Core · Cryptography
A deliberate CPU and Vulkan security boundary.
Secret-key and single-message operations stay on audited CPU implementations. Vulkan accelerates deferred batch work over public or non-secret data where parity can be verified precisely.
48 / 48 C++ tests5 / 5 Python testsGPU ML-DSA research is private
Security boundary
Typed secret operations
ML-DSA-65 key generation and signing use liboqs. Secret keys are move-only and zeroized on destruction.
Deferred batch hashing
SHAKE-128, SHAKE-256, Keccak-f[1600], and power-of-two Merkle roots have Vulkan batch routes with CPU parity tests.
Fail-closed parsing
Hashes, public keys, signatures, and Merkle proofs reject malformed lengths and encodings.
Claim discipline
Implementation tests are evidence; they are not a FIPS 140 validation or independent security certification.
Production surface
| Primitive | Backend | Status |
|---|---|---|
| Keccak-f[1600], SHAKE-128/256, KMAC-256 | CPU | Official known-answer vectors |
| OaHash and Merkle proofs | CPU | Strict parsing and malformed-proof tests |
| Batch SHAKE and Keccak-f[1600] | Vulkan | Deferred; CPU parity and direct KAT tests |
| Power-of-two Merkle root | Vulkan | Deferred; CPU parity tested |
| ML-DSA-65 keygen, sign, verify | CPU liboqs | Typed and negative-path tested |
ML-DSA-65 serialized sizes
| Type | Size | Contract |
|---|---|---|
OaHash | 32 bytes | SHAKE-256 output |
OaPublicKey | 1,952 bytes | Exact-length public serialization |
OaSecretKey | 4,032 bytes | Move-only; zeroized on destruction |
OaSignature | 3,309 bytes | Exact-length signature serialization |