In M2 you saw that hash-based signatures (stateful LMS/XMSS and stateless SLH-DSA) rest on a different trust model (hash function preimage resistance). In this lesson we make the general-purpose, stateless member of that family, SLH-DSA, concrete with FIPS 205’s own size table, and get to know the third lattice-based signature family, FN-DSA (Falcon), with its real (pre-draft) status today.
SLH-DSA: ‘s’ or ‘f’, a real trade-off
FIPS 205 defines 12 parameter sets; each is a hash family (SHA2/SHAKE), a security parameter, and a choice of ‘s’ (small signature) or ‘f’ (fast signing). Even within the same category the choice makes a big difference: SLH-DSA-SHA2-128s has a public key of 32 BSOURCED and a signature of 7856 BSOURCED, while SLH-DSA-SHA2-128f in the same category (category 1) has a signature of 17088 BSOURCED, more than twice as large. What you get for that price is faster signing; the ‘s’ variant does more computation while signing to keep the signature small, and the ‘f’ variant does the opposite. The same pattern repeats in the other two categories: 192s pk 48 BSOURCED/sig 16224 BSOURCED (category 3SOURCED), 256s pk 64 BSOURCED/sig 29792 BSOURCED (category 5SOURCED).
Remember XMSS’s hard ceiling of 2^20 signatures from M2: once the OTS keys ran out, a new key was needed. Because SLH-DSA is stateless it does not carry that limit; FIPS 205’s own footnote makes this concrete: the parameter sets were designed for up to 2^64SOURCED signatures, and “even if you signed 10 billion times per second, using up this number would take more than 58 years.” That is the concrete counterpart of the state discussion in M2: the price of choosing SLH-DSA is size (larger signatures than LMS/XMSS), and the gain is that the state management risk disappears entirely.
FN-DSA: the smallest signature, but not even a draft yet
The third signature family, FN-DSA, is based on the Falcon algorithm NIST selected and will be defined in FIPS 206. The summary of NIST’s own 2025 status presentation (Ray Perlner, Computer Security Division) is clear: “FN-DSA has very small signatures and public keys but is difficult to implement… significantly smaller than ML-DSA (FIPS 204)… Operations in KeyGen and Signing need floating-point arithmetic. This can lead to challenges for validation and side-channel protection.” So the price of FN-DSA’s small size is that signing requires floating-point arithmetic, which makes writing a constant-time, side-channel-safe implementation a much harder engineering problem than for ML-DSA or SLH-DSA. NIST’s own presentation devotes a long section to this difficulty (floating point, validation, side channels) and mentions a consultation process with the Falcon team lasting “a few years”. It is a reasonable inference that this difficulty contributed to FIPS 206 arriving much later than the other three FIPS (203/204/205), but the presentation does not state it explicitly as the single, direct cause.
Status, live-verified: the same presentation says “We expect to release an Initial Public Draft soon… It’s basically written, awaiting approval” (2025). If you check directly today (September 2026) (csrc.nist.gov/pubs/fips/206/ipd), the address still returns 404, so the IPD has not been published. FN-DSA is SELECTED2022-07-05 with not even a draft. The figures in falcon-sign.info’s own original specification (Falcon-512 pk 897 BSOURCED/sig 666 BSOURCED, Falcon-1024 pk 1793 BSOURCED/sig 1280 BSOURCED) are the only concrete reference available today, but they are not FIPS 206’s own text. When someone tells an architect “we support FN-DSA”, the question to ask is “against which specification, given that FIPS 206 does not exist yet?”
Numbers to know
SLH-DSA-SHA2-128s: pk 32 B, sig 7856 B, category 1, 's' (small signature). SLH-DSA-SHA2-128f: same category 1 but sig 17088 B; 'f' (fast) signs faster in exchange for a larger signature
Because SLH-DSA is stateless it can sign practically without limit (FIPS 205's own note: even at 10 billion signatures per second, using up 2^64 signatures would take more than 58 years); the exact opposite of XMSS's hard 2^20 ceiling in M2
FN-DSA (FIPS 206, Falcon) is still pre-draft today (September 2026): NIST's own 2025 presentation says 'IPD basically written, awaiting approval', and a live check confirms the IPD has not been published
Lab: Check FN-DSA's live status yourself
[not run] This is a live verification exercise, not a runnable command
404 Not Found (as of when this lesson was written, September 2026); direct evidence that FIPS 206 has no Initial Public Draft yet, without relying on second-hand news
At the table
How to say this in a bank meeting.
