Here at wolfSSL we never leave an optimization on the table in any of our products. We are currently working on a new optimization known as External-Mu in the PKI community. In ML-DSA, you sign a message directly; no pre-hash which is similar to Ed25519 and Ed448 but different from ECDSA. But the very first step in the signing and verification step is calculating Mu:
Mu = SHAKE_256(tr || 0x00 || ctxLen || ctx || msg)
Where:
tr = SHAKE_256(publicKey)
ctx = context string passed in (must be shorter than 255 bytes)
ctxLen = context string length
msg = the message to be signed
So Mu is 64 bytes because that is the length of a SHAKE-256 hash. Since messages are unbounded there is a chance that you would need to sign a very large message. In the case of wolfHSM, this could be a big performance hit if you need to send it over a slow transport or if the HSM core has performance limitations.
Since the calculation of Mu only requires public data, it might be appropriate to calculate it on the wolfHSM client.
Note that wolfSSL also supports HashML-DSA but this is a different algorithm and has different algorithm identifiers so the need for interoperability might make this scheme unfeasible.
Do you want to use ML-DSA with wolfHSM? If so, let us know! We can raise the priority of this optimization.
If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.
Download wolfSSL Now

