A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key Infrastructure
Kiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui, Attila A. Yavuz
Abstract
The U.S. Federal Public Key Infrastructures (FPKI) relies on digital certificates and a network of Certificate Authorities (CAs) to build trust between federal agencies and their commercial partners. However, the current certificate generation process of FPKI faces two critical issues: The emerging quantum threats that jeopardize the security of conventionalsecure digital signatures and the systemic vulnerabilities introduced by centralized signing operations. While threshold Post-Quantum (PQ) signatures offer a promising foundation for compromise-resilient trust, their adoption within the FPKI remains constrained by strict standard compliance requirements. ML-DSA is a prominent construction for thresholding within the NIST-PQ standards. However, existing threshold constructions of ML-DSA diverge from the NIST standard, limiting algorithmic compliance and hindering adoption in regulated settings such as FPKI, which require thorough cryptanalysis and revalidation. Hence, no fully standard-compliant threshold PQ solution currently meets FPKI's need for a distributed and quantum-resistant trust infrastructure.
We introduce SHIELD, an efficient threshold NIST-PQcompliant signature framework that replaces its classical centralized counterpart in certificate generation within the FPKI. SHIELD provides several key properties that overcome the limitations of prior approaches. First, it achieves algorithmic FIPS-204 compliance and seamless functional interchangeability with standard ML-DSA, without altering the signing algorithm. Second, it conforms to FPKI's structural and operational requirements, provides high security against adversarial environments, and prevents fraudulent certificates by mitigating single-key compromise risks. Finally, we provide the opensource implementation of SHIELD. We empirically evaluated the performance of SHIELD under diverse network latency conditions to validate its practical conformance with FPKI operational needs. https://github.com/open-threshold-pqc/SHIELD.git • Compromise Resilience Against Arbitrary Malicious Corruptions. SHIELD provides quantum-UC-secure [56]
TABLE 1: Comparison of prior threshold ML-DSA vs. SHIELD's threshold ML-DSA for adoption in FPKI Work Algorithmic FIPS-204 Compliance Free of Security Revalidation Federal Interoperability Base Work Threshold Tools Concealing Rejected Signature Open Source Code ( ) Supported Parties ( )
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e48f4977-afa8-4a2e-8e31-de5e571354bfBuilds on11
- Global-Scale Secure Multiparty ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 220 citations
- Threshold Raccoon: Practical Threshold Signatures from Standard Lattice AssumptionsRafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem et al.EUROCRYPT 2024 · 61 citations
- Adaptively Secure 5 Round Threshold Signatures from MLWE/MSIS and DL with RewindingShuichi Katsumata, Michael Reichle, Kaoru TakemureCRYPTO 2024 · 34 citations
- SPRINT: High-Throughput Robust Distributed Schnorr SignaturesFabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Yiping Ma et al.EUROCRYPT 2024 · 25 citations
- Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive SecurityRenas Bacho, Sourav Das, Julian Loss, Ling RenEUROCRYPT 2025 · 21 citations
Related papers
- Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPCAlexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou et al.USENIX Security 2026 · 1 citation
- Post-Quantum Authentication in TLS 1.3: A Performance StudyDimitrios Sikeridis, Panos Kampanakis, Michael DevetsikiotisNDSS 2020
- Efficient Threshold ML-DSASofía Celi, Rafael del Pino, Thomas Espitau, Guilhem Niot et al.USENIX Security 2026 · 1 citation
- Thresholdizing Standardized FALCON SignaturesRadhika Garg, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi et al.CCS 2026
- A Tale of Two Worlds, a Formal Story of WireGuard HybridizationPascal Lafourcade, Dhekra Mahmoud, Sylvain Ruhault, Abdul Rahman TalebUSENIX Security 2025
