Internet DRAFT - draft-ietf-cose-post-quantum-signatures

draft-ietf-cose-post-quantum-signatures







COSE                                                          M. Prorock
Internet-Draft                                                  mesur.io
Intended status: Standards Track                               O. Steele
Expires: 23 April 2023                                         Transmute
                                                             R. Misoczki
                                                                  Google
                                                              M. Osborne
                                                                     IBM
                                                         C. Cloostermans
                                                                     NXP
                                                         20 October 2022


           JOSE and COSE Encoding for Post-Quantum Signatures
               draft-ietf-cose-post-quantum-signatures-01

Abstract

   This document describes JSON and CBOR serializations for several
   Post-Quantum Cryptography (PQC) based suites including CRYSTALS
   Dilithium, Falcon, and SPHINCS+.

   This document does not define any new cryptography, only
   seralizations of existing cryptographic systems.

   This document registers key types for JOSE and COSE, specifically
   LWE, NTRU, and HASH.

   Key types in this document are specified by the cryptographic
   algorithm family in use by a particular algorithm as discussed in
   RFC7517.

   This document registers signature algorithms types for JOSE and COSE,
   specifically CRYDI3 and others as required for use of various post-
   quantum signature schemes.

Status of This Memo

   This Internet-Draft is submitted in full conformance with the
   provisions of BCP 78 and BCP 79.

   Internet-Drafts are working documents of the Internet Engineering
   Task Force (IETF).  Note that other groups may also distribute
   working documents as Internet-Drafts.  The list of current Internet-
   Drafts is at https://datatracker.ietf.org/drafts/current/.






Prorock, et al.           Expires 23 April 2023                 [Page 1]

Internet-Draft           post-quantum-signatures            October 2022


   Internet-Drafts are draft documents valid for a maximum of six months
   and may be updated, replaced, or obsoleted by other documents at any
   time.  It is inappropriate to use Internet-Drafts as reference
   material or to cite them other than as "work in progress."

   This Internet-Draft will expire on 23 April 2023.

Copyright Notice

   Copyright (c) 2022 IETF Trust and the persons identified as the
   document authors.  All rights reserved.

   This document is subject to BCP 78 and the IETF Trust's Legal
   Provisions Relating to IETF Documents (https://trustee.ietf.org/
   license-info) in effect on the date of publication of this document.
   Please review these documents carefully, as they describe your rights
   and restrictions with respect to this document.  Code Components
   extracted from this document must include Revised BSD License text as
   described in Section 4.e of the Trust Legal Provisions and are
   provided without warranty as described in the Revised BSD License.

Table of Contents

   1.  Notational Conventions  . . . . . . . . . . . . . . . . . . .   3
   2.  Terminology . . . . . . . . . . . . . . . . . . . . . . . . .   3
   3.  CRYSTALS-Dilithium  . . . . . . . . . . . . . . . . . . . . .   3
     3.1.  Overview  . . . . . . . . . . . . . . . . . . . . . . . .   3
     3.2.  Parameters  . . . . . . . . . . . . . . . . . . . . . . .   5
       3.2.1.  Parameter sets  . . . . . . . . . . . . . . . . . . .   5
     3.3.  Core Operations . . . . . . . . . . . . . . . . . . . . .   5
     3.4.  Using CRYDI with JOSE . . . . . . . . . . . . . . . . . .   5
       3.4.1.  CRYDI Key Representations . . . . . . . . . . . . . .   6
       3.4.2.  CRYDI Algorithms  . . . . . . . . . . . . . . . . . .   7
       3.4.3.  CRYDI Signature Representation  . . . . . . . . . . .  16
     3.5.  Using CRYDI with COSE . . . . . . . . . . . . . . . . . .  20
   4.  Falcon  . . . . . . . . . . . . . . . . . . . . . . . . . . .  20
     4.1.  Overview  . . . . . . . . . . . . . . . . . . . . . . . .  20
     4.2.  Core Operations . . . . . . . . . . . . . . . . . . . . .  21
     4.3.  Using FALCON with JOSE  . . . . . . . . . . . . . . . . .  21
       4.3.1.  FALCON Key Representations  . . . . . . . . . . . . .  22
       4.3.2.  FALCON Algorithms . . . . . . . . . . . . . . . . . .  23
     4.4.  Using FALCON with COSE  . . . . . . . . . . . . . . . . .  24
   5.  SPHINCS-PLUS  . . . . . . . . . . . . . . . . . . . . . . . .  24
     5.1.  Overview  . . . . . . . . . . . . . . . . . . . . . . . .  25
     5.2.  Core Operations . . . . . . . . . . . . . . . . . . . . .  26
     5.3.  Using SPHINCS-PLUS with JOSE  . . . . . . . . . . . . . .  26
       5.3.1.  SPHINCS-PLUS Key Representations  . . . . . . . . . .  26
       5.3.2.  SPHINCS-PLUS Algorithms . . . . . . . . . . . . . . .  28



Prorock, et al.           Expires 23 April 2023                 [Page 2]

Internet-Draft           post-quantum-signatures            October 2022


     5.4.  Using SPHINCS-PLUS with COSE  . . . . . . . . . . . . . .  28
   6.  Security Considerations . . . . . . . . . . . . . . . . . . .  29
     6.1.  Falcon specific Security Considerations . . . . . . . . .  30
     6.2.  Validating public keys  . . . . . . . . . . . . . . . . .  30
     6.3.  Side channel attacks  . . . . . . . . . . . . . . . . . .  30
     6.4.  Randomness considerations . . . . . . . . . . . . . . . .  30
   7.  IANA Considerations . . . . . . . . . . . . . . . . . . . . .  30
   8.  Appendix  . . . . . . . . . . . . . . . . . . . . . . . . . .  34
     8.1.  Test Vectors  . . . . . . . . . . . . . . . . . . . . . .  35
       8.1.1.  LWE CRYDI5  . . . . . . . . . . . . . . . . . . . . .  35
       8.1.2.  NTRU FALCON512  . . . . . . . . . . . . . . . . . . .  41
       8.1.3.  HASH SPHINCS+-SHAKE-256s-robust . . . . . . . . . . .  45
   9.  Normative References  . . . . . . . . . . . . . . . . . . . .  58
   10. Informative References  . . . . . . . . . . . . . . . . . . .  59
   Authors' Addresses  . . . . . . . . . . . . . . . . . . . . . . .  59

1.  Notational Conventions

   The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
   "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
   document are to be interpreted as described in [RFC2119].

2.  Terminology

   The following terminology is used throughout this document:

   PK : The public key for the signature scheme.

   SK : The secret key for the signature scheme.

   signature : The digital signature output.

   message : The input to be signed by the signature scheme.

   sha256 : The SHA-256 hash function defined in [RFC6234].

   shake256 : The SHAKE256 hash function defined in [RFC8702].

3.  CRYSTALS-Dilithium

3.1.  Overview

   This section of the document describes the lattice signature scheme
   CRYSTALS-Dilithium (CRYDI).  The scheme is based on "Fiat-Shamir with
   Aborts"[Lyu09, Lyu12] utlizing a matrix of polynomials for key
   material, and a vector of polynomials for signatures.  The parameter
   set is strategically chosen such that the signing algorithm is large
   enough to maintain zero-knowledge properties but small enough to



Prorock, et al.           Expires 23 April 2023                 [Page 3]

Internet-Draft           post-quantum-signatures            October 2022


   prevent forgery of signatures.  An example implementation and test
   vectors are provided.

   CRYSTALS-Dilithium is a post-quantum approach to digital signatures
   that is an algorithmic apprach that seeks to ensure key pair and
   signing properties that is a strong implementation meeting
   Existential Unforgeability under Chosen Message Attack (EUF-CMA)
   properties, while ensuring that the security levels reached meet
   security needs for resistance to both classical and quantum attacks.
   The algoritm itself is based on hard problems over module lattices,
   specifically Ring Learning with Errors (Ring-LWE).  For all security
   levels the only operations required are variants of Keccak and number
   theoretic transforms (NTT) for the ring Zq[X]/(X256+1).  This ensures
   that to increase or decrease the security level involves only the
   change of parameters rather than re-implementation of a related
   algorithm.

   While based on Ring-LWE, CRYSTALS-Dilithium has less algebraic
   structure than direct Ring-LWE implementations and more closely
   resembles the unstructured lattices used in Learning with Errors
   (LWE).  This brings a theorectical protection against future
   algebraic attacks on Ring-LWE that may be developed.

   CRYSTALS-Dilithium, brings several advantages over other approaches
   to signature suites:

   *  Post-quantum in nature - use of lattices and other approaches that
      should remain hard problems even when under attack utilizing
      quantum approaches
   *  Simple implementation while maintaining security - a danger in
      many possible approaches to cryptography is that it may be
      possible inadvertently introduce errors in code that lead to
      weakness or decreases in security level
   *  Signature and public key size - compared to other post-quantum
      approaches a reasonable key size has been achieved that also
      preserves desired security properties
   *  Conservative parameter space - parameterization is utilized for
      the purposes of defining the sizes of matrices in use, and thereby
      the number of polynomials described by the key material.
   *  Parameter set adjustment for greater security - increasing this
      matrix size increases the number of polynomials, and thereby the
      security level
   *  Performance and optimization - the approach makes use of well
      known transforms that can be highly optimized, especially with use
      of hardware optimizations without being so large that it cannot be
      deployed in embedded or IoT environments without some degree of
      optimization.




Prorock, et al.           Expires 23 April 2023                 [Page 4]

Internet-Draft           post-quantum-signatures            October 2022


   The primary known disadvantage to CRYSTALS-Dilithium is the size of
   keys and signatures, especially as compared to classical approaches
   for digital signing.

3.2.  Parameters

   Unlike certain other approaches such as Ed25519 that have a large set
   of parameters, CRYSTALS-Dilithium uses distinct numbers of paramters
   to increase or decrease the security level according to the required
   level for a particular scenario.  Under CRYSTALS-Dilithium, the key
   parameter specification determines the size of the matrix and thereby
   the number of polynomials that describe the lattice.  For use
   according to this specification we do not recommend a parameter set
   of less than 3, which should be sufficient to maintain 128 bits of
   security for all known classical and quantum attacks.  Under a
   parameter set at NIST level 3, a 6x5 matrix is utilized that thereby
   consists of 30 polynomials.

3.2.1.  Parameter sets

   Parameter sets are identified by the corresponding NIST level per the
   table below

   +============+=============+================+
   | NIST Level | Matrix Size | memory in bits |
   +============+=============+================+
   | 2          | 4x4         | 97.8           |
   +------------+-------------+----------------+
   | 3          | 6x5         | 138.7          |
   +------------+-------------+----------------+
   | 5          | 8x7         | 187.4          |
   +------------+-------------+----------------+

                      Table 1

3.3.  Core Operations

   Core operations used by the signature scheme should be implemented
   according to the details in [CRYSTALS-Dilithium].  Core operations
   include key generation, sign, and verify.

3.4.  Using CRYDI with JOSE

   This sections is based on CBOR Object Signing and Encryption (COSE)
   and JSON Object Signing and Encryption (JOSE)
   (https://datatracker.ietf.org/doc/html/rfc8812#section-3)





Prorock, et al.           Expires 23 April 2023                 [Page 5]

Internet-Draft           post-quantum-signatures            October 2022


3.4.1.  CRYDI Key Representations

   A new key type (kty) value "LWE" (for keys related to the family of
   algorithms that utilize Learning With Errors approaches to Post-
   quantum lattice based cryptography) is defined for public key
   algorithms that use base 64 encoded strings of the underlying binary
   material as private and public keys and that support cryptographic
   sponge functions.  It has the following parameters:

   *  The parameter "kty" MUST be "LWE".

   *  The parameter "alg" MUST be specified, and its value MUST be one
      of the values specified in the table below

              +========+===================================+
              | alg    | Description                       |
              +========+===================================+
              | CRYDI5 | CRYSTALS-Dilithium paramter set 5 |
              +--------+-----------------------------------+
              | CRYDI3 | CRYSTALS-Dilithium paramter set 3 |
              +--------+-----------------------------------+
              | CRYDI2 | CRYSTALS-Dilithium paramter set 2 |
              +--------+-----------------------------------+

                                 Table 2

   *  The parameter "pset" MAY be specfied to indicate the not only
      paramter set in use for the algorithm, but SHOULD also reflect the
      targeted NIST level for the algorithm in combination with the
      specified paramter set.  For "alg" "CRYDI" one of the described
      parameter sets "2", "3", or "5" MUST be specified.  Parameter set
      "3" or above SHOULD be used with "CRYDI" for any situation
      requiring at least 128bits of security against both quantum and
      classical attacks

   *  The parameter "x" MUST be present and contain the public key
      encoded using the base64url [RFC4648] encoding.

   *  The parameter "d" MUST be present for private keys and contain the
      private key encoded using the base64url encoding.  This parameter
      MUST NOT be present for public keys.

   Sizes of various key and signature material is as follows (for "pset"
   value "2")







Prorock, et al.           Expires 23 April 2023                 [Page 6]

Internet-Draft           post-quantum-signatures            October 2022


    +===========+===============+==============+======+==============+
    | Variable  | Paramter Name | Paramter Set | Size | base64url    |
    |           |               |              |      | encoded size |
    +===========+===============+==============+======+==============+
    | Signature | sig           | 2            | 3293 | 4393         |
    +-----------+---------------+--------------+------+--------------+
    | Public    | x             | 2            | 1952 | 2605         |
    | Key       |               |              |      |              |
    +-----------+---------------+--------------+------+--------------+
    | Private   | d             | 2            | 4000 | 5337         |
    | Key       |               |              |      |              |
    +-----------+---------------+--------------+------+--------------+

                                 Table 3

   When calculating JWK Thumbprints [RFC7638], the four public key
   fields are included in the hash input in lexicographic order: "kty",
   "alg", and "x".

3.4.2.  CRYDI Algorithms

   In order to reduce the complexity of the key representation and
   signature representations we register a unique algorithm name per
   pset.  This allows us to omit registering the pset term, and reduced
   the likelyhood that it will be misused.  These alg values are used in
   both key representations and signatures.

                      +=====+========+==============+
                      | kty | alg    | Paramter Set |
                      +=====+========+==============+
                      | LWE | CRYDI5 | 5            |
                      +-----+--------+--------------+
                      | LWE | CRYDI3 | 3            |
                      +-----+--------+--------------+
                      | LWE | CRYDI2 | 2            |
                      +-----+--------+--------------+

                                  Table 4

3.4.2.1.  Public Key

   Per section 5.1 of [CRYSTALS-Dilithium]:

   |  The public key, containing p and t1, is stored as the
   |  concatenation of the bit-packed representations of p and t1 in
   |  this order.  Therefore, it has a size of 32 + 288 kbytes.





Prorock, et al.           Expires 23 April 2023                 [Page 7]

Internet-Draft           post-quantum-signatures            October 2022


   The public key is represented as x and encoded using base64url
   encoding as described in [RFC7517].

   Example public key using only required fields:















































Prorock, et al.           Expires 23 April 2023                 [Page 8]

Internet-Draft           post-quantum-signatures            October 2022


   =============== NOTE: '\' line wrapping per RFC 8792 ================

   {
     "kty": "LWE",
     "alg": "CRYDI3",
     "x": "z7u7GwhsjjnfHH3Nkrs2xvvw020Rcw5ymdlTnhRenjDdrOO+nfXRVUZVy9q1\
   5zDn77zTgrIskM3WX8bqslc+B1fq12iA/wxD2jc1d6j+YjKCtkGH26OR7vc0YC2ZiMzW\
   zGl7yebt7JkmjRbN1N+u/2fAKFLuziMcLNP6WLoWbMqxoC2XOOVNAWX3QjXrCcGU23Nr\
   imtdmWz5NrP43E592Sctt5M+SVlfgQeYv8pHmtkQknE8/jr7TrgNpuiV7nXmhWHTMJ4I\
   zoGXgq43odFFthboEdKNT/enyu+VvUGoIJ6cN8C/1B6o1WlYHEaL0BEIFFbAiAhZ/vnf\
   cUYMaVPqsDJuETsjetcE32kGCD7Jkume2tO68DlIhB/2Z2JX8mkcbxFI6KrmXiRxXQj9\
   9LVn1fEzdf3Vfpcs/C3omsFGqmTpLDK+AvW/SWVkDi2NKq7hL/AyxlW2u2cqVErQZUTS\
   Z+ic6V8kZfxr3gRMnH0KuF5BtjleZ/yVvqqPjwPOZegCKEl2Gd8duhcUde7CR55pil1o\
   UXy5AwgCcZTdEcJn1OPObGoots9T19gw1x4vnZCQUKVDPZuZ1gIkGqDUYXS0lcNTjCMs\
   miFEmnOZvB88jxULpb1vl9HoQ3ocM2oZu4AZRt9G/L07Mwcui0uFCWtAIau+2gqNAn/Z\
   AS10l0j2N0LLtAaOxoF+Ctzscrt0ZMyGHmoQ9daHkpUvEq0cO8hDtLplnq3lQIIIfROQ\
   jcNs9vNKBu87COBjukZD+L8vV4zy8FNO59MCSb9UCLwz2xvfdI1js9/J7hTGaVec8VPx\
   md42yPFrGw5Na1oefm8vW49EDmevc8AjAtwDirRBDFv9pX3+5S+M6jhteSLYvpKJXQT1\
   zs1379KvIHwkn9VHpA+PiUUw9TgF6xF8xWEGSNlOo1Vn1xtM3givehjYxJ5p5/kBEFZI\
   DCyFzstAirJ2GadNhae+P1JFZzJWnX5jaLwzldquZwF3yTzNho4sgBA+fKqiXcgn2nw1\
   vz0Dkbxr6cMaUool0eFScU1nAz1Z39W64LtT2nEuYsORx/ht2RzJxxFc21X3nLeEDFCe\
   NkNDxQFBSfpZjKKgJtXEx23mp+CbBVMrbagsLnzsAGLYbnroVmATU5Iqr6LgYBpuFs+N\
   Rkq7ZXh6CZPukMGQbcOGuNwO6NBuuMNhir5ayGk1ZBiW82C7Nu0hs2pLcgNqWMtt1+LW\
   8R96KyoSc784ZYAZ40QqvoySwmxQPBRTRJ+wB0sVpGBLTxdY9Gw3pXeXN5nao340d2ZA\
   7YEMlqcTHCAv3F8B9ewl7OfQlmg6bvdMuoVdVE+p0er7IAmWMRgviIzYv9sKEEQrCmua\
   2qL5xPSbD05KRf8ZAZ2B8lSCDR1nzXrQXZbXBKJivsCVQDuzxrwGE0gqRMpbk4f5GYCG\
   4i/O8Knoru+jjf6wVQDYKfyz1QUGRlXHkGUGlXfv03r7UbJugycjVO5kbGxhoZkqOq8z\
   ZEpkefvrrNoxeotw/z4QpjI8JlY97GDb0mGVHbmdHugjMtVTGhVJFBbPIinmR+emt7O+\
   4qOr7ywRxCvt2lziWtpPBwaf/1XDnN5Gesex1gR1YrcTRNmB808b01sxLQmxcTt4eQ0/\
   LUkas7qTJ3AQThOfDdtIpkqsthsBFy+WjSQuoXCYMRcPi6MlpxJndDF32lCnL1ranV6e\
   F2ST0SYT+NwNDesMzTRmNbHUW5KAhu0k9WABTvcM5ba0Uq6iOa1NsFrcLag+KhxN6HPn\
   oobwJ/EsDi5S7TAl8WrjqIhZ8x6h9eRRXerpaOw/FYk+2MpWByp/98VE12/EwOqAIiPp\
   elAvUeMOlRkpG64bJsmyYtHuNWgcv5Qiy7/eGw9ZpvB3J3G3jxvbynExqdFyDc067EKi\
   5WxDFPuZUjkfKpekNvzQuIrqs49BzcRyMt5ndEVE21TPPfZ/R8B7Rxnb2LiK+hQc+cc9\
   pEEaWgwAOiMILcp/1CyY6ImdO6RHsxwflMH7gej+hN41kaoEghIOl9kMGTLZbq5Pc8Pz\
   6F2LKTBMJWg9o/0blvilMH9EPblcLeF/bR1AZTUD6ZFdi2TxN6Epn3QVqeG/qPm1EBTF\
   Gw1V92m6/08Dd6zI1HPqwKbkHx4F567owofKHaM2imin0yVUpwxoRJrulRHMCB3tn8C4\
   ZpFl+sGV3Gip3tKlS7PKQkTqI6DMwxEbdrvtdY1sHZagpclLDisA/yFT4RR2m3VNJR9P\
   6Nx3teqN1eg6RXmD/MlKCdWrlcjZ/6yeIQYwbr9CjItY/tLQX2gtAR1SXOh99UUBVv+Z\
   E03VOZ+Ecsc78lSB9G/6n6CFzlbk/HgAF+cu0yMbGnEM8W3mTUspS4JBACwk5w0XWNNQ\
   DWVEdgzuLGhPq+hYExDjVZrLELhkH8YgZA+7RXXUZHM/joNOGHUhpUG/bFo3ktnaILCu\
   xsOXMUbDC3VcitFFHsGK1svtcERDFxk1HA8pGa59jT0do6n3wEbnBDU1soKNFtpmcVkE\
   Ul3XpvuoW3BgCwJzBUCWvPs47DJRgGxO11bSaEYYlhTVaaShcvzgz46AkqO+Q7TjckDP\
   /8uzsSQk0AbuhxWFQpSiBP8OZ/U="
   }

