
FAEST is a digital signature scheme whose security reduces to the one-wayness of AES, built on the VOLE-in-the-Head paradigm. It has no novel hardness assumption beyond a standard symmetric primitive.
Key parameters
spec snapshot- Underlying primitive
- AES-128 / 192 / 256 (OWF)
- Framework
- VOLE-in-the-Head (zk for AES circuit)
- Public key size
- ~32 B
- Signature size (L1)
- ≈ 5,006 B (FAEST-128s)
- Sign / Verify cost
- Tens of ms (AES-NI accelerated)
- NIST security levels
- I, III, V
NIST citations
3 sourcesRound timeline
5 events · 2023 → 2027- Round 1
Submission accepted
Included in the 40-candidate cohort for the additional-signatures on-ramp.
- Round 2
Advanced to Round 2
NIST selected 14 candidates for continued analysis (IR 8528).
- Round 3
Advanced to Round 3
Down-selected to 9 candidates for the final evaluation round.
- Round 2
FAEST v2 spec released
Reduced signature size by ~25% via tighter VOLE parameters.
- Round 3
7th NIST PQC Standardization Conference
Scheduled late spring / early summer 2027, Gaithersburg, MD.
Source: NIST CSRC · IR 8610 (Round 3 advancement, May 14, 2026) · IR 8528 (Round 2 advancement, Oct 24, 2024).