Lune

S&P2026Top-tier venue

A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key Infrastructure

Kiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui, Attila A. Yavuz

2026Year

Abstract

The U.S. Federal Public Key Infrastructures (FPKI) relies on digital certificates and a network of Certificate Authorities (CAs) to build trust between federal agencies and their commercial partners. However, the current certificate generation process of FPKI faces two critical issues: The emerging quantum threats that jeopardize the security of conventionalsecure digital signatures and the systemic vulnerabilities introduced by centralized signing operations. While threshold Post-Quantum (PQ) signatures offer a promising foundation for compromise-resilient trust, their adoption within the FPKI remains constrained by strict standard compliance requirements. ML-DSA is a prominent construction for thresholding within the NIST-PQ standards. However, existing threshold constructions of ML-DSA diverge from the NIST standard, limiting algorithmic compliance and hindering adoption in regulated settings such as FPKI, which require thorough cryptanalysis and revalidation. Hence, no fully standard-compliant threshold PQ solution currently meets FPKI's need for a distributed and quantum-resistant trust infrastructure.

We introduce SHIELD, an efficient threshold NIST-PQcompliant signature framework that replaces its classical centralized counterpart in certificate generation within the FPKI. SHIELD provides several key properties that overcome the limitations of prior approaches. First, it achieves algorithmic FIPS-204 compliance and seamless functional interchangeability with standard ML-DSA, without altering the signing algorithm. Second, it conforms to FPKI's structural and operational requirements, provides high security against adversarial environments, and prevents fraudulent certificates by mitigating single-key compromise risks. Finally, we provide the opensource implementation of SHIELD. We empirically evaluated the performance of SHIELD under diverse network latency conditions to validate its practical conformance with FPKI operational needs. https://github.com/open-threshold-pqc/SHIELD.git • Compromise Resilience Against Arbitrary Malicious Corruptions. SHIELD provides quantum-UC-secure [56]

TABLE 1: Comparison of prior threshold ML-DSA vs. SHIELD's threshold ML-DSA for adoption in FPKI Work Algorithmic FIPS-204 Compliance Free of Security Revalidation Federal Interoperability Base Work Threshold Tools Concealing Rejected Signature Open Source Code ( ) Supported Parties ( )

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext e48f4977-afa8-4a2e-8e31-de5e571354bf

Builds on11

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines