is “against which specification, given that FIPS 206 does not exist yet?”

Numbers to know

  • SLH-DSA-SHA2-128s: pk 32 B, sig 7856 B, category 1, 's' (small signature). SLH-DSA-SHA2-128f: same category 1 but sig 17088 B; 'f' (fast) signs faster in exchange for a larger signature
  • Because SLH-DSA is stateless it can sign practically without limit (FIPS 205's own note: even at 10 billion signatures per second, using up 2^64 signatures would take more than 58 years); the exact opposite of XMSS's hard 2^20 ceiling in M2
  • FN-DSA (FIPS 206, Falcon) is still pre-draft today (September 2026): NIST's own 2025 presentation says 'IPD basically written, awaiting approval', and a live check confirms the IPD has not been published

Lab: Check FN-DSA's live status yourself

[not run] This is a live verification exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Open csrc.nist.gov/pubs/fips/206/ipd
Recorded output
404 Not Found (as of when this lesson was written, September 2026); direct evidence that FIPS 206 has no Initial Public Draft yet, without relying on second-hand news

At the table

How to say this in a bank meeting.

To an executive
FN-DSA (Falcon) is the candidate with the smallest signature and key sizes, but it does not even have a draft yet. Tying our production decisions to it today is premature; we should move forward with ML-DSA or SLH-DSA.
To an architect
The choice between SLH-DSA's 's' (small signature, slow) and 'f' (large signature, fast) variants depends on signing frequency: for a rarely signed, long-lived root certificate 's' is reasonable; in an operational scenario that signs often, 'f''s speed advantage may be worth a signature more than twice as large.
Objection
“"FN-DSA gives the smallest signature. Why not wait for it instead of moving forward with ML-DSA or SLH-DSA?"”
Answer
FN-DSA's signing process needs floating-point arithmetic, which, as NIST's own 2025 presentation admits, makes constant-time and side-channel-safe implementation harder; that is why its standardization has lagged ML-DSA and SLH-DSA by years and it is still pre-draft. Today's production decisions should rest on the two families that are final today (ML-DSA, SLH-DSA); once FN-DSA is final, it can be added where its size advantage is needed.

Sources

  • NIST, 2024. The primary source for the full size and category table of SLH-DSA's 12 parameter sets (Table 2, p.43)

    section 11, Table 2, p.43 / 10 min

  • NIST CSRC, 2025. A first-hand explanation from NIST's own staff of FN-DSA's draft status (IPD 'basically written, awaiting approval') and its floating-point difficulty

    "Where FIPS 206 (FN-DSA) stands", "FIPS 206 and FN-DSA" slides / 10 min

  • Falcon team (falcon-sign.info), 2020. The source of the original, pre-FIPS size figures of Falcon, on which FN-DSA is based; the only concrete size reference available today, since FIPS 206 has not published a draft

    performance/parameter table / 5 min

    Commercial stake: The Falcon team's own site; the figures are the original pre-FIPS submission values, not NIST's official FIPS 206 text

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What is the difference between SLH-DSA-SHA2-128s and SLH-DSA-SHA2-128f, and which category are both in?

  2. 02Recall

    What standardization status does FN-DSA have today, and how can you check it directly?

  3. 03Scenario

    An IoT firmware signing scenario needs thousands of signatures per second, and signature size is a secondary priority. Which SLH-DSA variant do you recommend, and why?

  4. 04Hostile

    A vendor says 'We already support FN-DSA, Falcon-based.' Knowing FIPS 206's real status, how do you question this claim?

Project linkContributes to the algorithm selection matrix of Project 4 (capstone) as the size, speed and status rationale for choosing a signature family (ML-DSA/SLH-DSA/FN-DSA).