   Example public key including optional fields:




Prorock, et al.           Expires 23 April 2023                 [Page 9]

Internet-Draft           post-quantum-signatures            October 2022


   =============== NOTE: '\' line wrapping per RFC 8792 ================

   {
     "kid": "key-0",
     "kty": "LWE",
     "alg": "CRYDI3",
     "key_ops": ["verify"],
     "x": "z7u7GwhsjjnfHH3Nkrs2xvvw020Rcw5ymdlTnhRenjDdrOO+nfXRVUZVy9q1\
   5zDn77zTgrIskM3WX8bqslc+B1fq12iA/wxD2jc1d6j+YjKCtkGH26OR7vc0YC2ZiMzW\
   zGl7yebt7JkmjRbN1N+u/2fAKFLuziMcLNP6WLoWbMqxoC2XOOVNAWX3QjXrCcGU23Nr\
   imtdmWz5NrP43E592Sctt5M+SVlfgQeYv8pHmtkQknE8/jr7TrgNpuiV7nXmhWHTMJ4I\
   zoGXgq43odFFthboEdKNT/enyu+VvUGoIJ6cN8C/1B6o1WlYHEaL0BEIFFbAiAhZ/vnf\
   cUYMaVPqsDJuETsjetcE32kGCD7Jkume2tO68DlIhB/2Z2JX8mkcbxFI6KrmXiRxXQj9\
   9LVn1fEzdf3Vfpcs/C3omsFGqmTpLDK+AvW/SWVkDi2NKq7hL/AyxlW2u2cqVErQZUTS\
   Z+ic6V8kZfxr3gRMnH0KuF5BtjleZ/yVvqqPjwPOZegCKEl2Gd8duhcUde7CR55pil1o\
   UXy5AwgCcZTdEcJn1OPObGoots9T19gw1x4vnZCQUKVDPZuZ1gIkGqDUYXS0lcNTjCMs\
   miFEmnOZvB88jxULpb1vl9HoQ3ocM2oZu4AZRt9G/L07Mwcui0uFCWtAIau+2gqNAn/Z\
   AS10l0j2N0LLtAaOxoF+Ctzscrt0ZMyGHmoQ9daHkpUvEq0cO8hDtLplnq3lQIIIfROQ\
   jcNs9vNKBu87COBjukZD+L8vV4zy8FNO59MCSb9UCLwz2xvfdI1js9/J7hTGaVec8VPx\
   md42yPFrGw5Na1oefm8vW49EDmevc8AjAtwDirRBDFv9pX3+5S+M6jhteSLYvpKJXQT1\
   zs1379KvIHwkn9VHpA+PiUUw9TgF6xF8xWEGSNlOo1Vn1xtM3givehjYxJ5p5/kBEFZI\
   DCyFzstAirJ2GadNhae+P1JFZzJWnX5jaLwzldquZwF3yTzNho4sgBA+fKqiXcgn2nw1\
   vz0Dkbxr6cMaUool0eFScU1nAz1Z39W64LtT2nEuYsORx/ht2RzJxxFc21X3nLeEDFCe\
   NkNDxQFBSfpZjKKgJtXEx23mp+CbBVMrbagsLnzsAGLYbnroVmATU5Iqr6LgYBpuFs+N\
   Rkq7ZXh6CZPukMGQbcOGuNwO6NBuuMNhir5ayGk1ZBiW82C7Nu0hs2pLcgNqWMtt1+LW\
   8R96KyoSc784ZYAZ40QqvoySwmxQPBRTRJ+wB0sVpGBLTxdY9Gw3pXeXN5nao340d2ZA\
   7YEMlqcTHCAv3F8B9ewl7OfQlmg6bvdMuoVdVE+p0er7IAmWMRgviIzYv9sKEEQrCmua\
   2qL5xPSbD05KRf8ZAZ2B8lSCDR1nzXrQXZbXBKJivsCVQDuzxrwGE0gqRMpbk4f5GYCG\
   4i/O8Knoru+jjf6wVQDYKfyz1QUGRlXHkGUGlXfv03r7UbJugycjVO5kbGxhoZkqOq8z\
   ZEpkefvrrNoxeotw/z4QpjI8JlY97GDb0mGVHbmdHugjMtVTGhVJFBbPIinmR+emt7O+\
   4qOr7ywRxCvt2lziWtpPBwaf/1XDnN5Gesex1gR1YrcTRNmB808b01sxLQmxcTt4eQ0/\
   LUkas7qTJ3AQThOfDdtIpkqsthsBFy+WjSQuoXCYMRcPi6MlpxJndDF32lCnL1ranV6e\
   F2ST0SYT+NwNDesMzTRmNbHUW5KAhu0k9WABTvcM5ba0Uq6iOa1NsFrcLag+KhxN6HPn\
   oobwJ/EsDi5S7TAl8WrjqIhZ8x6h9eRRXerpaOw/FYk+2MpWByp/98VE12/EwOqAIiPp\
   elAvUeMOlRkpG64bJsmyYtHuNWgcv5Qiy7/eGw9ZpvB3J3G3jxvbynExqdFyDc067EKi\
   5WxDFPuZUjkfKpekNvzQuIrqs49BzcRyMt5ndEVE21TPPfZ/R8B7Rxnb2LiK+hQc+cc9\
   pEEaWgwAOiMILcp/1CyY6ImdO6RHsxwflMH7gej+hN41kaoEghIOl9kMGTLZbq5Pc8Pz\
   6F2LKTBMJWg9o/0blvilMH9EPblcLeF/bR1AZTUD6ZFdi2TxN6Epn3QVqeG/qPm1EBTF\
   Gw1V92m6/08Dd6zI1HPqwKbkHx4F567owofKHaM2imin0yVUpwxoRJrulRHMCB3tn8C4\
   ZpFl+sGV3Gip3tKlS7PKQkTqI6DMwxEbdrvtdY1sHZagpclLDisA/yFT4RR2m3VNJR9P\
   6Nx3teqN1eg6RXmD/MlKCdWrlcjZ/6yeIQYwbr9CjItY/tLQX2gtAR1SXOh99UUBVv+Z\
   E03VOZ+Ecsc78lSB9G/6n6CFzlbk/HgAF+cu0yMbGnEM8W3mTUspS4JBACwk5w0XWNNQ\
   DWVEdgzuLGhPq+hYExDjVZrLELhkH8YgZA+7RXXUZHM/joNOGHUhpUG/bFo3ktnaILCu\
   xsOXMUbDC3VcitFFHsGK1svtcERDFxk1HA8pGa59jT0do6n3wEbnBDU1soKNFtpmcVkE\
   Ul3XpvuoW3BgCwJzBUCWvPs47DJRgGxO11bSaEYYlhTVaaShcvzgz46AkqO+Q7TjckDP\
   /8uzsSQk0AbuhxWFQpSiBP8OZ/U="
   }




Prorock, et al.           Expires 23 April 2023                [Page 10]

Internet-Draft           post-quantum-signatures            October 2022


3.4.2.2.  Private Key

   Per section 5.1 of [CRYSTALS-Dilithium]:

   |  The secret key contains p,K,tr,s1,s2 and t0 and is also stored as
   |  a bit-packed representation of these quantities in the given
   |  order.  Consequently, a secret key requires 64 + 48 + 32((k+l) *
   |  dlog (2n+ 1)e + 14k) bytes.  For the weak, medium and high
   |  security level this is equal to 112 + 576k+ 128l bytes.  With the
   |  very high security parameters one needs 112 + 544k + 96l = 3856
   |  bytes.

   The private key is represented as d and encoded using base64url
   encoding as described in [RFC7517].

   Example private key using only required fields:

   =============== NOTE: '\' line wrapping per RFC 8792 ================

   {
     "kty": "LWE",
     "alg": "CRYDI3",
     "x": "z7u7GwhsjjnfHH3Nkrs2xvvw020Rcw5ymdlTnhRenjDdrOO+nfXRVUZVy9q1\
   5zDn77zTgrIskM3WX8bqslc+B1fq12iA/wxD2jc1d6j+YjKCtkGH26OR7vc0YC2ZiMzW\
   zGl7yebt7JkmjRbN1N+u/2fAKFLuziMcLNP6WLoWbMqxoC2XOOVNAWX3QjXrCcGU23Nr\
   imtdmWz5NrP43E592Sctt5M+SVlfgQeYv8pHmtkQknE8/jr7TrgNpuiV7nXmhWHTMJ4I\
   zoGXgq43odFFthboEdKNT/enyu+VvUGoIJ6cN8C/1B6o1WlYHEaL0BEIFFbAiAhZ/vnf\
   cUYMaVPqsDJuETsjetcE32kGCD7Jkume2tO68DlIhB/2Z2JX8mkcbxFI6KrmXiRxXQj9\
   9LVn1fEzdf3Vfpcs/C3omsFGqmTpLDK+AvW/SWVkDi2NKq7hL/AyxlW2u2cqVErQZUTS\
   Z+ic6V8kZfxr3gRMnH0KuF5BtjleZ/yVvqqPjwPOZegCKEl2Gd8duhcUde7CR55pil1o\
   UXy5AwgCcZTdEcJn1OPObGoots9T19gw1x4vnZCQUKVDPZuZ1gIkGqDUYXS0lcNTjCMs\
   miFEmnOZvB88jxULpb1vl9HoQ3ocM2oZu4AZRt9G/L07Mwcui0uFCWtAIau+2gqNAn/Z\
   AS10l0j2N0LLtAaOxoF+Ctzscrt0ZMyGHmoQ9daHkpUvEq0cO8hDtLplnq3lQIIIfROQ\
   jcNs9vNKBu87COBjukZD+L8vV4zy8FNO59MCSb9UCLwz2xvfdI1js9/J7hTGaVec8VPx\
   md42yPFrGw5Na1oefm8vW49EDmevc8AjAtwDirRBDFv9pX3+5S+M6jhteSLYvpKJXQT1\
   zs1379KvIHwkn9VHpA+PiUUw9TgF6xF8xWEGSNlOo1Vn1xtM3givehjYxJ5p5/kBEFZI\
   DCyFzstAirJ2GadNhae+P1JFZzJWnX5jaLwzldquZwF3yTzNho4sgBA+fKqiXcgn2nw1\
   vz0Dkbxr6cMaUool0eFScU1nAz1Z39W64LtT2nEuYsORx/ht2RzJxxFc21X3nLeEDFCe\
   NkNDxQFBSfpZjKKgJtXEx23mp+CbBVMrbagsLnzsAGLYbnroVmATU5Iqr6LgYBpuFs+N\
   Rkq7ZXh6CZPukMGQbcOGuNwO6NBuuMNhir5ayGk1ZBiW82C7Nu0hs2pLcgNqWMtt1+LW\
   8R96KyoSc784ZYAZ40QqvoySwmxQPBRTRJ+wB0sVpGBLTxdY9Gw3pXeXN5nao340d2ZA\
   7YEMlqcTHCAv3F8B9ewl7OfQlmg6bvdMuoVdVE+p0er7IAmWMRgviIzYv9sKEEQrCmua\
   2qL5xPSbD05KRf8ZAZ2B8lSCDR1nzXrQXZbXBKJivsCVQDuzxrwGE0gqRMpbk4f5GYCG\
   4i/O8Knoru+jjf6wVQDYKfyz1QUGRlXHkGUGlXfv03r7UbJugycjVO5kbGxhoZkqOq8z\
   ZEpkefvrrNoxeotw/z4QpjI8JlY97GDb0mGVHbmdHugjMtVTGhVJFBbPIinmR+emt7O+\
   4qOr7ywRxCvt2lziWtpPBwaf/1XDnN5Gesex1gR1YrcTRNmB808b01sxLQmxcTt4eQ0/\
   LUkas7qTJ3AQThOfDdtIpkqsthsBFy+WjSQuoXCYMRcPi6MlpxJndDF32lCnL1ranV6e\
   F2ST0SYT+NwNDesMzTRmNbHUW5KAhu0k9WABTvcM5ba0Uq6iOa1NsFrcLag+KhxN6HPn\



Prorock, et al.           Expires 23 April 2023                [Page 11]

Internet-Draft           post-quantum-signatures            October 2022


   oobwJ/EsDi5S7TAl8WrjqIhZ8x6h9eRRXerpaOw/FYk+2MpWByp/98VE12/EwOqAIiPp\
   elAvUeMOlRkpG64bJsmyYtHuNWgcv5Qiy7/eGw9ZpvB3J3G3jxvbynExqdFyDc067EKi\
   5WxDFPuZUjkfKpekNvzQuIrqs49BzcRyMt5ndEVE21TPPfZ/R8B7Rxnb2LiK+hQc+cc9\
   pEEaWgwAOiMILcp/1CyY6ImdO6RHsxwflMH7gej+hN41kaoEghIOl9kMGTLZbq5Pc8Pz\
   6F2LKTBMJWg9o/0blvilMH9EPblcLeF/bR1AZTUD6ZFdi2TxN6Epn3QVqeG/qPm1EBTF\
   Gw1V92m6/08Dd6zI1HPqwKbkHx4F567owofKHaM2imin0yVUpwxoRJrulRHMCB3tn8C4\
   ZpFl+sGV3Gip3tKlS7PKQkTqI6DMwxEbdrvtdY1sHZagpclLDisA/yFT4RR2m3VNJR9P\
   6Nx3teqN1eg6RXmD/MlKCdWrlcjZ/6yeIQYwbr9CjItY/tLQX2gtAR1SXOh99UUBVv+Z\
   E03VOZ+Ecsc78lSB9G/6n6CFzlbk/HgAF+cu0yMbGnEM8W3mTUspS4JBACwk5w0XWNNQ\
   DWVEdgzuLGhPq+hYExDjVZrLELhkH8YgZA+7RXXUZHM/joNOGHUhpUG/bFo3ktnaILCu\
   xsOXMUbDC3VcitFFHsGK1svtcERDFxk1HA8pGa59jT0do6n3wEbnBDU1soKNFtpmcVkE\
   Ul3XpvuoW3BgCwJzBUCWvPs47DJRgGxO11bSaEYYlhTVaaShcvzgz46AkqO+Q7TjckDP\
   /8uzsSQk0AbuhxWFQpSiBP8OZ/U=",
     "d": "z7u7GwhsjjnfHH3Nkrs2xvvw020Rcw5ymdlTnhRenjDUBgL6FklHURz5btM5\
   yrI5FQdWk+U2srVuSmfDV7EYG897mUFY35Z0WQ0mZ9XvIOKCh+GFFOk56b5FOFq6xnV8\
   UDQnFyY2JREUOHdiUjcUNxA1YxR3QiQ0BkE1AUBmFEOAUHZGBzQAU2dxVIgTQRV3U3g4\
   GGiISEYQhHRSWDIBQ2Z3UIIWdSV1EWhwBTYiWGI3VmJVI1UIU2REdUhHBoJ2gRhFUThy\
   BSQnhBIGI1AoMVB2MCNhUXQiNUGCKHgzUmQxU3dEgBhmQyIQgmFjdxY1dCJgGBSEB4Ij\
   CEJ0MBGIQWRRN3QjRmRSQWQIJgNjcjdnMlJhJIU1MlJRd1NmF4dwhHIIdEYYcAhEclBQ\
   JjESAiBwBQYzYlAIIocBcoZFcGVkA2SDMCVTBjgzCAAzNnQGYHI1VwJzYxQRckBIZBV4\
   VxZmZiVlYXgHFRNjdEFIYVOFIVdhcnIINEhhIURjg0cxJ0SCIWYUUVcHJzdDUTASciAW\
   UiJAglIoQkIwNjMlcwACZxcHZVJAh4EnNnWAZVVoBjNnNEcicTdyEEUHBVFjETETNjd0\
   YUFmFDVXNUcHFVJoE2AlVwFhMzc0dQckMYJUaBJ0JkUBdyd1AnZiJ3hYYkWAgyR1VziD\
   BERVh1NQAFIGWIhUZXCEQxIThyR1FIGGNTKAcwdRNBGDYEd2RVEwUDMzWAAhNQEEMYAS\
   hUSCgTJ3VIdXUlFBFxFkhVCCZEABJjQCAxFGNkhHQzM1YSSHNlEBEmJkgWZCVwZHRSVD\
   GDZzRCQiNhE3IghDhSFoBYCHNFVHMxZAZTSGAVMUQkhBKIFRQEVBB0cHNGEiJVVScQQh\
   hzQiBzKBYRY4Q0R2MVUldwVCIkQYEEgFYEREY2NERyFVdHJzdAZHBmhmdSCFIgh1IwGB\
   AxNzFjEoUWFCF4AhZRJSEROEEThxAGYBJTgUcUdFJBOFRmcVYnZUUFCAY1AnZEZBVThS\
   ECBQYBNGeAdzQ3KGhIE3ZiFxQoVCgQBjEFdFcIV0IAaFcgI0iAgAUVQAhEInQWECY1I4\
   E2U0MkAXQSZkdSRRc2I4BjEiSGd4hgQEEDcTRmhFd3MBMmY2gERxNwiISAVkFVETGCcI\
   gYhzRXByGBgzKGVXJUhoGEY1hgFmZWgmEWYWVoISd4Vlhid4VUMHgSZXhXUSaCgmJ3Eg\
   MQIzIDIThwRSARQhBFB2QQBjEgIoEHN1BhMCiIIBUlZWCHdBMyZFQoQ2UUJXJCFnZyFD\
   RTFUUTQoQmUjB0aHJXJHeDZlJGBCExATEUEDg3BTAChWImN0AWcFB3IUgBEARxVUREdX\
   QzhVBEBBF4UgcRhCg4gUcoRkdYCAIUQBRUJUYjFjEBYUhSBjIyV2cXBYckEiMic1N4ED\
   gDUGVSCHhCYURXcQB1ODg4hDJFJ3Jld2gyYnQYclRjE3VWcQNXJBYnOGhYFoU2dHATAw\
   OEeBUGQjJHcDgUJTRXBXJ3IAEjEXhXeEEmghIAAGdjUVBndnI2FCAVcyV4cxIyZ2dYE1\
   ZEiHcYJYaCcXQXJCaER1coIDRWJkcSNhEVF3JGOCQkYWYkcndRA1QTh0MFgzIyVocYJY\
   cwIAFRNiE1VAUECBI3MzQiZkUhR1cid1NSAXFXN0gUNnRCV0ISNmYnB3NIZyMIQWEVVz\
   ElEohnQyKBNoY1cCdmdjVYiGhVUlA0CHMTZIURBgR4aIJwJQJlIDMYhwNGNwiGcIBUdA\
   NXMBETUgICJyMkMIN1BAIAB4gEMDUwhndFJkQDEgRRMld4EzhRM0ZhGAYHMgZ4NhEEhn\
   U2I2VicBBXZUFUNoczcmBzBnUEBxUWcDg4RHUXZSOEZogABHRAISVEAzdoQhRmBgEWYE\
   Z4U1dgQ2gjgQUjMScgIIFQR3YFczhTYoB1IiVCYGBAVmVAFIdhRmZ1InhwdTRjJjNhVx\
   IzcWgjFlFCaChlIWUySIaDFwAWV3RAIxg2QWYgAYMUjP7wmwOwPp7Ukl3L1KalY/6dN4\
   dBr1AYS8JnkVq6pPeBfO7ccX95SrVfAO7EX7RVEYyhVR9QOQyEpLBUMcfcfnHCZWKM0o\
   OBF7BXiWMR9BQo4ybtpJGKQ+IZyCKUJVRhZ+uae182qYcBKFMdOOzXiO8kAa98eUy6SR\
   pPfKPD6D+xXgtJ0FWtYnp1Jy2aIG3HqMiTHoSdVIvccGkf94gpVWTMeJQsQpgq7dAJiJ\
   5JOMQjk7JIHcIzxb4T8sQHzA55MFfvM7Hus/8FUX7NfIN1JRmc2zHL/7kdfCFSwG67iW\
   U4ob2kTwdKzPvOL+d3e+AOE0PihJ4vVJAOjhWmO2fIFNvFhNqPh0MSiSkatPGbSVdqQ1\