To an executive
FN-DSA (Falcon) is the candidate with the smallest signature and key sizes, but it does not even have a draft yet. Tying our production decisions to it today is premature; we should move forward with ML-DSA or SLH-DSA.
To an architect
The choice between SLH-DSA's 's' (small signature, slow) and 'f' (large signature, fast) variants depends on signing frequency: for a rarely signed, long-lived root certificate 's' is reasonable; in an operational scenario that signs often, 'f''s speed advantage may be worth a signature more than twice as large.
Objection
“"FN-DSA gives the smallest signature. Why not wait for it instead of moving forward with ML-DSA or SLH-DSA?"”
Answer
FN-DSA's signing process needs floating-point arithmetic, which, as NIST's own 2025 presentation admits, makes constant-time and side-channel-safe implementation harder; that is why its standardization has lagged ML-DSA and SLH-DSA by years and it is still pre-draft. Today's production decisions should rest on the two families that are final today (ML-DSA, SLH-DSA); once FN-DSA is final, it can be added where its size advantage is needed.
NIST CSRC, 2025. A first-hand explanation from NIST's own staff of FN-DSA's draft status (IPD 'basically written, awaiting approval') and its floating-point difficulty
"Where FIPS 206 (FN-DSA) stands", "FIPS 206 and FN-DSA" slides / 10 min
Falcon team (falcon-sign.info), 2020. The source of the original, pre-FIPS size figures of Falcon, on which FN-DSA is based; the only concrete size reference available today, since FIPS 206 has not published a draft
performance/parameter table / 5 min
Commercial stake: The Falcon team's own site; the figures are the original pre-FIPS submission values, not NIST's official FIPS 206 text
Checkpoint
Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.
01Recall
What is the difference between SLH-DSA-SHA2-128s and SLH-DSA-SHA2-128f, and which category are both in?
Model answer
Both are category 1, but SLH-DSA-SHA2-128s has a 7856-byte signature while SLH-DSA-SHA2-128f has a 17088-byte signature, more than twice as large. 's' (small signature) does more computation to keep the signature small; 'f' (fast signing) produces a larger signature in exchange for faster signing.
02Recall
What standardization status does FN-DSA have today, and how can you check it directly?
Model answer
Today (September 2026) FN-DSA is SELECTED; not even its draft (IPD) has been published. To check directly, open csrc.nist.gov/pubs/fips/206/ipd; that address still returns 404.
03Scenario
An IoT firmware signing scenario needs thousands of signatures per second, and signature size is a secondary priority. Which SLH-DSA variant do you recommend, and why?
Model answer
The 'f' (fast signing) variant, because in this scenario signing speed is the priority and size is secondary. The 'f' variant signs faster in exchange for a larger signature (for example 17088 bytes for 128f, more than twice 128s); in an operational scenario that signs often, that trade-off makes sense.
A complete answer includes
Your score: 0/3
04Hostile
A vendor says 'We already support FN-DSA, Falcon-based.' Knowing FIPS 206's real status, how do you question this claim?
Model answer
Ask the vendor which specification they support, because FIPS 206 has not even reached the draft (IPD) stage today (September 2026); it is still SELECTED. The only concrete size reference available is the original, pre-FIPS Falcon specification on falcon-sign.info; the vendor's support most likely rests on that original Falcon submission rather than NIST's official FIPS 206 text, and the side-channel and validation difficulties of floating-point arithmetic have not yet been settled in a FIPS.
A complete answer includes
Your score: 0/3
Project linkContributes to the algorithm selection matrix of Project 4 (capstone) as the size, speed and status rationale for choosing a signature family (ML-DSA/SLH-DSA/FN-DSA).