Update Dilithium from crystals upstream #1894
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issues:
Resolves #CryptoAlg-2722
Description of changes:
This PR updates the implementation of Dilithium (v3.1) with subsequent changes made in the official upstream repository (https://github.com/pq-crystals/dilithium).
As there are significant algorithmic changes between pre-FIPS 204 Dilithium (v3.1) and FIPS 204 IPD/Final we note that the integration of this code will cause Dilithium v3.1 signatures to fail. Consumers of AWS-LC were made aware of the unstable nature of the Dilithium implementation and API during the integration into the library (see https://github.com/aws/aws-lc/blob/8a1ee93969d8df64c4c51b2d6ddffb26a54adea9/crypto/dilithium/README.md).
As part of our due diligence we have verified that there are no existing deployments contingent on the stability of Dilithium. As such, we will continue to support the most up to date version of the algorithm from the authors upstream.
Call-outs:
Among the changes are modifications made per the FIPS 204 ML-DSA standard:
Testing:
As the signature size and private key size of ML-DSA has changed since v3.1, so too must the tests
EVPExtraTest.d2i_PrivateKey
for testing the parsing of ML-DSA private keys, as well as the certificates used forX509Test.TestDilithium3
.I have updated the private key
kExampleDilithium3KeyDER
and test certificatekDilithium3Cert
to reflect changes to the signature/key lengths, but will need to manually reproduce test-case certificateskDilithium3CertNull
,kDilithium3CertParam
.By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license and the ISC license.