Prorock, et al.           Expires 23 April 2023                [Page 12]

Internet-Draft           post-quantum-signatures            October 2022


   PsG6C+1YqMrTM7KFr4hTQM8a3+tAOsImMjXSSPDkVeuJFq1rw642SJJx8yZTXVe8g75D\
   ZTYghbeX5LLzaVkt9mZS7cW16Zy+C3MwnWDrGQ6hUDxYaYJp7SOGJHepcmVV214oD6nw\
   5QprgpGIxVcdXQUO0fhKwerYDkoOIj+uqk7NYDvOt8zANphYcE3v+6yVFyYh3eg7DYRJ\
   rIzIcbaG91ySv2iRRC+cWaymH6xuqaHRwZu/p962/u8/c3rITJzCoVc+ObnZ5oItZFBe\
   AYFhLBx7PvPdBULXyCqmtkOtnT/jnaCUVxtGeaIeQmmeM4yPq3d5uWBfOvIyuPmfBSKd\
   Y0NETGlsaoQuqFpOkCmQdMVZKh3UZ8AOjw22LlqaZlrUf0akb0fs7le2HT47KV9yOJHC\
   tec9tjHUeBVmma5O4AofGcVXLbkqKv+Soax9GooHVOv+uxa8iwjAdTZKtqwKnKDx4jaR\
   +zotCsYi4BuB2JbkjnHG6NL7ubN+aNKnwnzZnMKQZIh2Q7vSRYKTM8j9OGLq7IP8q2NS\
   oc7iT//eAvb4oF6LaY7qebxQ6ROXCSRrrXgpo+pw3ltfuUCuGzAxD4+wMZU3dlXsivhJ\
   PnTEjI/V6GmkRlfZ9XnYfj8SILETWk03dMFJh3LmUwkbRV+C3mL2GzjgQVTkvP82KDBL\
   DAR9iKyPkJnMnK9Ix/StVyJbGAtGp4jHnp+PSjz9ja4qI9jVRjGgIUQhw0DnI0fnplUn\
   Qhz3F9MQXMPLSPvFw8M0xkUKsAcxQvxZGb5LkYByZ0ZrO/ipphwnE6zQuOva+8uTyBX/\
   B9VR24tUItvlhy7SS6JrULrvTA+D/ZCiqKRx61iF6pU3BoC8fgA9D/AifiQnPz0SI5kx\
   FJfDTz1LWMjUlQKBHFvRFLE9eFD0rnwAGx7Pgpyc/KrLqVmcmj/96TYtoedp/iW4asfY\
   C2vs+GVyxVoumIdFPHJpencWbE/niZnVDaJCih1iqgXzDsI8bENh2B9cutDWX+bsHZSC\
   jSQb9YkGN+MoNiJlXmQHSJDyfPhzWPibdS/lpS90ppPWIY+PpLOfzDSGFFWswQ4q5Phc\
   pLWHx5lw9KSye+T86p6kadnBBTLTyfn0dG7NpO9QKQObMN60MnybkVGx5nH9yLJlFlmV\
   0H+K0VZIKm4UzYV+RYfqqXYtMqTQxeQ1U7L7o0H+6viErxuKj5rS3i+r1rdfECAGgCoq\
   0mixATHISAHi2eSV5fk3r5xMkKSwwPIRuMt50+kklRPUoLohTj7G1CnL6O2xwBdQMTUx\
   4Jq5JBWnfB+U4D9n0si1DwikIhpaUyOoBeaWo4iFQiWVLwjeeQvY6zj66l7OXsPHjZXg\
   uCitsWfp5MYV3cLTkb80uCM/xhp4Y0Edobt6x3k1FD8vbh8g3YAG0Xe/U+Iz3klnpCt2\
   ROQ2lGQa0JMl4nbQr3tqTLoXv4szaErfP/Xw05Cnt9DsBzN5DNrmfF6EDcfVf/hn8v9a\
   wrg6Rfv8Jpys1YFpwLanhb3Wz+x1yaDsa54IdlFOFnyBxv8GppbFrMpVFx/nLAXGIocc\
   WjcRKs0tBJUW/IoXeKOMPUd1wHR4dqUCEXsoexHJiNe5sH+akr6UIDObF70hhupBoiY9\
   AzVXi5zXf2VdafyQrkGfKz4BEUkiqcaajHr1CF9ZJ+Mjdmfr3z0xyCmCAWir5ZLOBXDj\
   T7sYCV3QjCz4a2mGvee9IxC9kSLapCq90UMAxnTLjJGQM/dlpgjDsjsCZX5wKdsnMs79\
   60Z75BGDOC1dDINj4f5kHZmwwcmw/04mi/1RPBUABXse3Up3eJQOX2haZPqmY0+2PZTF\
   exku9pETHtKcfSdRe1oJLmlB34JSogRmNp1eBxakcIL09huiFVtGVZng/pC/ryoJ/T9q\
   9w4aV5H+4u2dHc29Vb77SasxCdRH0sDaLaPpesRXsrdJwjbizOgzRlIx+83oO7NuhE+C\
   kKfO7cZMrFm8r8g1MlzDiFrTf3RTusMtiW6CVlVuTROPZFngqaR5yeYPprpSELtQHSwz\
   U5AaY5Qd8tbky5ec+2/QkXO+cdyWhQUuBRpibwpRpD3x1yTgT4E91cwTFpvSLk54ZHf+\
   D3EsZf0PYMN6d4jVdh9iv+0tCebnfMqP65wY26YBopSLtCXXb1anUlRPlzPzRq99yKnt\
   FM7gK1XnBAZoZBBqCyZw9OHWmttIFWcml4Wd5BxF9uZh2Y8gtcN8UKWHv43tsNBa7j/T\
   ikIBSkIVI/6EQvyPW4YTdyz2V8RKHN5XcdpdWFaVhgSJMC4I6Bm0Lwenhkmal7Sd247q\
   uCtEow8qh+w7Jk4SxrmvJxd5sBnvz15OKEaHPeWNNJW00bWEDT+0ZzzD8vMN1/GkbbB3\
   s7UfcJXZbRu7HtQ+wHIblBKVstX3hMonra+k6wS9KPhcAaC3IjZ7ZApSedKk1sW1SuDg\
   l48YW2/cyS3LvmISQn9KPWK7yEpNQnV0vurn3ZFOGO0eDjSXUjI+xIrRia5GQ1yb31ma\
   nJnf2PdHcMmVr0wu4lMGno7a14nMRdnXkBU8bVOp8wF6Toz59hBJ3a/F+mP4/a19Ixra\
   wiVVeEPgoi9QQ9NcLgQEFCoskA+EpcLK0FxV2rYI9JFNF/nDxP5nmGtnkmlFaLo+pleH\
   CJYS0OTGKQr6X+Y65NOllx5nNwsnWkIUkCodoSt4Givdoe/S9JNIu8tW+jTBae2hNr9c\
   glErCNKDYe1+T+Ldyr9rfOKm9LKNyTBsodgF4KI/hFh9Iv/i55DTWtqjpN0eQnPTB3/6\
   +7KzTfSE9il5UMcP3zKKC2mAQvtyYxF3k0m24ZTwPs2LAPJkr/xtPH3BnGE/UfUDmvDS\
   TBp9m049Nh9oDZvI4HKsY8auiyENk0ys67F9GTHhOYM0FgHyP5qk4/IR5YC3lnq7xx6i\
   owebEJAy63htMytq+xd3cJyZR0lWBUOqvSpd/A=="
   }

   Example private key using optional fields:




Prorock, et al.           Expires 23 April 2023                [Page 13]

Internet-Draft           post-quantum-signatures            October 2022


   =============== NOTE: '\' line wrapping per RFC 8792 ================

   {
     "kid": "key-0",
     "kty": "LWE",
     "alg": "CRYDI3",
     "key_ops": ["sign"],
     "x": "z7u7GwhsjjnfHH3Nkrs2xvvw020Rcw5ymdlTnhRenjDdrOO+nfXRVUZVy9q1\
   5zDn77zTgrIskM3WX8bqslc+B1fq12iA/wxD2jc1d6j+YjKCtkGH26OR7vc0YC2ZiMzW\
   zGl7yebt7JkmjRbN1N+u/2fAKFLuziMcLNP6WLoWbMqxoC2XOOVNAWX3QjXrCcGU23Nr\
   imtdmWz5NrP43E592Sctt5M+SVlfgQeYv8pHmtkQknE8/jr7TrgNpuiV7nXmhWHTMJ4I\
   zoGXgq43odFFthboEdKNT/enyu+VvUGoIJ6cN8C/1B6o1WlYHEaL0BEIFFbAiAhZ/vnf\
   cUYMaVPqsDJuETsjetcE32kGCD7Jkume2tO68DlIhB/2Z2JX8mkcbxFI6KrmXiRxXQj9\
   9LVn1fEzdf3Vfpcs/C3omsFGqmTpLDK+AvW/SWVkDi2NKq7hL/AyxlW2u2cqVErQZUTS\
   Z+ic6V8kZfxr3gRMnH0KuF5BtjleZ/yVvqqPjwPOZegCKEl2Gd8duhcUde7CR55pil1o\
   UXy5AwgCcZTdEcJn1OPObGoots9T19gw1x4vnZCQUKVDPZuZ1gIkGqDUYXS0lcNTjCMs\
   miFEmnOZvB88jxULpb1vl9HoQ3ocM2oZu4AZRt9G/L07Mwcui0uFCWtAIau+2gqNAn/Z\
   AS10l0j2N0LLtAaOxoF+Ctzscrt0ZMyGHmoQ9daHkpUvEq0cO8hDtLplnq3lQIIIfROQ\
   jcNs9vNKBu87COBjukZD+L8vV4zy8FNO59MCSb9UCLwz2xvfdI1js9/J7hTGaVec8VPx\
   md42yPFrGw5Na1oefm8vW49EDmevc8AjAtwDirRBDFv9pX3+5S+M6jhteSLYvpKJXQT1\
   zs1379KvIHwkn9VHpA+PiUUw9TgF6xF8xWEGSNlOo1Vn1xtM3givehjYxJ5p5/kBEFZI\
   DCyFzstAirJ2GadNhae+P1JFZzJWnX5jaLwzldquZwF3yTzNho4sgBA+fKqiXcgn2nw1\
   vz0Dkbxr6cMaUool0eFScU1nAz1Z39W64LtT2nEuYsORx/ht2RzJxxFc21X3nLeEDFCe\
   NkNDxQFBSfpZjKKgJtXEx23mp+CbBVMrbagsLnzsAGLYbnroVmATU5Iqr6LgYBpuFs+N\
   Rkq7ZXh6CZPukMGQbcOGuNwO6NBuuMNhir5ayGk1ZBiW82C7Nu0hs2pLcgNqWMtt1+LW\
   8R96KyoSc784ZYAZ40QqvoySwmxQPBRTRJ+wB0sVpGBLTxdY9Gw3pXeXN5nao340d2ZA\
   7YEMlqcTHCAv3F8B9ewl7OfQlmg6bvdMuoVdVE+p0er7IAmWMRgviIzYv9sKEEQrCmua\
   2qL5xPSbD05KRf8ZAZ2B8lSCDR1nzXrQXZbXBKJivsCVQDuzxrwGE0gqRMpbk4f5GYCG\
   4i/O8Knoru+jjf6wVQDYKfyz1QUGRlXHkGUGlXfv03r7UbJugycjVO5kbGxhoZkqOq8z\
   ZEpkefvrrNoxeotw/z4QpjI8JlY97GDb0mGVHbmdHugjMtVTGhVJFBbPIinmR+emt7O+\
   4qOr7ywRxCvt2lziWtpPBwaf/1XDnN5Gesex1gR1YrcTRNmB808b01sxLQmxcTt4eQ0/\
   LUkas7qTJ3AQThOfDdtIpkqsthsBFy+WjSQuoXCYMRcPi6MlpxJndDF32lCnL1ranV6e\
   F2ST0SYT+NwNDesMzTRmNbHUW5KAhu0k9WABTvcM5ba0Uq6iOa1NsFrcLag+KhxN6HPn\
   oobwJ/EsDi5S7TAl8WrjqIhZ8x6h9eRRXerpaOw/FYk+2MpWByp/98VE12/EwOqAIiPp\
   elAvUeMOlRkpG64bJsmyYtHuNWgcv5Qiy7/eGw9ZpvB3J3G3jxvbynExqdFyDc067EKi\
   5WxDFPuZUjkfKpekNvzQuIrqs49BzcRyMt5ndEVE21TPPfZ/R8B7Rxnb2LiK+hQc+cc9\
   pEEaWgwAOiMILcp/1CyY6ImdO6RHsxwflMH7gej+hN41kaoEghIOl9kMGTLZbq5Pc8Pz\
   6F2LKTBMJWg9o/0blvilMH9EPblcLeF/bR1AZTUD6ZFdi2TxN6Epn3QVqeG/qPm1EBTF\
   Gw1V92m6/08Dd6zI1HPqwKbkHx4F567owofKHaM2imin0yVUpwxoRJrulRHMCB3tn8C4\
   ZpFl+sGV3Gip3tKlS7PKQkTqI6DMwxEbdrvtdY1sHZagpclLDisA/yFT4RR2m3VNJR9P\
   6Nx3teqN1eg6RXmD/MlKCdWrlcjZ/6yeIQYwbr9CjItY/tLQX2gtAR1SXOh99UUBVv+Z\
   E03VOZ+Ecsc78lSB9G/6n6CFzlbk/HgAF+cu0yMbGnEM8W3mTUspS4JBACwk5w0XWNNQ\
   DWVEdgzuLGhPq+hYExDjVZrLELhkH8YgZA+7RXXUZHM/joNOGHUhpUG/bFo3ktnaILCu\
   xsOXMUbDC3VcitFFHsGK1svtcERDFxk1HA8pGa59jT0do6n3wEbnBDU1soKNFtpmcVkE\
   Ul3XpvuoW3BgCwJzBUCWvPs47DJRgGxO11bSaEYYlhTVaaShcvzgz46AkqO+Q7TjckDP\
   /8uzsSQk0AbuhxWFQpSiBP8OZ/U=",
     "d": "z7u7GwhsjjnfHH3Nkrs2xvvw020Rcw5ymdlTnhRenjDUBgL6FklHURz5btM5\
   yrI5FQdWk+U2srVuSmfDV7EYG897mUFY35Z0WQ0mZ9XvIOKCh+GFFOk56b5FOFq6xnV8\



Prorock, et al.           Expires 23 April 2023                [Page 14]

