ML-DSA-65 Implementation Evidence
RANNTA PQ Cloud uses the ML-DSA-65 algorithm specified by NIST FIPS 204 and publishes RANNTA-generated implementation, fail-closed and production end-to-end evidence for technical due diligence.
Validation and certification boundary
RANNTA does not currently claim NIST ACVP/CAVP algorithm validation, CMVP module validation, a NIST validation certificate, or third-party certification for PQ Cloud. References to FIPS 204 identify the public algorithm specification implemented by the service; they do not mean that RANNTA PQ Cloud is a FIPS-validated cryptographic module.
ML-DSA-65, as specified in NIST FIPS 204Published release snapshot
RANNTA-PQ-CLOUD-PHASE2-20260911-01Core tests11 passed, 0 failedProduction policy E2E
PASSRecorded benchmark
100 / 100 sequential valid requestsCustomer-side cross-check
@noble/post-quantum 0.7.1RANNTA-published implementation evidence
- Customer-side TypeScript SDK build: PASS.
- Local ML-DSA-65 positive verification: PASS.
- Local one-byte mutation rejection: PASS.
- Production public-key registration and service policy activation: PASS.
- Production valid signed request: PASS.
- Production replay rejection: PASS.
- Production one-byte mutation rejection: PASS.
- Production
classical_verified=falserejection: PASS. - 100 / 100 recorded sequential production
/v1/hybrid/verifyrequests succeeded.
Important trust boundary
PQ Cloud cryptographically verifies ML-DSA-65 evidence. The customer performs the classical authorization in its own system and submits classical_verified=true as a customer assertion. PQ Cloud enforces that this assertion is present and true under the configured policy, but it does not independently cryptographically verify the customer's classical signature or authorization event.
Implementation identity
- Recorded production E2E harness source commit:
0ddce50395b6b9ffd6e03d4aa882e1fe50d5d4b4. - Recorded core test runtime: Rust 1.98.1 with OpenSSL 3.5.7.
- ML-DSA-65 public key observed: 1952 bytes.
- ML-DSA-65 signature observed: 3309 bytes.
- Customer-side private key remained customer-side throughout the recorded production E2E run.
Evidence scope: this page is a RANNTA-published implementation record. It is not an independent audit, NIST validation, certification or assurance report.
Open the production E2E evidence record or view measured production verification latency.