Hanzo AI 61aa6adf24 sign-off: cryptographer review of Magnetar v0.3.0 — APPROVED WITH GATES
Internal cryptographer agent review of the Magnetar v0.3.0 threshold
SLH-DSA implementation. Conducted via direct reading of all 12
production Go source files (~2186 LOC) plus the test surface
(~1451 LOC across 11 test files); verified build + vet + tests +
coverage measurement (76.8%).

Verdict: APPROVED WITH GATES for the Tier A documentation shape +
production-library posture. Five open gates tracked on the
v0.4.0 / v0.5.0 / v0.6.0 roadmap:

  GATE-1: EC theory shells for the threshold overlay (v0.5.0)
  GATE-2: Lean ↔ EC bridge via cross-citation to Pulsar (v0.5.0)
  GATE-3: dudect 10⁹ samples on threshold layer (v0.6.0)
  GATE-4: external cryptographic audit (v0.6.0)
  GATE-5: v0.4 lifecycle additions (ML-KEM envelope wrap, reshare) (v0.4.0)

Findings: 3 Informational (v0.1 reveal-and-aggregate trust caveat,
plaintext envelopes, race-detector skip pattern), 5 Minor (no
threshold-layer dudect, no EC theory shells, no duplicate-Round2
sender rejection at DKG, no Round-1 cardinality enforcement at
ThresholdSigner.Round2, ErrNotInQuorum declaration location).
0 Major, 0 Critical.

Code review highlights — verified green by file:line citation:
  - combine.go:106 ctEqual32 commit-bind gate
  - combine.go:163-203 explicit zeroize on every return
  - dkg.go:309-316 ComplaintEquivocation emission
  - dkg.go:359-415 Round-3 zeroize discipline
  - keygen.go:114 PublicKey.Equal constant-time
  - verify.go:104 thin dispatch to circl FIPS 205
  - sign.go:82 thin dispatch to circl SignDeterministic
  - transcript.go:28-36 domain-separated MAGNETAR-* tags
  - shamir.go:127 Lagrange GF(257) reconstruction

Honest about what's NOT proved: §3 of PROOF-CLAIMS.md enumerates
7 explicit non-claims; this sign-off mirrors that discipline.

Mirrors Pulsar's CRYPTOGRAPHER-SIGN-OFF.md exact structure.
2026-05-19 08:01:12 -07:00
2026-05-19 01:25:31 -07:00

Magnetar — Threshold SLH-DSA (FIPS 205)

Tier B: production library + submission scaffold landed v0.2.0. Threshold hash-based PQ signature primitive over FIPS 205 SLH-DSA implementing the v0.1 reveal-and-aggregate construction. Mechanized refinement + independent audit on the roadmap to Tier A.

See SPEC.md for the construction specification, DEPLOYMENT-RUNBOOK.md for the v0.1 trust-model disclosure, BLOCKERS.md for the remaining Tier B → A path, and SUBMISSION-STATUS.md for the NIST MPTC roadmap.

Status

Field Value
Standard FIPS 205 SLH-DSA (single-party + reveal-and-aggregate threshold)
Construction v0.1 reveal-and-aggregate (Shamir VSS over the SLH-DSA scheme seed)
Reference implementation ref/go/pkg/magnetar/ — pure Go, depends on cloudflare/circl/sign/slhdsa
KAT vectors vectors/{keygen,sign,verify,threshold-sign,dkg}.json (deterministic regeneration)
Class-N1-analog claim threshold signature is byte-equal to single-party slhdsa.SignDeterministic on the same reconstructed seed
Submission package NIST MPTC roadmap — see SUBMISSION-STATUS.md for the v0.3 target window
Cert-profile role Polaris profile in luxfi/quasar (cross-family PQ diversity)
Proof artifacts None yet — see BLOCKERS.md BLK-7
Independent review None yet — see BLOCKERS.md BLK-9