Internet-Draft           post-quantum-signatures            October 2022


   UDQnFyY2JREUOHdiUjcUNxA1YxR3QiQ0BkE1AUBmFEOAUHZGBzQAU2dxVIgTQRV3U3g4\
   GGiISEYQhHRSWDIBQ2Z3UIIWdSV1EWhwBTYiWGI3VmJVI1UIU2REdUhHBoJ2gRhFUThy\
   BSQnhBIGI1AoMVB2MCNhUXQiNUGCKHgzUmQxU3dEgBhmQyIQgmFjdxY1dCJgGBSEB4Ij\
   CEJ0MBGIQWRRN3QjRmRSQWQIJgNjcjdnMlJhJIU1MlJRd1NmF4dwhHIIdEYYcAhEclBQ\
   JjESAiBwBQYzYlAIIocBcoZFcGVkA2SDMCVTBjgzCAAzNnQGYHI1VwJzYxQRckBIZBV4\
   VxZmZiVlYXgHFRNjdEFIYVOFIVdhcnIINEhhIURjg0cxJ0SCIWYUUVcHJzdDUTASciAW\
   UiJAglIoQkIwNjMlcwACZxcHZVJAh4EnNnWAZVVoBjNnNEcicTdyEEUHBVFjETETNjd0\
   YUFmFDVXNUcHFVJoE2AlVwFhMzc0dQckMYJUaBJ0JkUBdyd1AnZiJ3hYYkWAgyR1VziD\
   BERVh1NQAFIGWIhUZXCEQxIThyR1FIGGNTKAcwdRNBGDYEd2RVEwUDMzWAAhNQEEMYAS\
   hUSCgTJ3VIdXUlFBFxFkhVCCZEABJjQCAxFGNkhHQzM1YSSHNlEBEmJkgWZCVwZHRSVD\
   GDZzRCQiNhE3IghDhSFoBYCHNFVHMxZAZTSGAVMUQkhBKIFRQEVBB0cHNGEiJVVScQQh\
   hzQiBzKBYRY4Q0R2MVUldwVCIkQYEEgFYEREY2NERyFVdHJzdAZHBmhmdSCFIgh1IwGB\
   AxNzFjEoUWFCF4AhZRJSEROEEThxAGYBJTgUcUdFJBOFRmcVYnZUUFCAY1AnZEZBVThS\
   ECBQYBNGeAdzQ3KGhIE3ZiFxQoVCgQBjEFdFcIV0IAaFcgI0iAgAUVQAhEInQWECY1I4\
   E2U0MkAXQSZkdSRRc2I4BjEiSGd4hgQEEDcTRmhFd3MBMmY2gERxNwiISAVkFVETGCcI\
   gYhzRXByGBgzKGVXJUhoGEY1hgFmZWgmEWYWVoISd4Vlhid4VUMHgSZXhXUSaCgmJ3Eg\
   MQIzIDIThwRSARQhBFB2QQBjEgIoEHN1BhMCiIIBUlZWCHdBMyZFQoQ2UUJXJCFnZyFD\
   RTFUUTQoQmUjB0aHJXJHeDZlJGBCExATEUEDg3BTAChWImN0AWcFB3IUgBEARxVUREdX\
   QzhVBEBBF4UgcRhCg4gUcoRkdYCAIUQBRUJUYjFjEBYUhSBjIyV2cXBYckEiMic1N4ED\
   gDUGVSCHhCYURXcQB1ODg4hDJFJ3Jld2gyYnQYclRjE3VWcQNXJBYnOGhYFoU2dHATAw\
   OEeBUGQjJHcDgUJTRXBXJ3IAEjEXhXeEEmghIAAGdjUVBndnI2FCAVcyV4cxIyZ2dYE1\
   ZEiHcYJYaCcXQXJCaER1coIDRWJkcSNhEVF3JGOCQkYWYkcndRA1QTh0MFgzIyVocYJY\
   cwIAFRNiE1VAUECBI3MzQiZkUhR1cid1NSAXFXN0gUNnRCV0ISNmYnB3NIZyMIQWEVVz\
   ElEohnQyKBNoY1cCdmdjVYiGhVUlA0CHMTZIURBgR4aIJwJQJlIDMYhwNGNwiGcIBUdA\
   NXMBETUgICJyMkMIN1BAIAB4gEMDUwhndFJkQDEgRRMld4EzhRM0ZhGAYHMgZ4NhEEhn\
   U2I2VicBBXZUFUNoczcmBzBnUEBxUWcDg4RHUXZSOEZogABHRAISVEAzdoQhRmBgEWYE\
   Z4U1dgQ2gjgQUjMScgIIFQR3YFczhTYoB1IiVCYGBAVmVAFIdhRmZ1InhwdTRjJjNhVx\
   IzcWgjFlFCaChlIWUySIaDFwAWV3RAIxg2QWYgAYMUjP7wmwOwPp7Ukl3L1KalY/6dN4\
   dBr1AYS8JnkVq6pPeBfO7ccX95SrVfAO7EX7RVEYyhVR9QOQyEpLBUMcfcfnHCZWKM0o\
   OBF7BXiWMR9BQo4ybtpJGKQ+IZyCKUJVRhZ+uae182qYcBKFMdOOzXiO8kAa98eUy6SR\
   pPfKPD6D+xXgtJ0FWtYnp1Jy2aIG3HqMiTHoSdVIvccGkf94gpVWTMeJQsQpgq7dAJiJ\
   5JOMQjk7JIHcIzxb4T8sQHzA55MFfvM7Hus/8FUX7NfIN1JRmc2zHL/7kdfCFSwG67iW\
   U4ob2kTwdKzPvOL+d3e+AOE0PihJ4vVJAOjhWmO2fIFNvFhNqPh0MSiSkatPGbSVdqQ1\
   PsG6C+1YqMrTM7KFr4hTQM8a3+tAOsImMjXSSPDkVeuJFq1rw642SJJx8yZTXVe8g75D\
   ZTYghbeX5LLzaVkt9mZS7cW16Zy+C3MwnWDrGQ6hUDxYaYJp7SOGJHepcmVV214oD6nw\
   5QprgpGIxVcdXQUO0fhKwerYDkoOIj+uqk7NYDvOt8zANphYcE3v+6yVFyYh3eg7DYRJ\
   rIzIcbaG91ySv2iRRC+cWaymH6xuqaHRwZu/p962/u8/c3rITJzCoVc+ObnZ5oItZFBe\
   AYFhLBx7PvPdBULXyCqmtkOtnT/jnaCUVxtGeaIeQmmeM4yPq3d5uWBfOvIyuPmfBSKd\
   Y0NETGlsaoQuqFpOkCmQdMVZKh3UZ8AOjw22LlqaZlrUf0akb0fs7le2HT47KV9yOJHC\
   tec9tjHUeBVmma5O4AofGcVXLbkqKv+Soax9GooHVOv+uxa8iwjAdTZKtqwKnKDx4jaR\
   +zotCsYi4BuB2JbkjnHG6NL7ubN+aNKnwnzZnMKQZIh2Q7vSRYKTM8j9OGLq7IP8q2NS\
   oc7iT//eAvb4oF6LaY7qebxQ6ROXCSRrrXgpo+pw3ltfuUCuGzAxD4+wMZU3dlXsivhJ\
   PnTEjI/V6GmkRlfZ9XnYfj8SILETWk03dMFJh3LmUwkbRV+C3mL2GzjgQVTkvP82KDBL\
   DAR9iKyPkJnMnK9Ix/StVyJbGAtGp4jHnp+PSjz9ja4qI9jVRjGgIUQhw0DnI0fnplUn\
   Qhz3F9MQXMPLSPvFw8M0xkUKsAcxQvxZGb5LkYByZ0ZrO/ipphwnE6zQuOva+8uTyBX/\
   B9VR24tUItvlhy7SS6JrULrvTA+D/ZCiqKRx61iF6pU3BoC8fgA9D/AifiQnPz0SI5kx\
   FJfDTz1LWMjUlQKBHFvRFLE9eFD0rnwAGx7Pgpyc/KrLqVmcmj/96TYtoedp/iW4asfY\
   C2vs+GVyxVoumIdFPHJpencWbE/niZnVDaJCih1iqgXzDsI8bENh2B9cutDWX+bsHZSC\



Prorock, et al.           Expires 23 April 2023                [Page 15]

Internet-Draft           post-quantum-signatures            October 2022


   jSQb9YkGN+MoNiJlXmQHSJDyfPhzWPibdS/lpS90ppPWIY+PpLOfzDSGFFWswQ4q5Phc\
   pLWHx5lw9KSye+T86p6kadnBBTLTyfn0dG7NpO9QKQObMN60MnybkVGx5nH9yLJlFlmV\
   0H+K0VZIKm4UzYV+RYfqqXYtMqTQxeQ1U7L7o0H+6viErxuKj5rS3i+r1rdfECAGgCoq\
   0mixATHISAHi2eSV5fk3r5xMkKSwwPIRuMt50+kklRPUoLohTj7G1CnL6O2xwBdQMTUx\
   4Jq5JBWnfB+U4D9n0si1DwikIhpaUyOoBeaWo4iFQiWVLwjeeQvY6zj66l7OXsPHjZXg\
   uCitsWfp5MYV3cLTkb80uCM/xhp4Y0Edobt6x3k1FD8vbh8g3YAG0Xe/U+Iz3klnpCt2\
   ROQ2lGQa0JMl4nbQr3tqTLoXv4szaErfP/Xw05Cnt9DsBzN5DNrmfF6EDcfVf/hn8v9a\
   wrg6Rfv8Jpys1YFpwLanhb3Wz+x1yaDsa54IdlFOFnyBxv8GppbFrMpVFx/nLAXGIocc\
   WjcRKs0tBJUW/IoXeKOMPUd1wHR4dqUCEXsoexHJiNe5sH+akr6UIDObF70hhupBoiY9\
   AzVXi5zXf2VdafyQrkGfKz4BEUkiqcaajHr1CF9ZJ+Mjdmfr3z0xyCmCAWir5ZLOBXDj\
   T7sYCV3QjCz4a2mGvee9IxC9kSLapCq90UMAxnTLjJGQM/dlpgjDsjsCZX5wKdsnMs79\
   60Z75BGDOC1dDINj4f5kHZmwwcmw/04mi/1RPBUABXse3Up3eJQOX2haZPqmY0+2PZTF\
   exku9pETHtKcfSdRe1oJLmlB34JSogRmNp1eBxakcIL09huiFVtGVZng/pC/ryoJ/T9q\
   9w4aV5H+4u2dHc29Vb77SasxCdRH0sDaLaPpesRXsrdJwjbizOgzRlIx+83oO7NuhE+C\
   kKfO7cZMrFm8r8g1MlzDiFrTf3RTusMtiW6CVlVuTROPZFngqaR5yeYPprpSELtQHSwz\
   U5AaY5Qd8tbky5ec+2/QkXO+cdyWhQUuBRpibwpRpD3x1yTgT4E91cwTFpvSLk54ZHf+\
   D3EsZf0PYMN6d4jVdh9iv+0tCebnfMqP65wY26YBopSLtCXXb1anUlRPlzPzRq99yKnt\
   FM7gK1XnBAZoZBBqCyZw9OHWmttIFWcml4Wd5BxF9uZh2Y8gtcN8UKWHv43tsNBa7j/T\
   ikIBSkIVI/6EQvyPW4YTdyz2V8RKHN5XcdpdWFaVhgSJMC4I6Bm0Lwenhkmal7Sd247q\
   uCtEow8qh+w7Jk4SxrmvJxd5sBnvz15OKEaHPeWNNJW00bWEDT+0ZzzD8vMN1/GkbbB3\
   s7UfcJXZbRu7HtQ+wHIblBKVstX3hMonra+k6wS9KPhcAaC3IjZ7ZApSedKk1sW1SuDg\
   l48YW2/cyS3LvmISQn9KPWK7yEpNQnV0vurn3ZFOGO0eDjSXUjI+xIrRia5GQ1yb31ma\
   nJnf2PdHcMmVr0wu4lMGno7a14nMRdnXkBU8bVOp8wF6Toz59hBJ3a/F+mP4/a19Ixra\
   wiVVeEPgoi9QQ9NcLgQEFCoskA+EpcLK0FxV2rYI9JFNF/nDxP5nmGtnkmlFaLo+pleH\
   CJYS0OTGKQr6X+Y65NOllx5nNwsnWkIUkCodoSt4Givdoe/S9JNIu8tW+jTBae2hNr9c\
   glErCNKDYe1+T+Ldyr9rfOKm9LKNyTBsodgF4KI/hFh9Iv/i55DTWtqjpN0eQnPTB3/6\
   +7KzTfSE9il5UMcP3zKKC2mAQvtyYxF3k0m24ZTwPs2LAPJkr/xtPH3BnGE/UfUDmvDS\
   TBp9m049Nh9oDZvI4HKsY8auiyENk0ys67F9GTHhOYM0FgHyP5qk4/IR5YC3lnq7xx6i\
   owebEJAy63htMytq+xd3cJyZR0lWBUOqvSpd/A=="
   }

3.4.3.  CRYDI Signature Representation

   For the purpose of using the CRYSTALS-Dilithium Signature Algorithm
   (CRYDI) for signing data using "JSON Web Signature (JWS)" [RFC7515],
   algorithm "CRYDI" is defined here, to be applied as the value of the
   "alg" parameter.

   The following key subtypes are defined here for use with CRYDI:












Prorock, et al.           Expires 23 April 2023                [Page 16]

Internet-Draft           post-quantum-signatures            October 2022


                    +============+====================+
                    | "paramter" | CRYDI Paramter Set |
                    +============+====================+
                    | 5          | CRYDI5             |
                    +------------+--------------------+
                    | 3          | CRYDI3             |
                    +------------+--------------------+
                    | 2          | CRYDI2             |
                    +------------+--------------------+

                                  Table 5

   The key type used with these keys is "LWE" and the algorithm used for
   signing is "CRYDI".  These subtypes MUST NOT be used for key
   agreement.

   The CRYDI variant used is determined by the subtype of the key
   (CRYDI3 for "pset 3" and CRYDI2 for "pset 2").

   Implementations need to check that the key type is "LWE" for JOSE and
   that the pset of the key is a valid subtype when creating a
   signature.

   The CRYDI digital signature is generated as follows:

   1.  Generate a digital signature of the JWS Signing Input using CRYDI
       with the desired private key, as described in Section 3.2 (#name-
       sign).  The signature bit string is the concatenation of a bit
       packed representation of z and encodings of h and c in this
       order.

   2.  The resulting octet sequence is the JWS Signature.

   When using a JWK for this algorithm, the following checks are made:

   *  The "kty" field MUST be present, and it MUST be "LWE" for JOSE.

   *  The "alg" field MUST be present, and it MUST represent the
      algorith and parameter set.

   *  If the "key_ops" field is present, it MUST include "sign" when
      creating an CRYDI signature.

   *  If the "key_ops" field is present, it MUST include "verify" when
      verifying an CRYDI signature.

   *  If the JWK "use" field is present, its value MUST be "sig".




Prorock, et al.           Expires 23 April 2023                [Page 17]

Internet-Draft           post-quantum-signatures            October 2022


   Example signature using only required fields, represented in compact
   form:

   eyJhbGciOiJQUzM4NCIsImtpZCI6ImJpbGJvLmJhZ2dpbnNAaG9iYml0b24uZX
   hhbXBsZSJ9
   .
   SXTigJlzIGEgZGFuZ2Vyb3VzIGJ1c2luZXNzLCBGcm9kbywgZ29pbmcgb3V0IH
   lvdXIgZG9vci4gWW91IHN0ZXAgb250byB0aGUgcm9hZCwgYW5kIGlmIHlvdSBk
   b24ndCBrZWVwIHlvdXIgZmVldCwgdGhlcmXigJlzIG5vIGtub3dpbmcgd2hlcm
   UgeW91IG1pZ2h0IGJlIHN3ZXB0IG9mZiB0by4
   .
   cu22eBqkYDKgIlTpzDXGvaFfz6WGoz7fUDcfT0kkOy42miAh2qyBzk1xEsnk2I
   pN6-tPid6VrklHkqsGqDqHCdP6O8TTB5dDDItllVo6_1OLPpcbUrhiUSMxbbXU
   vdvWXzg-UD8biiReQFlfz28zGWVsdiNAUf8ZnyPEgVFn442ZdNqiVJRmBqrYRX
   e8P_ijQ7p8Vdz0TTrxUeT3lm8d9shnr2lfJT8ImUjvAA2Xez2Mlp8cBE5awDzT
   0qI0n6uiP1aCN_2_jLAeQTlqRHtfa64QQSUmFAAjVKPbByi7xho0uTOcbH510a
   6GYmJUAfmWjwZ6oD4ifKo8DYM-X72Eaw

   The same example decoded for readability:

   =============== NOTE: '\\' line wrapping per RFC 8792 ===============

   {
     "header": { "alg": "CRYDI3", "kid": "did:example:123#key-0" },
     "payload": "It's a dangerous business, Frodo, going out your door.\
   \ You step onto the road, and if you don't keep your feet, there's\
   \ no knowing where you might be swept off to.",
     "signature": "2As8T1AHenWzLuTojcAYFDnT05n4bmDGIWenHqoXVizL7311HtVg\
   \7PEJHYmpc1fIvFNrm0xJt0asD5bQk3ZY8WuEQDUjsn4j+zbyob8MPQI5u3p5ZkqlLhG\
   \6Q8p1q0Hd5voY4a78vNxFJpYsETc0bECAft196z5hml2VjuDBqI7W4ju/iDKambJIDz\
   \NLYgYinNyPcHjlfBP7aCfOqGBAOQrWuVgrAkdeM+uH6djaXW25+FeUl4Lg1uOIBPrcj\
   \ZJO4MO7j7BmiuHJDB74QG/ifVqnvr4z2alMWHjjR7nPPr2CIKpuRthSpNWYVTRSN3mM\
   \v0GjVLyaqhJpmUmewhjaQCi3iP7c59yKatGYjLPPEapsbN7ypIo1Bod/R2PZR0zeool\
   \d9k30VmGsVLkJ4OEIFnlA8epv+bJISApZWrGuU6NBP8vr4UB2D9DRd8zwvd/vI0BWdq\
   \nfglX4x18lWe8Tnd+21UC9n4zUb+KQlo9RR14VfXEOt9g5aOIzCWjAN+Oz8vqJ/ZwgH\
   \zZotZNF+nZehtFPcPLM3dpoUkEI391VH3QQ6VTYfbMW9wGJ6UnylxZFEzNCnMFF9Qhs\
   \7Xehy4yEDgJBFYIvbTRCfD+EbZbWQAnLKsm7UXXBR7HdUsJMhTkwdffGziWJBTf1UsG\
   \tqaCF1bvXgbcCSe0XGhc0QkQKwwj3kNWY9/hnhH1bn7kyySqaI+W4Ph3pKwRb38sCS/\
   \Gb3ryptI8zez0JR+lClWnu18noJjGincZq7jCGMiMCRFpzUV6rpY/FiM26IpZ8M9ShF\
   \BHsTN7KGpyIqG6Yc3GzOJ/4ir7V3I3wYguK7iBUiuTM+OKwxtM75carZJPX/2lkn2Hh\
   \TC+JVb2/yaHS2oDrlCwQosNhA/cB/cm+YmYgHc3KQwrZ/3Axr6weUSrWJ8qV+vJ5QKK\
   \a1+CLrkVGJX6vh+ps1NB5EV9yyMhBXAbbJZ3K+dGed3G7Vj/qF2kbnIUlSIeP1f6LsH\
   \XASuVLTU6qG0rTaCMYKwaAc5ROwAgyZmPXuOUwyCtNFb0+S73uX5/N2drrUPdXiURW+\
   \luFKCtaNimU8myoz6YkoY234kz8pedST8eqBZAioe8HeYEKtZSAyYov4YfLgkqHqJG6\
   \ycD2uA33kwnMim+jg/hIrWAIYYP9R90KECTvFR877RtfFgfn3+tZjWlmsxHZ5pNsTIA\
   \dNR+VmNpoUZkQ0dgHuFLztyAnCaumL38LHYHFHj2boa0zYsMGw8WtpEQ3+BNgoanNax\
   \dJ5THRRmhvMS3EDwanERimsZ6ZjdK8uchuVhytNiiKvBwEFWYIyoK9uUMBoEfDje4DX\
   \wIAefXYCqPK8eXhL+9qDLxADlDQbCu+Ey3whX/r4r2Q6l+34HpRrn3g5ok+GtO/3ni9\



