DashboardNIST PQC R3FAEST
MPCitHRound 3 · 9 of 9sig ~5 KBmed sign

FAEST

AES one-wayness

FAEST is a digital signature scheme whose security reduces to the one-wayness of AES, built on the VOLE-in-the-Head paradigm. It has no novel hardness assumption beyond a standard symmetric primitive.

Key parameters

spec snapshot
Underlying primitive
AES-128 / 192 / 256 (OWF)
Framework
VOLE-in-the-Head (zk for AES circuit)
Public key size
~32 B
Signature size (L1)
≈ 5,006 B (FAEST-128s)
Sign / Verify cost
Tens of ms (AES-NI accelerated)
NIST security levels
I, III, V

NIST citations

3 sources

Round timeline

5 events · 2023 → 2027
  1. Round 1

    Submission accepted

    Included in the 40-candidate cohort for the additional-signatures on-ramp.

  2. Round 2

    Advanced to Round 2

    NIST selected 14 candidates for continued analysis (IR 8528).

  3. Round 3

    Advanced to Round 3

    Down-selected to 9 candidates for the final evaluation round.

  4. Round 2

    FAEST v2 spec released

    Reduced signature size by ~25% via tighter VOLE parameters.

  5. Round 3

    7th NIST PQC Standardization Conference

    Scheduled late spring / early summer 2027, Gaithersburg, MD.

Source: NIST CSRC · IR 8610 (Round 3 advancement, May 14, 2026) · IR 8528 (Round 2 advancement, Oct 24, 2024).