What v0.2.0 ships

  • Reference implementation (ref/go/pkg/magnetar/): single-party + DKG + threshold-sign + Combine over the SLH-DSA scheme seed.
  • Parameter sets: SHAKE-192s (recommended), SHAKE-192f, SHAKE-256s.
  • KAT generator (ref/go/cmd/genkat): deterministic vectors at five profiles (keygen, sign, verify, threshold-sign, dkg). Re-running on a clean checkout produces byte-identical output.
  • Headline test (n1_byte_equality_test.go): threshold-produced signatures are byte-identical to single-party FIPS 205 SignDeterministic on the reconstructed master seed.
  • Honest trust-model disclosure: DEPLOYMENT-RUNBOOK.md documents the v0.1 reveal-and-aggregate aggregator-as-TCB caveat with the same rigor as Pulsar's.

What v0.2.0 does NOT yet ship

  • Formal proofs (EasyCrypt theories, Lean bridges, Jasmin sources) — see BLOCKERS.md BLK-7.
  • Constant-time analysis under dudect of the threshold layer — see BLOCKERS.md BLK-7.
  • ML-KEM-768 wrapping of DKG Round-1 envelopes (closes passive-network-observer channel) — planned for v0.3 / Pulsar parity.
  • Independent cryptographer sign-off — see BLOCKERS.md BLK-9.
  • Full 16-document submission package — see BLOCKERS.md BLK-8.

Where this is used

The Magnetar leg of the Polaris cert profile in luxfi/quasar — the maximum-assurance cross-family profile that pairs lattice PQ (Pulsar M-LWE + Corona R-LWE) with hash-based PQ (Magnetar SLH-DSA). Polaris is the production migration target for when Magnetar matures to Tier A.

At v0.2.0 Tier B, Magnetar is available as a library but not yet the production cert-profile target. Production chains run the Pulsar profile; Polaris remains reserved.

Why hash-based threshold matters

SLH-DSA's security rests on collision/preimage resistance of the underlying hash (SHA-2 or SHAKE), with no lattice assumption. A threshold profile of SLH-DSA gives cross-family defense in depth: even if a future cryptanalytic break hits the entire lattice family (both M-LWE and R-LWE), Magnetar's hash-based threshold leg keeps the cert sound.

The v0.1 trust caveat (READ THIS)

The v0.1 reveal-and-aggregate construction reconstructs the master SLH-DSA seed in aggregator-process memory during each Combine call. The aggregator process is in the trusted computing base for this brief window. This is the same trust model as Pulsar's v0.1 reveal-and-aggregate.

Mitigations (see DEPLOYMENT-RUNBOOK.md for the full matrix):

  • TEE (SGX / SEV-SNP / TDX) is the recommended deployment posture.
  • mlock, ptrace-off (kernel.yama.ptrace_scope=3), ulimit -c 0 are mandatory.
  • Aggregator role SHOULD rotate per signing request.

A v0.2 instantiation that gives true threshold secrecy (aggregator never sees the seed) is on the research path — full MPC over SLH-DSA's hash tree is the candidate construction; see BLOCKERS.md BLK-1 follow-on work.

Quick start

import (
    "github.com/luxfi/magnetar/ref/go/pkg/magnetar"
)

// Single-party usage (single-instance signer).
params := magnetar.MustParamsFor(magnetar.ModeM192s)
sk, _ := magnetar.GenerateKey(params, nil) // crypto/rand
sig, _ := magnetar.Sign(params, sk, msg, ctx, false /* deterministic */, nil)
err := magnetar.Verify(params, sk.Pub, msg, sig)

For DKG + threshold signing, see the n1_byte_equality_test.go end-to-end example.

Cross-references

  • luxfi/quasar — umbrella spec; Magnetar is PRIMITIVES.md row
  • luxfi/pulsar — sibling threshold M-LWE primitive (Tier A production)
  • luxfi/corona — sibling threshold R-LWE primitive (Tier A submission)

License

BSD-3-Clause. See LICENSE.

Maintainer

magnetar@lux.network — Lux Industries, Inc.

S
Description
Magnetar — Lux threshold SLH-DSA (FIPS 205) hash-based PQ signature primitive
Readme
3.6 MiB
Languages
Go 93.5%
Shell 3.9%
eC 2.1%
Lean 0.5%