Prorock, et al.           Expires 23 April 2023                [Page 18]

Internet-Draft           post-quantum-signatures            October 2022


   \dYiIYpcXYfhMGDoXJLZ3IMkK7L6e5u4/Wye7lot2B5ekSGRrkLkjv+bTIkppxbTU4Pi\
   \n40qbD91sRzw2/GzZmJsfcFaKbj5dhoNWyh5cZr1PqsxMI5EdXSxJ69VWf8e+h4iPoB\
   \YS1JnUjhicVWslpA1rdAvTkAsVY8rC22e09Hxzbkb/E7bt3iLDpekbbQAghZ31AwDv5\
   \KEG72bBbXIYHzPvhJzrlS2LR0XKTJVd8tAxOSdxQDOt8tE2eKpmWZ38MJfRIxt2Rzol\
   \p+bpKrR++pMLRrpViekVpZl/tlEojImNO5rLqxZhLxvZOyDfcT37jc1oqire527/Y9L\
   \3k894eHNYcXxjb0LGGPDeLuTSEX+afHZLNbd93Qa5VTmLwsPxEW/Erua6nXUrAR/87P\
   \0gIyce3h3sl5jzCXsQm/iODgyn7PTEo5ksQCFRPiyXq5xgiXGKGGkqTGg28Ohdby+lN\
   \DPnNHU2J0F6GLTqwK3qGbBLzDGIMR2sePGpxZ/pecoX7yn5bTOf4iY1OCyLo5nEgSeb\
   \JdBJh0ZU+QodLRN0cnenLmP1oNK2yCuT9uIAlWH9C1CLhBiEOfoIs9/r1W1XHPiPsX7\
   \c21w+B1IPfzUX1cVdndnNo4XdHl9CH1tYJDLr8LfeuYnz+bnaFlqEUryTc8zUl4A+qB\
   \SIDDDjefCbmDsTrdqzGT2J89MKViOogy3qJzyt3jo04xq+Q3OGjbOFJikyJEqUm8BmX\
   \d3ctGfzsEr+5w7fDRco40/tDQUSH0qOWOsPkhuelLqKDziJXwhPQI42miVN2A4+OAS4\
   \f2uTgpDNn1gIfH2+dOCkBjlhZeA1Tgrp8FHQxcaO5kut6cTLrL7CSBqINa7Khe1zyXa\
   \PZG/tXUk+iv0BYT92b7CRNmg1qhE0G8V3q3QrB6EePYa1WxRQ7ij4rRcQWcj66A1hZ5\
   \KjDUVJh+02cZTFrv97wM/im3vb3dbiSxAiQExSa2KATfLI2oS+y7RlRNJ+9nF/vTaFc\
   \0HOdKfmuJAUkAcyk/h0Quvdaf9jxEcstj95mva+HkIqPuFifidlvGiafKr4fHZryp1h\
   \g7QUtDRU2a4BRfzcLz6PKOBFV3xVI7qoQbKEqQyldv8mZRd0LBRKprxHW7PdUqutH2V\
   \GEmZ4UuCYXT11UweBx2W9lHrQX+xaKAjTu6oLYIOvmFVCUr4mCrYRcLZnzwORcsqIl4\
   \G88x8r5aeilL4lsQZO3kNotR4n0qzFVRU2+EXO7QJFm+NKxB7aRZ5oH+dSy+Ye6aMeG\
   \Epv491LU0LVnZNMBP2eUhoEoOgimmZGtUobjRdLuYyNiJfJzVkjwF3gYQtY59zb+46N\
   \SzvWUqpFUG80Vswns8GNAQ5hfLoH8OGGohT+UvoqvpTEXhiAAFstT/EQrHLZrYpXHJI\
   \YaICW+6uo9ixL0oWkfI0HlYaXyNkaFKHQ5ZbPaP45dbWq/dqXdrRe2YU8AqdjCxyyzO\
   \lyZR6zH9wHj0k1AIOHvnKZ/B2v4bS8YAtNZ1zgKbOvM4qqSIFETfr8N4yIteumHEznP\
   \prD7Gr6W2VCS/0FXnQt5y0QC8z4ffrnggwPjcZfsCRSknktQB1q6Cx8KUOipf+RhOvs\
   \HnNN3qJZmxz6YCvo2M7fxJtyRvm34UEVaj8QKXrmzX70Y9rDl6wEhhvSThaeq4dcfAC\
   \vczGXWgCLB10gl+Iz6hVDTgCx7bC2BQ2oHtzSDc+v/UuJewvVaIL9tn4CtMZU86f3Zc\
   \fTN2zke5alNpoJP9A+mkbcfy0aD6yFcn3nw2ueFDsssRg1ZcS5CujNeylAwxRYaNSmU\
   \zDzMygHu0CTxfGEG2c63J32HkG4Ds58KSk7HSD58jgScBv+QjBUAGSJozFG9y7yIF5R\
   \kD74aSJMYmuzow2UnGayR9yM5ONbW1brD4wNyJHqDIroCUvrL8zu24ErFWDKy6VaZ0m\
   \ggPvX38IoxIPnE+PmOtRGr+ua9r9zO47TtEoADjIEtwQuNem0S1fqeVx2Fd1TmKc5+v\
   \cxMsmuEKQiewTbviLdIWHTz4snU/dt77cxQEFWkS3pu31kCLyLbpiCKMrn1nELafNBg\
   \RbzwEqGTT0i24Kz/kvC5RYr2USuHKksZxPfgx7Y0OpY3IbemFO11EmnG9odSwnVcww+\
   \9/IIevZHUw1qqTxZu1re/AMfqhKgaD8XiwuKxPZQQo7Z6jj3yOugAVWYOw/88bAXO2k\
   \deVc0mG53sKH9ChLg35LdPrpLgHeFjIHJ27L9ucqUw70Pu58vRJUnYDey997y57k1vh\
   \9RwPkNvIs269v6s/xfg9VM9N4aY4X25EWCxchMWlH9LMamYF6JTP0v7v00cdHycmX5D\
   \EnwqspYYNomVpJlOOxgMAO9oy1E4dhg3IJo+fJgL9rgOxJ4INTJOg/9tUz21LPI3c1c\
   \D5pPs/y0zy0cF9f6ahaYxMDk/nfout2FGmoesMCaTN11JngYYC5H95cDeMwErm6ppSU\
   \woCqut45noJq0VS4V3PKfASIfuUwP3vgFKo+82Wy3dqEr+sBAsve44CKQ8Tq1GLYjet\
   \L3xugCkl0uaGh6TFqj2X/vJlXOW0Ouyvzt62fxeQ4esOrs4LdRxkJbKT2I2p6rQAlBi\
   \GaZLvOuccQh7NSt7BEJBy8QUrPV10vPmCNGQrKS6alC/JNFLaxmsP4CPQqwRQ3fg2ia\
   \qQRol0htD+UFjWUBXrQdrs48b9TdLHmbPHPbG6+ZeuCi87kJ/zJyjHA0SYUP6awkfga\
   \ckiLUppo0oNIc9/qsVr2lFIWIO9+UWnIFR9nNFPzgbqw/cMOC/uWAOOsGS8ADQ/rePO\
   \fTXx0mfkvI2YeTdiIayy+uwUxoLdz90DGhUysP+JGU9kZTqYNJYsjC4OgLXS+qKCYai\
   \oW/leFs1fdP6SH+E24pOOJARU/f/ZajcMMXAwQdIVeOo7jvDhMydne90/18fcwpNVN0\
   \tswhRsnW4uMCSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIEBMZHyE="
   }





Prorock, et al.           Expires 23 April 2023                [Page 19]

Internet-Draft           post-quantum-signatures            October 2022


3.5.  Using CRYDI with COSE

   The approach taken here matches the work done to support secp256k1 in
   JOSE and COSE in [RFC8812].

   The following tables map terms between JOSE and COSE for signatures.

          +========+=======+======================+=============+
          | Name   | Value | Description          | Recommended |
          +========+=======+======================+=============+
          | CRYDI5 | TBD   | CRYSTALS-Dilithium   | No          |
          |        |       | with parameter set 5 |             |
          +--------+-------+----------------------+-------------+
          | CRYDI3 | TBD   | CRYSTALS-Dilithium   | No          |
          |        |       | with parameter set 3 |             |
          +--------+-------+----------------------+-------------+
          | CRYDI2 | TBD   | CRYSTALS-Dilithium   | No          |
          |        |       | with parameter set 2 |             |
          +--------+-------+----------------------+-------------+

                                  Table 6

   The following tables map terms between JOSE and COSE for key types.

         +======+=======+=========================+=============+
         | Name | Value | Description             | Recommended |
         +======+=======+=========================+=============+
         | LWE  | TBD   | kty for Learning with   | No          |
         |      |       | Errors based Signatures |             |
         +------+-------+-------------------------+-------------+

                                 Table 7

4.  Falcon

4.1.  Overview

   This section of the document describes the lattice signature scheme
   [Falcon], the "Fast Fourier lattice-based compact signatures over
   NTRU".  Falcon is based on the GPV hash-and-sign lattice-based
   signature framework introduced by Gentry, Peikert and Vaikuntanathan
   [GPV08], which is a framework that requires a class of lattices and a
   trapdoor sampler technique.  For the class of lattices, Falcon uses
   the well-known NTRU lattices, while for the trapdoor sampler, it uses
   a new fast Fourier sampling technique [DP16].  The underlying hard
   problem is the short integer solution problem (SIS) over NTRU
   lattices, for which no efficient solving algorithm is currently known
   for both classical as well as quantum settings.



Prorock, et al.           Expires 23 April 2023                [Page 20]

Internet-Draft           post-quantum-signatures            October 2022


   The main design principle of Falcon is compactness, i.e. it was
   designed in a way that achieves minimal total memory bandwidth
   requirement (the sum of the signature size plus the public key size).
   This is possible due to the compactness of NTRU lattices.  Falcon
   also offers very efficient signing and verification procedures.  The
   main potential downsides of Falcon refer to the non-triviality of its
   algorithms and the need for floating point arithmetic support.

   The GPV framework, which underpins the Falcon design, is proven to be
   secure in the (quantum) random oracle model as long as the SIS
   problem remains intractable.  Falcon requires an adaption of this
   prove to account for the fact it uses NTRU lattices.

   Falcon brings several advantages over other approaches to signature
   suites:

   *  Post-quantum secure as long as the NTRU-SIS problem remains
      intractable.
   *  Compactness: Falcon aims at minimum signature plus public key
      sizes.  This should be contrasted with hash-based signature
      schemes (e.g.  SPHINCS+), which minimizes public key sizes but
      suffer from long signatures, and multivariate quadratic schemes,
      which minimizes signatures sizes but suffers from long public
      keys.  It also offers substantially shorter signatures than other
      lattice schemes while public keys are about the same size.
   *  Efficiency: Falcon can produce thousands of signatures per second
      on a common computer, while verification is up to ten times
      faster.  The operations in Falcon have O(n log n) complexity for
      degree n.
   *  Side-channel resistance: Falcon may still have an important
      limitation regarding side-channel attacks due to the hardness of
      implementing discrete Gaussian sampling over the integers in
      constant-time.  This gap that may have recently filled, but is
      under active investigation.

4.2.  Core Operations

   Core operations used by the signature scheme should be implemented
   according to the details in [Falcon].  Core operations include key
   generation, sign, and verify.

4.3.  Using FALCON with JOSE

   This sections is based on CBOR Object Signing and Encryption (COSE)
   and JSON Object Signing and Encryption (JOSE)
   (https://datatracker.ietf.org/doc/html/rfc8812#section-3)





Prorock, et al.           Expires 23 April 2023                [Page 21]

Internet-Draft           post-quantum-signatures            October 2022


4.3.1.  FALCON Key Representations

   A new key type (kty) value "NTRU" (for keys related to the family of
   algorithms that utilize NTRU based approaches to Post-quantum lattice
   based cryptography) is defined for public key algorithms that use
   base 64 encoded strings of the underlying binary material as private
   and public keys and that support cryptographic sponge functions.  It
   has the following parameters:

   *  The parameter "kty" MUST be "NTRU".

   *  The parameter "alg" MUST be specified, and its value MUST be one
      of the values specified the below table

              +============+================================+
              | alg        | Description                    |
              +============+================================+
              | FALCON512  | Falcon with parameter set 512  |
              +------------+--------------------------------+
              | FALCON1024 | Falcon with parameter set 1024 |
              +------------+--------------------------------+

                                  Table 8

   *  The parameter "pset" MAY be specfied to indicate the parameter set
      in use for the algorithm, but SHOULD also reflect the targeted
      NIST level for the algorithm in combination with the specified
      parameter set.  For "alg" "FALCON" one of the described parameter
      sets "512" or "1024" MUST be specified.  Parameter set "512" or
      above SHOULD be used with "FALCON" for any situation requiring at
      least 128bits of security against both quantum and classical
      attacks

   *  The parameter "x" MUST be present and contain the public key
      encoded using the base64url [RFC4648] encoding.

   *  The parameter "d" MUST be present for private keys and contain the
      private key encoded using the base64url encoding.  This parameter
      MUST NOT be present for public keys.

   Sizes of various key and signature material is as follows










Prorock, et al.           Expires 23 April 2023                [Page 22]

Internet-Draft           post-quantum-signatures            October 2022


           +=============+===============+==============+======+
           | Variable    | Paramter Name | Paramter Set | Size |
           +=============+===============+==============+======+
           | Signature   | sig           | 512          | 666  |
           +-------------+---------------+--------------+------+
           | Public Key  | x             | 512          | 897  |
           +-------------+---------------+--------------+------+
           | Private Key | d             | 512          | 1281 |
           +-------------+---------------+--------------+------+
           | Signature   | sig           | 1024         | 1280 |
           +-------------+---------------+--------------+------+
           | Public Key  | x             | 1024         | 1793 |
           +-------------+---------------+--------------+------+
           | Private Key | d             | 1024         | 2305 |
           +-------------+---------------+--------------+------+

                                  Table 9

   When calculating JWK Thumbprints [RFC7638], the four public key
   fields are included in the hash input in lexicographic order: "kty",
   "alg", and "x".

   When using a JWK for this algorithm, the following checks are made:

   *  The "kty" field MUST be present, and it MUST be "NTRU" for JOSE.

   *  The "alg" field MUST be present, and it MUST represent the
      algorith and parameter set.

   *  If the "key_ops" field is present, it MUST include "sign" when
      creating an NTRU signature.

   *  If the "key_ops" field is present, it MUST include "verify" when
      verifying an NTRU signature.

   *  If the JWK "use" field is present, its value MUST be "sig".

4.3.2.  FALCON Algorithms

   In order to reduce the complexity of the key representation and
   signature representations we register a unique algorithm name per
   pset.  This allows us to omit registering the pset term, and reduced
   the likelyhood that it will be misused.  These alg values are used in
   both key representations and signatures.







Prorock, et al.           Expires 23 April 2023                [Page 23]

Internet-Draft           post-quantum-signatures            October 2022


                   +======+============+==============+
                   | kty  | alg        | Paramter Set |
                   +======+============+==============+
                   | NTRU | FALCON512  | 512          |
                   +------+------------+--------------+
                   | NTRU | FALCON1024 | 1024         |
                   +------+------------+--------------+

                                 Table 10

4.4.  Using FALCON with COSE

   The approach taken here matches the work done to support secp256k1 in
   JOSE and COSE in [RFC8812].

   The following tables map terms between JOSE and COSE for signatures.

   +============+=======+================================+=============+
   | Name       | Value | Description                    | Recommended |
   +============+=======+================================+=============+
   | FALCON512  | TBD   | Falcon with parameter set 512  | No          |
   +------------+-------+--------------------------------+-------------+
   | FALCON1024 | TBD   | Falcon with parameter set      | No          |
   |            |       | 1024                           |             |
   +------------+-------+--------------------------------+-------------+

                                  Table 11

   The following tables map terms between JOSE and COSE for key types.

            +======+=======+====================+=============+
            | Name | Value | Description        | Recommended |
            +======+=======+====================+=============+
            | NTRU | TBD   | kty for NTRU based | No          |
            |      |       | digital signatures |             |
            +------+-------+--------------------+-------------+

                                  Table 12

5.  SPHINCS-PLUS

   This section defines core operations used by the signature scheme, as
   proposed in [SPHINCS-PLUS].








Prorock, et al.           Expires 23 April 2023                [Page 24]

Internet-Draft           post-quantum-signatures            October 2022


5.1.  Overview

   This section of the document describes the hash-based signature
   scheme SPHINCS+. The scheme is based on the concept of authenticating
   a large number or few-time signatures keypair using a combination of
   Merkle-tree signatures, a so-called hypertree.  For each message to
   be signed a (pseudo-)random FTS keypair is selected with which the
   message can be signed.  Combining this signature along with an
   authentication path through the hyper-tree consisting of hash-based
   many-time signatures then gives the SPHINC+ signature.  The parameter
   set is strategically chosen such that the probability of signing too
   many messages with a specific FTS keypair to impact security is small
   enough to prevent forgery attacks.  A trade-off in parameter set can
   be made on security guarantees, performance and signature size.

   SPHINCS+ is a post-quantum approach to digital signatures that is
   promises Post-Quantum Existential Unforgeability under Chosen Message
   Attack (PQ-EU-CMA), while ensuring that the security levels reached
   meet security needs for resistance to both classical and quantum
   attacks.  The algoritm itself is based on the hardness assumptions of
   its underlying hash functions, which can be chosen from the set
   Haraka, SHA-256 or SHAKE256.  For all security levels the only
   operations required are calls to these hash functions on various
   combinations of parameters and internal states.

   Contrary to CRYSTALS-Dilithium and Falcon, SPHINCS+ is not based on
   any algebraic structure.  This reduces the possible attack surface of
   the algorithm.

