Hanzo AI 5e78a2581e feat: KAT generator + deterministic vectors (ref/go/cmd/genkat)
cmd/genkat: deterministic KAT (Known Answer Test) generator. Emits
five JSON vector files under vectors/:

- keygen.json: 9 vectors (3 seeds x 3 modes)
- sign.json: 9 vectors (3 seeds x 3 modes; deterministic
  SignDeterministic on random seed-derived keys)
- verify.json: 6 vectors (1 positive + 1 negative per mode x 3
  modes; negative case flips a byte mid-signature)
- threshold-sign.json: 3 vectors (n=3/t=2, n=5/t=3, n=7/t=4 over
  ModeM192s only — the recommended mode is the only one
  exercised in v0.1 threshold path)
- dkg.json: 3 vectors (same configurations as threshold-sign)

Determinism gate: re-running genkat on a clean checkout MUST
produce byte-identical output. Validated by diff -r against a
fresh second run; KAT replay tests in kat_test.go further check
that the package reproduces every entry verbatim.

Total vectors size: ~935 KB (sign.json dominates at ~494 KB
because SLH-DSA-SHAKE-192s signatures are 16224 bytes each).
2026-05-19 01:25:10 -07:00

Magnetar — Threshold SLH-DSA (FIPS 205)

Research-stage construction. Threshold hash-based PQ signature primitive over FIPS 205 SLH-DSA. Not production-ready. Not part of any current NIST submission. See DESIGN.md for the research direction and SUBMISSION-STATUS.md for the path to NIST MPTC v0.3.

Status

Field Value
Standard FIPS 205 SLH-DSA (single-party)
Threshold construction Open research — no fixed protocol
Implementation None
Submission package Roadmap: NIST MPTC v0.3 target
Cert-profile role Polaris profile in luxfi/quasar (cross-family PQ diversity)

Where this is used

The Magnetar leg of the Polaris cert profile in luxfi/quasar — the maximum-assurance cross-family profile that pairs lattice PQ (Pulsar M-LWE + Corona R-LWE) with hash-based PQ (Magnetar SLH-DSA). Polaris is the production migration target for when Magnetar matures.

Until Magnetar exists in production form, the Polaris profile is reserved but not deployable; production chains run the Pulsar or Aurora profile.

Why hash-based threshold matters

SLH-DSA's security rests on collision/preimage resistance of the underlying hash (SHA-2 or SHAKE), with no lattice assumption. A threshold profile of SLH-DSA gives cross-family defense in depth: even if a future cryptanalytic break hits the entire lattice family (both M-LWE and R-LWE), Magnetar's hash-based threshold leg keeps the cert sound.

Why it's hard

See DESIGN.md for the construction-level challenges. Summary: SLH-DSA does not decompose into a linear-aggregation identity the way ML-DSA does, so the FROST-style aggregation pattern that powers Pulsar/Corona doesn't transfer. Threshold SLH-DSA in the literature requires MPC over hash computations + per-signature MPC ceremony, which dominates deployment economics.

Cross-references

  • luxfi/quasar — umbrella spec; Magnetar is PRIMITIVES.md row
  • luxfi/pulsar — sibling threshold M-LWE primitive (production)
  • luxfi/corona — sibling threshold R-LWE primitive (production)

License

BSD-3-Clause. See LICENSE.

Maintainer

magnetar@lux.network — Lux Industries, Inc.

S
Description
Magnetar — Lux threshold SLH-DSA (FIPS 205) hash-based PQ signature primitive
Readme
3.6 MiB
Languages
Go 93.5%
Shell 3.9%
eC 2.1%
Lean 0.5%