   SPHINCS+ brings several advantages over other approaches to signature
   suites:

   *  Post-quantum in nature - use of cryptographically secure hash
      functions and other approaches that should remain hard problems
      even when under an attack utilizing quantum approaches
   *  Minimal security assumptions - compared to other schemes does not
      base its security on a new paradigm.  The security is solely based
      on the security of the assumptions of the underlying hash
      function.
   *  Performance and Optimization - based on combining a great many
      hash function calls of SHA-256, SHAKE256 or Haraka means existing
      (secure) SW and HW implementations of those hash functions can be
      re-used for increased performance
   *  Private and Public Key Size - compared to other post-quantum
      approaches a very small key size is the form of hash inputs-
      outputs.  This then has the drawback that either a large signature
      or low signing speed has to be accepted




Prorock, et al.           Expires 23 April 2023                [Page 25]

Internet-Draft           post-quantum-signatures            October 2022


   *  Cryptanalysis assuarance - attacks (both pre-quantum and quantum)
      are easy to relate to existing attacks on hash functions.  This
      allows for precise quantification of the security levels
   *  Overlap with stateful hash-based algorithms - means there are
      possibilities to combine implementions with those of XMSS and LMS.
      For example, both have the same underlying hash functions and
      utilize existing HW acceleration.  Furthermore, an API to a XMSS
      implementation can be directly used by the subroutines of Sphincs+
   *  Inherent resistance against side-channel attacks - since its core
      primitive is a hash function, it thereby is hard to attack with
      side-channels.

   The primary known disadvantage to SPHINCS+ is the size signatures, or
   the speed of signing, depending on the chosen parameter set.
   Especially in IoT applications this might pose a problem.
   Additionally hash-based schemes are also vulnerable to differential
   and fault attacks.

5.2.  Core Operations

   Core operations used by the signature scheme should be implemented
   according to the details in [SPHINCS-PLUS].  Core operations include
   key generation, sign, and verify.

5.3.  Using SPHINCS-PLUS with JOSE

   This sections is based on CBOR Object Signing and Encryption (COSE)
   and JSON Object Signing and Encryption (JOSE)
   (https://datatracker.ietf.org/doc/html/rfc8812#section-3)

5.3.1.  SPHINCS-PLUS Key Representations

   A new key type (kty) value "HASH" (for keys related to the family of
   algorithms that utilize hash based approaches to post-quantum
   cryptography) is defined for public key algorithms that use base 64
   encoded strings of the underlying binary material as private and
   public keys and that support cryptographic sponge functions.  It has
   the following parameters:

   *  The parameter "kty" MUST be "HASH".

   *  The parameter "alg" MUST be specified, and its value MUST be one
      of the values specified the below table








Prorock, et al.           Expires 23 April 2023                [Page 26]

Internet-Draft           post-quantum-signatures            October 2022


          +==============+=====================================+
          | alg          | Description                         |
          +==============+=====================================+
          | SPHINCS+128s | SPHINCS+ with parameter set of 128s |
          +--------------+-------------------------------------+
          | SPHINCS+128f | SPHINCS+ with parameter set of 128f |
          +--------------+-------------------------------------+
          | SPHINCS+192s | SPHINCS+ with parameter set of 192s |
          +--------------+-------------------------------------+
          | SPHINCS+192f | SPHINCS+ with parameter set of 192f |
          +--------------+-------------------------------------+
          | SPHINCS+256s | SPHINCS+ with parameter set of 256s |
          +--------------+-------------------------------------+
          | SPHINCS+256f | SPHINCS+ with parameter set of 256f |
          +--------------+-------------------------------------+

                                 Table 13

   *  The parameter "pset" MAY be specfied to indicate the paramter set
      in use for the algorithm, but SHOULD also reflect the targeted
      NIST level for the algorithm in combination with the specified
      paramter set.  For "alg" "HAS" one of the described parameter sets
      as listed in the section SPHINCS+ Algorithms MUST be specified.

   *  The parameter "x" MUST be present and contain the public key
      encoded using the base64url [RFC4648] encoding.

   *  The parameter "d" MUST be present for private keys and contain the
      private key encoded using the base64url encoding.  This parameter
      MUST NOT be present for public keys.

   When calculating JWK Thumbprints [RFC7638], the four public key
   fields are included in the hash input in lexicographic order: "kty",
   "alg", and "x".

   When using a JWK for this algorithm, the following checks are made:

   *  The "kty" field MUST be present, and it MUST be "HASH" for JOSE.

   *  The "alg" field MUST be present, and it MUST represent the
      algorith and parameter set.

   *  If the "key_ops" field is present, it MUST include "sign" when
      creating a HASH signature.

   *  If the "key_ops" field is present, it MUST include "verify" when
      verifying a HASH signature.




Prorock, et al.           Expires 23 April 2023                [Page 27]

Internet-Draft           post-quantum-signatures            October 2022


   *  If the JWK "use" field is present, its value MUST be "sig".

5.3.2.  SPHINCS-PLUS Algorithms

   In order to reduce the complexity of the key representation and
   signature representations we register a unique algorithm name per
   pset.  This allows us to omit registering the pset term, and reduced
   the likelyhood that it will be misused.  These alg values are used in
   both key representations and signatures.

   Sphincs+ targets different security levels (128-, 192- and 256-bit
   security) and tradeoffs between size and speed.  For each security
   level a small (s) and fast (f) parameter set is provided.

                  +======+==============+==============+
                  | kty  | alg          | Paramter Set |
                  +======+==============+==============+
                  | HASH | SPHINCS+128s | 128s         |
                  +------+--------------+--------------+
                  | HASH | SPHINCS+128f | 128f         |
                  +------+--------------+--------------+
                  | HASH | SPHINCS+192s | 192s         |
                  +------+--------------+--------------+
                  | HASH | SPHINCS+192f | 192f         |
                  +------+--------------+--------------+
                  | HASH | SPHINCS+256s | 256s         |
                  +------+--------------+--------------+
                  | HASH | SPHINCS+256f | 256f         |
                  +------+--------------+--------------+

                                 Table 14

5.4.  Using SPHINCS-PLUS with COSE

   The approach taken here matches the work done to support secp256k1 in
   JOSE and COSE in [RFC8812].

   The following tables map terms between JOSE and COSE for signatures.













Prorock, et al.           Expires 23 April 2023                [Page 28]

Internet-Draft           post-quantum-signatures            October 2022


        +==============+=======+====================+=============+
        | Name         | Value | Description        | Recommended |
        +==============+=======+====================+=============+
        | SPHINCS+128s | TBD   | SPHINCS+ with      | No          |
        |              |       | parameter set 128s |             |
        +--------------+-------+--------------------+-------------+
        | SPHINCS+128f | TBD   | SPHINCS+ with      | No          |
        |              |       | parameter set 128f |             |
        +--------------+-------+--------------------+-------------+
        | SPHINCS+192s | TBD   | SPHINCS+ with      | No          |
        |              |       | parameter set 192s |             |
        +--------------+-------+--------------------+-------------+
        | SPHINCS+192f | TBD   | SPHINCS+ with      | No          |
        |              |       | parameter set 192f |             |
        +--------------+-------+--------------------+-------------+
        | SPHINCS+256s | TBD   | SPHINCS+ with      | No          |
        |              |       | parameter set 256s |             |
        +--------------+-------+--------------------+-------------+
        | SPHINCS+256f | TBD   | SPHINCS+ with      | No          |
        |              |       | parameter set 256f |             |
        +--------------+-------+--------------------+-------------+

                                  Table 15

   The following tables map terms between JOSE and COSE for key types.

   +======+=======+======================================+=============+
   | Name | Value | Description                          | Recommended |
   +======+=======+======================================+=============+
   | HASH | TBD   | kty for hash based                   | No          |
   |      |       | digital signature                    |             |
   +------+-------+--------------------------------------+-------------+

                                  Table 16

6.  Security Considerations

   The following considerations SHOULD apply to all signature schemes
   described in this specification, unless otherwise noted.

   Care should be taken to ensure "kty" and intended use match, the
   algorithms described in this document share many properties with
   other cryptographic approaches from related families that are used
   for purposes other than digital signatures.







Prorock, et al.           Expires 23 April 2023                [Page 29]

Internet-Draft           post-quantum-signatures            October 2022


6.1.  Falcon specific Security Considerations

   Falcon utilizes floating point multiplications as part of fast
   Fourier transforms in its internal operations.  This is somewhat
   novel and care should be taken to ensure consistent implementation
   across hardware platforms.  Well tested underlying implementations
   should be selected for use with JOSE and COSE implementations.

6.2.  Validating public keys

   All algorithms in that operate on public keys require first
   validating those keys.  For the sign, verify and proof schemes, the
   use of KeyValidate is REQUIRED.

6.3.  Side channel attacks

   Implementations of the signing algorithm SHOULD protect the secret
   key from side-channel attacks.  Multiple best practices exist to
   protect against side-channel attacks.  Any implementation of the the
   CRYSTALS-Dilithium, Falcon or Sphincs+ signing algorithms SHOULD
   utilize the following best practices at a minimum:

   *  Constant timing - the implementation should ensure that constant
      time is utilized in operations
   *  Sequence and memory access persistance - the implemention SHOULD
      execute the exact same sequence of instructions (at a machine
      level) with the exact same memory access independent of which
      polynomial is being operated on.
   *  Uniform sampling - uniform sampling is the default in CRYSTALS-
      Dilithium to prevent information leakage, however care should be
      given in implementations to preserve the property of uniform
      sampling in implementation.
   *  Secrecy of S1 - utmost care must be given to protection of S1 and
      to prevent information or power leakage.  As is the case with most
      proposed lattice based approaches to date, fogery and other
      attacks may succeed, for example, with Dilithium through leakage
      of S1 (https://eprint.iacr.org/2018/821.pdf) through side channel
      mechanisms.

6.4.  Randomness considerations

   It is recommended that the all nonces are from a trusted source of
   randomness.

7.  IANA Considerations

   The following has NOT YET been added to the "JSON Web Key Types"
   registry:



Prorock, et al.           Expires 23 April 2023                [Page 30]

Internet-Draft           post-quantum-signatures            October 2022


   *  Name: "LWE"
   *  Description: LWE family post-quantum signature algorithm key pairs
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of this document (TBD)

   The following has NOT YET been added to the "JSON Web Key Types"
   registry:

   *  Name: "NTRU"
   *  Description: NTRU family post-quantum signature algorithm key
      pairs
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of this document (TBD)

   The following has NOT YET been added to the "JSON Web Key Types"
   registry:

   *  Name: "HASH"
   *  Description: Hash based post-quantum signature algorithm key pairs
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of this document (TBD)

   The following has NOT YET been added to the "JSON Web Key Parameters"
   registry:

   *  Parameter Name: "pset"
   *  Parameter Description: The parameter set of the crypto system
   *  Parameter Information Class: Public
   *  Used with "kty" Value(s): "LWE", "NTRU", "HASH"
   *  Change Controller: IESG
   *  Specification Document(s): Section 2 of this document (TBD)

   The following has NOT YET been added to the "JSON Web Key Parameters"
   registry:

   *  Parameter Name: "d"
   *  Parameter Description: The private key
   *  Parameter Information Class: Private
   *  Used with "kty" Value(s): "LWE", "NTRU", "HASH"
   *  Change Controller: IESG
   *  Specification Document(s): Section 2 of RFC 8037

   The following has NOT YET been added to the "JSON Web Key Parameters"
   registry:




Prorock, et al.           Expires 23 April 2023                [Page 31]

Internet-Draft           post-quantum-signatures            October 2022


   *  Parameter Name: "x"
   *  Parameter Description: The public key
   *  Parameter Information Class: Public
   *  Used with "kty" Value(s): "LWE", "NTRU", "HASH"
   *  Change Controller: IESG
   *  Specification Document(s): Section 2 of RFC 8037

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "CRYDI2"
   *  Algorithm Description: CRYDI2 signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "CRYDI3"
   *  Algorithm Description: CRYDI3 signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "CRYDI5"
   *  Algorithm Description: CRYDI5 signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "FALCON512"
   *  Algorithm Description: FALCON512 signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG



Prorock, et al.           Expires 23 April 2023                [Page 32]

Internet-Draft           post-quantum-signatures            October 2022


   *  Specification Document(s): Section 4.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "FALCON1024"
   *  Algorithm Description: FALCON1024 signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 4.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "SPHINCS+128s"
   *  Algorithm Description: SPHINCS+128s signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 5.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "SPHINCS+128f"
   *  Algorithm Description: SPHINCS+128f signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 5.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "SPHINCS+192s"
   *  Algorithm Description: SPHINCS+192s signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 5.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)





Prorock, et al.           Expires 23 April 2023                [Page 33]

Internet-Draft           post-quantum-signatures            October 2022


   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "SPHINCS+192f"
   *  Algorithm Description: SPHINCS+192f signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 5.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "SPHINCS+256s"
   *  Algorithm Description: SPHINCS+256s signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 5.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

   The following has NOT YET been added to the "JSON Web Signature and
   Encryption Algorithms" registry:

   *  Algorithm Name: "SPHINCS+256f"
   *  Algorithm Description: SPHINCS+256f signature algorithms
   *  Algorithm Usage Location(s): "alg"
   *  JOSE Implementation Requirements: Optional
   *  Change Controller: IESG
   *  Specification Document(s): Section 5.1 of this document (TBD)
   *  Algorithm Analysis Documents(s): (TBD)

8.  Appendix

   *  JSON Web Signature (JWS) - RFC7515 (https://tools.ietf.org/html/
      rfc7515)
   *  JSON Web Encryption (JWE) - RFC7516 (https://tools.ietf.org/html/
      rfc7516)
   *  JSON Web Key (JWK) - RFC7517 (https://tools.ietf.org/html/rfc7517)
   *  JSON Web Algorithms (JWA) - RFC7518 (https://tools.ietf.org/html/
      rfc7518)
   *  JSON Web Token (JWT) - RFC7519 (https://tools.ietf.org/html/
      rfc7519)
   *  JSON Web Key Thumbprint - RFC7638 (https://tools.ietf.org/html/
      rfc7638)
   *  JWS Unencoded Payload Option - RFC7797
      (https://tools.ietf.org/html/rfc7797)



Prorock, et al.           Expires 23 April 2023                [Page 34]

Internet-Draft           post-quantum-signatures            October 2022


   *  CFRG Elliptic Curve ECDH and Signatures - RFC8037
      (https://tools.ietf.org/html/rfc8037)
   *  CRYSTALS-Dilithium - Dilithium (https://www.pq-
      crystals.org/dilithium/data/dilithium-specification-
      round3-20210208.pdf)
   *  SPHINCS+ - SPHINCS-PLUS (https://sphincs.org/data/sphincs+-
      round3-specification.pdf)

   [DP16]: Leo Ducas and Thomas Prest.  Fast fourier orthogonalization.
   In Sergei A.  Abramov, Eugene V.  Zima, and Xiao-Shan Gao, editors,
   Proceedings of the ACM on International Symposium on Symbolic and
   Algebraic Computation, ISSAC 2016, Waterloo, ON, Canada, July 19-22,
   2016, pages 191-198.  ACM, 2016.  [GPV08]: Craig Gentry, Chris
   Peikert, and Vinod Vaikuntanathan.  Trapdoors for hard lattices and
   new cryptographic constructions.  In Richard E.  Ladner and Cynthia
   Dwork, editors, 40th ACM STOC, pages 197-206, Victoria, BC, Canada,
   May 17-20, 2008.  ACM Press.

8.1.  Test Vectors

8.1.1.  LWE CRYDI5

8.1.1.1.  publicKeyJwk

   {"kty":"LWE","alg":"CRYDI5","x":"lgNFI62eq4YKxuvpMl2V9SVtGV5z_vQQZei\
   \iCziAVcFMuUUzjpbwrd7uKHRbtxNPWsLIlfYKmM5SM-OLeoDII-GNQYJfm3QRt9l33P\
   \AOyJpbeLidJg6e4UAIZJQx-KbKrIVqK6F42P8WmhDWxgc5xJZXUabUtMHV-irm9pMP8\
   \kjrlRFuIenHS_YYj3RrX9yeAZKmD6YJsROVMEprjR1B7uOQxJYX1WNNRD5AEiGL8TKF\
   \oxbOg-qDIP-M6ubjuKZqlhd3_-z1bLJDVkN_uh9hSIlqpghWD7niDldxKBAUldyELqn\
   \WzvadJyhKTt3KevLOWGuPJGc927VgDnTVSvaiOW0bZu3wHEup5PxsqymxGEuJGkiY6Q\
   \zL15KWzr4jdhq-_HpknGUjg2LbC0Q-f5raUm27vkT8EI7A3i-ar5Jhd9lhfXpGJ4Ui6\
   \amgeTedhqJCKOzTrEF12ecwQ9ERhjdsksC8XMDe2lQS1W-AyHfntg2oPeC7O2q0E46J\
   \MG_OUcLtMo3ShprY1VF93ObswsozfX6mmwqinQvYSpDAC7HHd39mp6CwJu10auoPi7H\
   \DEAb0aSO-qUgdh8WOPgyCEe0GJ_Hpl7sokVq5dXtbV4458_zDtc-pUcX7C8J3OUgLfN\
   \KsZzeOxQhgqkk0nG56CTleN_9u4rfWQzQZBH5ofr_biWHgr05HZ-UdjL4ezxPUIGW7M\
   \_HvwktpowTnXfV4-6HTF16jqmH-AmO5XJlwjP44IbRMNk5m-vHOBJj6ELGiDuNQoiat\
   \hKHS_-L0AO-7d2IxcpVuNWZfz1SvHzC4XPHt2lp0l_Rp9vu7obwGlFRrnLx1IrWcK6n\
   \R3ux8oDJTM3H8J4cdRgzKaPM9_lBMhamWnpCXFThwRWshaTapgnLEfEXpMjikdho-SP\
   \8DH6yddFrV-Sl_1Z8re1vD5CUXh50EcOepvnDYK5deW-Jqh6e_wGGlrwD7d9XZK9hKQ\
   \oX1cYPsfkdgRIBywrD1bMIs7pyu5PVNSR39HD5woExp1y5bKgCaJDF-tBSl1tGQVl1U\
   \pzENPHMi6fTCsv0OtEuvPZJkDvE-osJ_3Ajj9eTdKilJDdIYzSKu2Uodc96vaH3bXJW\
   \05iBprV6h-nG6MuQuXIrUNiG9h8nQ7MmaJ_Jdr58_cBChxYZRu1zaJcSwpTecAtktv3\
   \R-Yp2Lc7LxebwbEa19598X7CQtyS4RoUKorLOX4FkuXplJZduQbM2QftVqA6ufBkFH2\
   \3Axy_fZooaz0oBM8YYBAIqJAs2Ya1iLfrdqo42rDL0K_VXmVGqctqKhM0etvM2nfx_8\
   \VbsdoSmionB4d2Ur3no0AvzZbHcmIdHFg-EgJzfoIAhgKdHIzsN_AWEC9CFAp0dPwdi\
   \MUs0sPhkWNAfs9hmnEX-IzxO57IyxE_iLkI9smuR6f2NkU23279NaZHBmIpmPU1tryg\
   \SZ0i8yssFqKCDpRZwVV83F1Wcg3pnGsh9HXHC7rqI3-TB0_KxbTEmgKVspoido3Tl2Z\
   \9Dx-9Jawe6rd7g1lheMOzlBWEfHFWwDTr5TxhEOo59zATIaJu4DxWkKfFQj4iXMYP-R\



Prorock, et al.           Expires 23 April 2023                [Page 35]

Internet-Draft           post-quantum-signatures            October 2022


   \hA8QxNe82yUXoJGJo04f-C7N1xXJ64dOPoW0JNeDyM7liqtAQQgR6TNzVJvOb97E4Wl\
   \AAC2gYfXGS8kOawcTyeWdytjXs8fqwOPJ3or2HZK1jnXZloGeSJILxHOQtl2PDM2k-W\
   \0KZ1CPzbzjqQwQdg9CZ1F02b1Kusl42T2OjUylXsDGg4vaF-_IYucO7js31adyf90GZ\
   \sMeoLqrwE1txMYJSk9SWSkjpL0csNDHH_sh5911O1ogQk6QoUIf_lMa-hg7EWKJAkP2\
   \w2NsxPqr8vIAcdyCO_t5b6XpYCp7gkZiVxFn8tSrlofZbyW-zT1gp1gVEMhrWK5tIBZ\
   \gE2ftMnG-AGekLYFD3aMzF3YZIDa3-Fs-_-YBOjx4ptOLCa8mXMUTj9s0KTXyB3BhYA\
   \V7n8MDBRYITV17KMkLrY9vU1uhkxzSrNnBtSewEXf8Q4sGv2wEJjRJZyNPQzGtXRHNr\
   \FKwCG3TVklCwc1d5C2Ttwh5HBtMtCBxTkAchRgRZshMWyVjnUiPn4rcGA-5XP6n8EZM\
   \XOPo9vYkFuvb83GSB1g56jNCKGNStA-ZP33KKw_U8zdGz1fKX5xGvWrTU1MkhTST-aX\
   \DHqpKjFTPU2M3wfraj37lfYK42rUYR-viKHyRXVH221DI6Ke-s1rKQxzSSHjSUBl3ID\
   \eHtFb-pklL_JqIabpAKh_LkSthBvsiM1M8PUkiw30zzKQqScYiMxl_Ns3yvoahiWDh0\
   \xO38smAiws9FjgI71mRywWBGJj4z21HTWfMAwWbzbld0MqZ4AW4zN6e-pMSfnPl-jF9\
   \2C-FcXG58UQuBociY7Jwpg1XvWrVsTo3I8Qedzp1RYVV8qu3TQCCiCLom-UOwehbPdE\
   \hp3ugI2nYjVygbk2QwseoRISKEylUlJ_vveItZCkinsK5Cy5g9OD59Ym4WzpdXjtRIP\
   \k1ilfyLYcFwgdnNVLSNk1hb1iHgde9rghymzaUkEDdQwjfjXu8BsjKABdVyJwqF2r3g\
   \V5UlK300F8Etd7n36y3RBxIx1fqkpCD-G-tePQ0zkbYwRouMC5P7Ws_Qj1WPAq9vIVF\
   \WYDmRcXN4PKLb94qOQu8Ev2MfffDKDTvuPWU33UvOd3KbzKd3Jyfpq62WbeXEr_JgJ6\
   \o442fEaWx4gh9tq1XZFQ4Wb9GzTuGz_hLkpCdOQd7snxiHPSxYqOjd9g8lYcsQKOhw_\
   \dHCuSKyxxIAmI2MwLmGp6YnhY_JrfuUpZ1jfwcSCUqrzEvAS7CDvwzJ6-PAi2XO43ou\
   \SP1-CGg9JS5hIiiIR5hpW3-Fqg2tOeqv7fFn_fAGyEtpHWDxkLJDTDcIzL2eU2umYUr\
   \dbPynO9J99cEW3MU956D6LbmgRWK6lxQ5m539KMP7D4KQPPDt6CRA3YqAzZw-Vga8zd\
   \2UxphCkORsaAs8pBihHwwe4ZhQl5qolmFKtQT2chnqVkn6nmpQmH3Th13XGf0RlByq-\
   \bTEcwboddD_vYorb6HHyv9ciM0qh4g7tgmiphuR5b6LiVyqwxrMAN13cU8TiNIveY9A\
   \fbS6qJMshNi61lkux4wnM6fpENDxCvRVCCyLB4NhS57fYddsTPiGZ6w1PeS_2Be8J9h\
   \IN1g_yLmN8C1-9dgSx3yYYJZ4MGBNzxtbQIYcdH0_1mraXouf7hkhHAvbDPEcpCfUxt\
   \mAI8hlYy-Pq1fjQTHoaEm9XaVe0SQfN6EsrbcXF2zjrG2uJuglRRM-IoWhleeMc1lv8\
   \WCi33fB2KJhNo-iTKlhFYQmsO6qJyxusPu5Bmcl1EzONbBuHOeIHxzWBFoz5o4ziz3A\
   \C1sD7eTc5-bF9enC-6J7OzRTx6mft5GwF8-FkQFJdqulPfgnr-_TYQZScKHW0Iki8kp\
   \TUTr"}

8.1.1.2.  privateKeyJwk

   {"kty":"LWE","alg":"CRYDI5","x":"lgNFI62eq4YKxuvpMl2V9SVtGV5z_vQQZei\
   \iCziAVcFMuUUzjpbwrd7uKHRbtxNPWsLIlfYKmM5SM-OLeoDII-GNQYJfm3QRt9l33P\
   \AOyJpbeLidJg6e4UAIZJQx-KbKrIVqK6F42P8WmhDWxgc5xJZXUabUtMHV-irm9pMP8\
   \kjrlRFuIenHS_YYj3RrX9yeAZKmD6YJsROVMEprjR1B7uOQxJYX1WNNRD5AEiGL8TKF\
   \oxbOg-qDIP-M6ubjuKZqlhd3_-z1bLJDVkN_uh9hSIlqpghWD7niDldxKBAUldyELqn\
   \WzvadJyhKTt3KevLOWGuPJGc927VgDnTVSvaiOW0bZu3wHEup5PxsqymxGEuJGkiY6Q\
   \zL15KWzr4jdhq-_HpknGUjg2LbC0Q-f5raUm27vkT8EI7A3i-ar5Jhd9lhfXpGJ4Ui6\
   \amgeTedhqJCKOzTrEF12ecwQ9ERhjdsksC8XMDe2lQS1W-AyHfntg2oPeC7O2q0E46J\
   \MG_OUcLtMo3ShprY1VF93ObswsozfX6mmwqinQvYSpDAC7HHd39mp6CwJu10auoPi7H\
   \DEAb0aSO-qUgdh8WOPgyCEe0GJ_Hpl7sokVq5dXtbV4458_zDtc-pUcX7C8J3OUgLfN\
   \KsZzeOxQhgqkk0nG56CTleN_9u4rfWQzQZBH5ofr_biWHgr05HZ-UdjL4ezxPUIGW7M\
   \_HvwktpowTnXfV4-6HTF16jqmH-AmO5XJlwjP44IbRMNk5m-vHOBJj6ELGiDuNQoiat\
   \hKHS_-L0AO-7d2IxcpVuNWZfz1SvHzC4XPHt2lp0l_Rp9vu7obwGlFRrnLx1IrWcK6n\
   \R3ux8oDJTM3H8J4cdRgzKaPM9_lBMhamWnpCXFThwRWshaTapgnLEfEXpMjikdho-SP\
   \8DH6yddFrV-Sl_1Z8re1vD5CUXh50EcOepvnDYK5deW-Jqh6e_wGGlrwD7d9XZK9hKQ\
   \oX1cYPsfkdgRIBywrD1bMIs7pyu5PVNSR39HD5woExp1y5bKgCaJDF-tBSl1tGQVl1U\



Prorock, et al.           Expires 23 April 2023                [Page 36]

Internet-Draft           post-quantum-signatures            October 2022


   \pzENPHMi6fTCsv0OtEuvPZJkDvE-osJ_3Ajj9eTdKilJDdIYzSKu2Uodc96vaH3bXJW\
   \05iBprV6h-nG6MuQuXIrUNiG9h8nQ7MmaJ_Jdr58_cBChxYZRu1zaJcSwpTecAtktv3\
   \R-Yp2Lc7LxebwbEa19598X7CQtyS4RoUKorLOX4FkuXplJZduQbM2QftVqA6ufBkFH2\
   \3Axy_fZooaz0oBM8YYBAIqJAs2Ya1iLfrdqo42rDL0K_VXmVGqctqKhM0etvM2nfx_8\
   \VbsdoSmionB4d2Ur3no0AvzZbHcmIdHFg-EgJzfoIAhgKdHIzsN_AWEC9CFAp0dPwdi\
   \MUs0sPhkWNAfs9hmnEX-IzxO57IyxE_iLkI9smuR6f2NkU23279NaZHBmIpmPU1tryg\
   \SZ0i8yssFqKCDpRZwVV83F1Wcg3pnGsh9HXHC7rqI3-TB0_KxbTEmgKVspoido3Tl2Z\
   \9Dx-9Jawe6rd7g1lheMOzlBWEfHFWwDTr5TxhEOo59zATIaJu4DxWkKfFQj4iXMYP-R\
   \hA8QxNe82yUXoJGJo04f-C7N1xXJ64dOPoW0JNeDyM7liqtAQQgR6TNzVJvOb97E4Wl\
   \AAC2gYfXGS8kOawcTyeWdytjXs8fqwOPJ3or2HZK1jnXZloGeSJILxHOQtl2PDM2k-W\
   \0KZ1CPzbzjqQwQdg9CZ1F02b1Kusl42T2OjUylXsDGg4vaF-_IYucO7js31adyf90GZ\
   \sMeoLqrwE1txMYJSk9SWSkjpL0csNDHH_sh5911O1ogQk6QoUIf_lMa-hg7EWKJAkP2\
   \w2NsxPqr8vIAcdyCO_t5b6XpYCp7gkZiVxFn8tSrlofZbyW-zT1gp1gVEMhrWK5tIBZ\
   \gE2ftMnG-AGekLYFD3aMzF3YZIDa3-Fs-_-YBOjx4ptOLCa8mXMUTj9s0KTXyB3BhYA\
   \V7n8MDBRYITV17KMkLrY9vU1uhkxzSrNnBtSewEXf8Q4sGv2wEJjRJZyNPQzGtXRHNr\
   \FKwCG3TVklCwc1d5C2Ttwh5HBtMtCBxTkAchRgRZshMWyVjnUiPn4rcGA-5XP6n8EZM\
   \XOPo9vYkFuvb83GSB1g56jNCKGNStA-ZP33KKw_U8zdGz1fKX5xGvWrTU1MkhTST-aX\
   \DHqpKjFTPU2M3wfraj37lfYK42rUYR-viKHyRXVH221DI6Ke-s1rKQxzSSHjSUBl3ID\
   \eHtFb-pklL_JqIabpAKh_LkSthBvsiM1M8PUkiw30zzKQqScYiMxl_Ns3yvoahiWDh0\
   \xO38smAiws9FjgI71mRywWBGJj4z21HTWfMAwWbzbld0MqZ4AW4zN6e-pMSfnPl-jF9\
   \2C-FcXG58UQuBociY7Jwpg1XvWrVsTo3I8Qedzp1RYVV8qu3TQCCiCLom-UOwehbPdE\
   \hp3ugI2nYjVygbk2QwseoRISKEylUlJ_vveItZCkinsK5Cy5g9OD59Ym4WzpdXjtRIP\
   \k1ilfyLYcFwgdnNVLSNk1hb1iHgde9rghymzaUkEDdQwjfjXu8BsjKABdVyJwqF2r3g\
   \V5UlK300F8Etd7n36y3RBxIx1fqkpCD-G-tePQ0zkbYwRouMC5P7Ws_Qj1WPAq9vIVF\
   \WYDmRcXN4PKLb94qOQu8Ev2MfffDKDTvuPWU33UvOd3KbzKd3Jyfpq62WbeXEr_JgJ6\
   \o442fEaWx4gh9tq1XZFQ4Wb9GzTuGz_hLkpCdOQd7snxiHPSxYqOjd9g8lYcsQKOhw_\
   \dHCuSKyxxIAmI2MwLmGp6YnhY_JrfuUpZ1jfwcSCUqrzEvAS7CDvwzJ6-PAi2XO43ou\
   \SP1-CGg9JS5hIiiIR5hpW3-Fqg2tOeqv7fFn_fAGyEtpHWDxkLJDTDcIzL2eU2umYUr\
   \dbPynO9J99cEW3MU956D6LbmgRWK6lxQ5m539KMP7D4KQPPDt6CRA3YqAzZw-Vga8zd\
   \2UxphCkORsaAs8pBihHwwe4ZhQl5qolmFKtQT2chnqVkn6nmpQmH3Th13XGf0RlByq-\
   \bTEcwboddD_vYorb6HHyv9ciM0qh4g7tgmiphuR5b6LiVyqwxrMAN13cU8TiNIveY9A\
   \fbS6qJMshNi61lkux4wnM6fpENDxCvRVCCyLB4NhS57fYddsTPiGZ6w1PeS_2Be8J9h\
   \IN1g_yLmN8C1-9dgSx3yYYJZ4MGBNzxtbQIYcdH0_1mraXouf7hkhHAvbDPEcpCfUxt\
   \mAI8hlYy-Pq1fjQTHoaEm9XaVe0SQfN6EsrbcXF2zjrG2uJuglRRM-IoWhleeMc1lv8\
   \WCi33fB2KJhNo-iTKlhFYQmsO6qJyxusPu5Bmcl1EzONbBuHOeIHxzWBFoz5o4ziz3A\
   \C1sD7eTc5-bF9enC-6J7OzRTx6mft5GwF8-FkQFJdqulPfgnr-_TYQZScKHW0Iki8kp\
   \TUTr","d":"lgNFI62eq4YKxuvpMl2V9SVtGV5z_vQQZeiiCziAVcFVyXWhRDnGPXKI\
   \-p70KAxRHm3Z7G8D21xfkTEWs04DNJgtnqBBjiKbqrqLXMEK5vvJe5W96PyYrlTbImN\
   \DBL6yQ0ZIYBYJm4YtmygJAakg2bQoyRAwIzMgIpBBkAgAFJMg1MgMUBgEYoQhGUOMma\
   \RloDABmgCKGhmN3IgQI4KECMExwBBNwoRlkhQpYbYwHKMFkaQtoaRgysBQm4YE1CYgQ\
   \7hBAcaEAgOGHLAskqRBo0CQVKCMiKhx2wZkYAJkEQGNiihogoQoEQYKAYCISxJxWLhx\
   \GZUlkkRFISQwGiVNA4WBJDCM0cZFE6VBGSWAWjKFWsSNUaYIRBAMGqFhWSAuYjaISMg\
   \MowIlw0BloThlpLCRJDIqHAQAwwZgBMcRSRQNHCJywABJCCJsIbWNyIiIJEFiw0hwEj\
   \Nug4RgSgAB2iAsgpRtYgCO1IAtHAIuUqIA3IIJ3MggyyBgGkWMm8QAhBaAgCJMScQkw\
   \QCFk5RNxJRFCqkgHDVmwkhEBAFNnEQoo5YJyYBRg4QgCAiF4ZiNCRkgJIls24hB2Uhp\
   \YsYBWkJtUrYx4TCGo7YlIDguXAZkAgWRY4QRgYBsoaiBA0JAkJCQ04Ask4IByyhiigK\
   \BE8GQnAIAjAIp2ShlERCCGEEsUiJtkoiQErhpSYAxJAUEYwggEbKNoiIkEyMlTCBI4j\
   \ZOXJAJ0cZsIkiADDIIGAJByBCFQwIuzLJQIKBIAyMAIUZJJLBlQAJhiCJtVMRpSARpg\



Prorock, et al.           Expires 23 April 2023                [Page 37]

Internet-Draft           post-quantum-signatures            October 2022


   \LQAIrZI0iAImygl5MRpUpSF2aAJokYAwgRQIJBtAyhRkhhuQhZGEieKSIAsEbUwwjCE\
   \0iQgVBBCCZRJWJRwC0ZG0SZl2rBBGKgo5CJEArFwSzBAG0hlkJQMGgclwgQm2AIqETE\
   \kSYgtCLQpELFBGAIEwBhEysRQ2UgCkwgJgbhg2IYtFCZqEBZxoBJOpJIBjERpSahAwb\
   \iMTKKIyihqwJKFGhCMwkBSUTaRiLSNjAKJoihwGchAy7JgAoYtSShyg8YNIEKI2hYhI\
   \hdyCUVJ3CCSVIJgSDINgsKMkJCEoEYFACURwYBxQagJoIIIAZFBRMZxmCguIjMxo6KJ\
   \U0AB07aN0qQQgzhtHKglCwYKCCZsUAhhlDYOgUYMSZaBlERBDEkpw7YtGgNOUqYFC6J\
   \h2ZQNCQaBWCIhozIKDDhpZChuRIKA5AaFIhiREUlQJMAN1AZRlKhQYUJyGiFgGUdqQw\
   \BS3IJhlCiGyoiFI7MApJKFWkANCzYSygQlkSgpnKSBikIqYiIFBLAkIcGMwrQJYCAkI\
   \acEiSACyoJkCBQKQkIg4xZMECBgkphtBBgtmDQpCqWJIgAwCAWGIpEBIhaEXDYIUwRl\
   \gAKBIaeQEoUglMgMgCZCGpcwwpQp2YKMyqaRCkhQowQB0YBBhBghC7lQRDYpFAghS8C\
   \IAYclGDmSFCEQ2aaNgEBsygRBpBaFIRMs4xgMCUJgArVk3AJoEbkxCSBI4haCI5VJlJ\
   \RQYyAFgSYJAUdJjAAqSyZRCgIQYiZJywYkUIaEAzYJWahBSwZOiTYgk4YpECcmCyFhE\
   \wIxEjFy4jYQwTJwkAQEUqJMxChuDIkhCiBJiAhGmCBOgxQJTBJukzYkm4JomUZtHDeG\
   \CAhpS6QkABUswMIFS6QgShgpmKYpwASE2hYIiwBIAzVgkERNZAYlGAlFg0BMQQRRWyi\
   \OkohJERItyJhEE0NwkbREmJBFGgWIk0BhRBBOSgBNYRZJFKOITAJghARtIwVxmZaQCh\
   \RpXBAMijJMYYAhkTQwibIxwTRCA8dNIJJgW5KNDJYAELiMoSCIGqZBVKAgSURtYDgMx\
   \Dgk4IYgFCCEwhaG45IwY5CNzKJQIAUKBEQEoARmHCBJWDggm4YsyUAkUMQlXKAtwiJS\
   \FKIMUjBpYgAJA8BFwzgIG0aRVBCIAsBBYIhkFLMgGCMqI0WCEjgAAJBtCZhBCSUQiyR\
   \uUEItYkaK2agNAEQm4ESREhNmIreMAxYuETZpEyJBUAJuJBRu7kh_85-NnVU1ybdxVd\
   \53EQwXd5rJr3r9DUZ9en2KzzPDgzcTPEBfQk6JsroofVPkTLuv91Qj4vyeB31IohvBL\
   \bh8fqaYioveZBPNbp2I_J9RfRRCxdSXau28NFfYfc5aeDMHfOM_UKqIIu-hUZNtGUNR\
   \NxS58X2hiJPFORu5EjJDMagA9tjYrRggbZuWkcpf67BUt2NMG68zIj27rB3tb3NwPzf\
   \zr1PJ0uVn0q17uZr5HozPSJMHqUjfJFxeMLxLNpYfIyxkMjlKT_WsvQiWacudZKFWk6\
   \IJhi8Pwp7wBXeF2zzDfZkpMtRKNeQxLGeJ5RCWqcW40FIOFzkVI1p-fckThXER0UXJL\
   \j_5Od5_KhaZPO22eM3MM0AvDhg3ZcoKKGIOxtL9WGS3Cg5xMrtiJOwN42YyehXxGUN8\
   \NYZL3nufSS0zslDq3SmQ6dM-SzsAB1oYw9g-DB07Y2xcPsNzH6QvcOc6oa9t0JK9RYF\
   \BySCyH9ZSCwfij1FFD81Zgd8ociINcPU8BFV0WpnOcYdRWmzX6czabmaVWCdGcBfCIB\
   \8kNw28PZhYmrzkgF3Ti8qDTCrZFMay1knaS0qRX3NDWIEs4fU_rYiMKsYi9dIEmXqPj\
   \zknXYi-Sj21mjxliPWZkT1Iqbh7d14i-1C4c9WA5HCXPSPNa8VRb-dmVjdZ9ZBvlYzU\
   \BiaRLfxwx6pbdslldHxDgFFBc8J9eDsH_-9dQgDmgGrgQgNI9ItlZwpvrTLb-n3YZmo\
   \ZhCd0mWgTZnuMRSCmWPTj_2iHgtqX-EHj0hOjqXXfu7t54FMSgyKYMiu8q1_xm_Xztg\
   \CPjE8tkCq1bAXZ-Vw4MXTf0ks9tiiUMExVLzT7hEgTVreYOqB_oToZVd_BVJqvbCNDe\
   \GBp3Sd8q2VdWr_X3ISmr1SBacl7loRwsVElEEa6a_unR2Cpk9M_j9wMXAR_-0pnY0sO\
   \GJKv9_1mWEMc8393npbg5P7I7cTS6bJOpcopRX2mlwof_QB65633bf51FBpmJ7qI-9e\
   \iEz0EJ4o46RNo990ZEEJ6z7HLCE_IJJwnnRQbaNUPymZhoJ7ALMTxU-TODBL1jotS-_\
   \2ZJPbS_yIOnx7sD1Gk4IqF39TDWUhqEdDbXR3laEJHTfeCezn32UBDuz_Jp3yl6nSrW\
   \htiFk-gZPfHf-6cz8C1QCV7ezl_HiwIflF2RSVT3ZNkkisfkvRnwJpK_RS5H8jvvMR3\
   \uVUE3MLVKznPg7Y5cbUERoCL_6DE6FHpZqPa6H0WKg7SE3bZpXbQiTnfo17kZqpYBCo\
   \KBjDkHzQgMNnA-l1Z2Pdzkumgz_volZO8WuK2pNg47c44Yenm2RBxvag1KsI8ZWSK_n\
   \Xia9yzygQHVh2h89MV2z1bynRinC5VysJ5KG1Zya_0jgLOmX0D1MG2m6mwmQ5OzHeJe\
   \ymk87uzKJDfdCAcrUSRRlVyBFO4Fxe2fdl58q1ofIrI6S1juh0gb0wPryCy5Izh4aaP\
   \gSpGYG7O6Eddi_8pdmIluXr7eSkwIqsQCT0eLYtXDmOWMmh5W4QDBZHrV_iA7nNM1PW\
   \fynapnsoyiCewwqIeForRRbYEnMHUd5ksFYHlLtAbsqvB9oIm98crCkN3V0eWg8Tzti\
   \f11S8JqD5G5QY8CdvxXzh5AeOIUziedqZd0trBhswRDpaM7n61vPt3wurgDgHktFJn1\
   \VVQtgIEqjMFP_lWfrDWaVSCgd5ekSvuPmYdjatIp3v0N5uyj_GqkCU0O98X7NcyWfBA\
   \gGtbTmn5yl25HFqPsLyGND0suzXjOeNX9N4e01u7d-Z57-9baO4sEJ1sHQ3PGTwc6Sa\
   \Y1BR-EF79WZBES9VI0AElkSkdMHIAVAQ9-JJxxJgNbdcWLbmrdH5-fWtEKRYRoA9LOO\
   \pe6ry1kBv3uOMqAKn7uneUrvADZmHxrVgAP1TV4OlYBdqOiz5QfauvgCM-V4S16D3Rd\



Prorock, et al.           Expires 23 April 2023                [Page 38]

Internet-Draft           post-quantum-signatures            October 2022


   \Nr8KWbYOuqSVI2Jc12AAbcwBTMDq1AKpIXU8xE_LYjjXXaBhKbtvtN3Qh7l2ge-d7RD\
   \DxefPqpafrQoa4KO_-YyfNgnIEG0lVWp3sZPenUnq2tEpgDAUIXcy2zMH4G5CmU_Ozb\
   \fh9iT97h5K3LLG7JnM_E-jneyEO6KkYIHlvEUC5J4PC84ixUWqr7xNNfE2URYmhlE_s\
   \VX5UZObF2MYRsOfb6dtVfojyliW_IN2n3KmggYfmVnQEl1XPC7dyN9gXfheu3agxDnw\
   \UjqbRj79oQdxmXHOhzE2JzhcglYD9BSPyfRH8o1PnP86LRAVGaYUm8HILZ0ESEJ3PYq\
   \P8K-uVY2P4Po8lbHgnFtH9U680jlqZ65rs1K5IKLctRZ7i58mO55jXAaEMpf0g-91Zy\
   \imJkJO9DeZ6-sI66y2hw7ofAUK9ZboFxYNtIQKulbIrncUILwvDxTCHCy4QPX1hMVgc\
   \6YF_vIrQFINILZ8tyYgqaoJlMd9YQEnGM9fqIWkcZtj4X1zJ-wFRxg_VXoT3thIHDuo\
   \kd0p5WGmuY5kmpa0CmYG6ZZLYJMGsYzf-8OZm3t_4_AHZwCPXfui8kCFOP_0EJSvlWo\
   \X_baoet6d4-u342BjgHnd9a2uOHqaZY_YHwdy3LxEVrusMxUqqUhjIPZfJJGhopUVOy\
   \KRxyP6nFMY8Z4rAs5fkrtURL2mjOfDJBAW0o6i1tBTyscVfSHBayMffby2glDPzmH21\
   \kSAffoWLRxo7pRm6TLXAjxTr4Rk-7CLQt8zURy8rdy815xvAEvtCweMeyWqjMDzJjI3\
   \fX3jMr6Sjw_yQ7JOZ1VPBLa5APNJKt8ilKST01W_gQMPIoVDZSAdnmjq1EytPfXfDDq\
   \CeC6l66qDuoxO7hOoHTrGZlztsduZsN7J8lRckp5AuBupmD3pQKeWRDKgoMxluTrt60\
   \V_7HtORNg-NCiWSejw0YGrboqyShJ5efIV9vzmh6-N1X6y5s0GShHgiWIo8xYFdshP-\
   \i1wzUoOAmPTaBiLHDjb0M7keH8HEpfmqnRWfIDZQ3T9xHIQXHcQYa8ggRGkAhcijr_x\
   \qdYN58YmNDRR5IKAPisnfe6jRxhIQxE4Pvphmpq4pRRTD98Ui6AXbuMEQuzqHJe25O6\
   \tgYIrvemsY2dtUZiMr5QzXDaAvWBJ2o60nlkWn2ucFATTjHipHLfs-tsuMova-XIKYo\
   \VfJ3MeX3nxQHbMGzYhKT9YMYNRQ7Yo0nYcBraTia3bprcStwTySZgUP3l4ybRQJrcso\
   \nwIVkl1C7XSaxKJhznwViTGpCSBwctn46yHMrlvvqNt8TCwClKk-8_OFsNxBhSjFxZC\
   \Y6zq-HaQe0HP59tDDEuUAjkcgfGNh5Aj_JGrz1WVnyDVrXGXZ6BpzqPbJJypjXukZpv\
   \U3yCcPNYVRKIUlstKFC43rN2XMQS-_K0NwGxbrHUiG01ApRg21AcLNjXQuO1_H5IMPP\
   \fUMPwXZrLNIVBmJjTnylI8uNwBmU1WRF-2v_jfdVqPvdHZtw3xodWSZuZmzgMvMVL1l\
   \sa78QCoZAqBEpqYEOxvwl99rlTPhnqHYM5Az41CWBY1co1AkCTfBpcBxKE9QdpvpIPH\
   \U1diCScJfEq1f3A_pMr-HrWrmpnk-KXRBgogRp4Hjezk9HyhxTfQA00RcPQPuDvxfu1\
   \EIVMhar4TdUjfA3OhQeigoXbRG9bC4fTJ6q3LiHAQRNgMzGIfwAZfgyTQXuAst4BvmH\
   \cS45n-dl2eeye8i7gi5V0vnfqCdhzCMGHh9gt1Vg50stA93xBPLJVudYcwUDitSHSs3\
   \AmakHXG8YHYOZuIJFvj_UtiMC7k4YMmF6ZTzOU2F7wmNgIdp1I-UqKPitk5BIWZbDpx\
   \jSwyfjty5bfM4lsONII38-TFGF6cWnWC-QClBhxYsnl8cUfZwoEiShOPK4iy0pMVpYr\
   \kfivcXzDYPfpWBEKE4BRcfRqrs4w5TK_zqLbt9tv8V_CLnJXEYmJrIdF6tVyIf2bGPK\
   \p58YF8QuPjJArNc4qVC1R9yyKs7hxNb4WLaWsDQPYEYlbJeTJ8TsCPM7mSvp7F3weqi\
   \AwbLAd5f8girEKeYSjx0jlK3zWbOBL7u_O7a8kJZYkt7L9sn5jnGumeLedvabOcWP-1\
   \g6hCjHn1BvVpI66spO4i9OZSVMEpcXWWUUMrxG373uuZlAqVbQu6mYuMJNwavv4hf53\
   \GwPRytC46rfTLIDvOBKVyTLRpGCQsWXqWw-IHAYLWoT00IZ695xePq5z03o-Sek-Kxj\
   \UgGg91tIm74KuaMYIrMQCyNDv_-Qdj_OEDAxRj2V4w5TS3c04Dy2IPftmSjOxivXS8S\
   \YJQNsncI1tXA2-di2gyvsr6qf2ae91QpCa0P3vW9golEgeO4Mq6lo4VAzaNrmPJhelL\
   \aQyE_NsYEfJhvI9EAAAbg4Q28Dg1GSxErZHd4tgy82nRqlYdPFzjGUvYFzS4lePnQ"}

8.1.1.3.  jws

   eyJhbGciOiJDUllESTUifQ.OTA4NWQyYmVmNjkyODZhNmNiYjUxNjIzYzhmYTI1ODYyO\
   \Tk0NWNkNTVjYTcwNWNjNGU2NjcwMDM5Njg5NGUwYw.8xELcU6FTHpMyTHwLqwmHJDck\
   \Zdm7J6zLy1wT6XtW5zG9qBQoCP2dBULau1YkM7ZECnZ09h8XEa_7L8dfiIsOdWHdbOr\
   \S5-OdQlDMbLEA8zgn8Jb12RyqH2Ehw9PsRCxp4BtyqvnZCnpV_UHykYdMVtUq2NKLT8\
   \XrZfJWXcG4dzz-GddE6jJQPmKDzBQt0CsmaEwQl_WzN-167I0mPMmzwxOJcfjerWg6H\
   \4wcwMj_0WPeAe5iMygAwCIIIFp72crFyLjWu3ziLojmKO65UL9_a99C_YbzagwNjYc7\
   \2SJVYDcaDWiyajvnXfGM-e9hpMO-SeX79p-U8PlKNKBb8aPzP7LSUxrwCdf_xFPS68d\
   \0QE6njannI7DbamW--LzMcRwKI6zUvdBVn0hYpM32fg2T-aOmW3KIL-aQZZ0wWH85OE\



Prorock, et al.           Expires 23 April 2023                [Page 39]

Internet-Draft           post-quantum-signatures            October 2022


   \JVeUrSVX2uaGp2eFbNY6Y_C4OwByKLmE5OtrQUsLYwzkfHu9jaTWhBfUXhkdQLGy1qO\
   \1xflJpbYfe4Doy7v0XfgDEYvGVYO-1PZ78d7WyrYLxJCSQGuuG8K2u7_g2QW0Rc5ESN\
   \D4adRMMBBG0RfRJiXMN3Fem8Si2rV5k-eoT-sMs8lsQcLWEHWmS38hH4IuRtsUmfXnz\
   \cq-X7mljwAKB6fnnU6poZvB0ag0MFNJha76N0fmdz3HeH4dK7f9DR2wt7pw_16h20SD\
   \xASLLMTeIYPVN4Vzi63KfZ23FsXcnqBAwaK4ihBC7OLwUNkwfZo11OSxiVXlkO0eVqT\
   \RiJe_VgDqxRk5sSgnaKBs_wklPeEG1K_cXLWcxp1akyC-e5kYdu3HX1g6Oo5MJdFPz0\
   \E4JX5LCNU5w5CrkoJSKHCyys3KHCT6vmnpyMesJWhywuGPa0iS65Q2brkwCgqg-pUCJ\
   \BeyqpzSVlJ-89xPPhU2BE6XSorXXAhrO9S_FehFw8ypNh2uS9S42Ul5vY4ccy-Jc6Tw\
   \y4Pwqecsr7AlnSsvHDrUebItid2Pqa9DHa9gN_1zS6f-u9ne7tC7_PnYS9M5warHhDt\
   \LTwm9k9z8bVtR7pHYKPWoutVtWaoI-Z0VVOvnZmKYL26gt1KJ7qUfvUOvzxNdkDHvV_\
   \IQlAx9U_uQdrmOglz1F2Ia967tMA-x2xQtlNA0kcc6e8ZZeW40eG0xXJgV7pYmsGtPN\
   \JvATmTCcEEqJ2rzG99PNAbNgon1UWz6-X3mRBXr5Kt75wP0I_IG3-k7SjqoTuOYmnOW\
   \pzaIKlsG8wL_Vk0r3x1gN3DjBxuA6_LmU5RyyCPlfPB7ZtxJKSiB7O7IGLJBmeYVnAL\
   \l1-24Nvy2jXjfeQJlJ8crOMQEglVliCci6XKmjtG_T8m5kTXrRL0yP64jir4M8H_tkL\
   \TKCW1DH51K_U7genF9auecB8ASy8Uj9X129A2ccvP58PDYsP8YHpA5wsfixDtJotfLq\
   \j3wsA-baB4hdQnhhZ0-K5Qufa8TIiCyyyIuJ1iV04IOsKWMAuW0ePGrFQwksba8GiW-\
   \b15CXP8jC_DPtR6OULeaxLIBjtykIm_p0hL6JprKV8FAD6QFCMlyHapirma8ubLdyx9\
   \p5c2STHq1UTCss8xTUyDcIz7oY_sVhk5Pelv5HFRpBRaoaVe2pcIcgAZ2uVOP8K09ne\
   \WdbBOwKXwZmlVdnCLXe-ylscsb6NyvMEdMWSrerjSv2CSFA_HHfiKCYJ8BC_DPEUedv\
   \nrAx4X0MGEnThIUah0AoRL41gp-AKuOp0lHftC2zBhHDxKeJpBS5UqTY7v8slTr6z1h\
   \cGbLUaNzBC7U5QXxiHGZVtcN2s1W4v6ilEaOJKj72FUBt6ME9v22sGphJaDJ1iGfktr\
   \LPSPAvp-6X6d0_pIbMydMyWABd-Ch9GOE4n-WX0cPUUIepm5loRUx7-dKG1MfmmU00q\
   \dLlEw_Dwn299TGGKFyDVwnNCnGGEDKEfmqJcvUOCD_i5JChe4QKwuM7wU3KBOtDhQag\
   \KLbIFa-4SZitqws8fn6TaH5DCi9E8JL7r3zvsfsJwj5-951ZIKTcB057cXynNkUT6C_\
   \bucH1ReBj8n8mGp7ZtTNusV9OMManLzpDlizgUlwDi9Gv4rH6VqWuSndnozLKkzIdrj\
   \a5iV9QuGgkuwCxkgcVC0Omixik9eBxkGdXbiUz8xdyYh21RLPLmHHELqqUUZMMcQGGF\
   \Bg_DHozNMT48-1mS4MdkA8FUAaAUOxBPA9Qkanqh1AJQf2jnw63J-iK2A6U4l0cxpzE\
   \-S2XXu51g6sgStI8iWrA8o3Xit8HenL_SNsNNk8tO_VwaO6Vj0poENkNqZS6MjSWR8y\
   \nbvItMz8ANt8ZLhCAlJRxsFwG9-t3CHVb6GfsbPSe4H6UGG91y4sJ-Sbmebl9eMzxJD\
   \ay2bi07C0IrRoWkAQsawu8Vbyyb8Pm40LqBgxbajimBELTDSNUZNMKHFw9uR5OQKXoe\
   \Yaet_LCpRzAv-tj3JpC8vJYWMdPwpcheIVjOqw2abjOoNDNRFZNbCUAHLjeqEC01Nwx\
   \kb1Nw_cUlGo4liuREMbgr9qqBpiELsr_qk9vIEB3AcgO7TJu-fq21jQ9AdKLHtyxHwz\
   \jGLER3YwW7i3qqcKcoCJbv9PPaFD4Wob3tZ_OKi2mOKvHq8cIjyEb1xGdXt73T9cima\
   \-dxshgiaayVzpMUSdVdHyvAfjK2JPpUEMJ-t3SCPN7QrPkmVhhUYCdxot3dIQ35TR4F\
   \V9sp-52UckVckfLSPZmthJ2XAG_a2xt8Jnek8uhgYs1YhWkaCfbq-PVTGKLLGeDgIdc\
   \W-vwzygAcMyMrH8CoSt6Zm3YLlpTaFN3eG0DJmvd7mSBcn7B_D7tQ2INEPK9YJKfjXs\
   \JEfEIi88lp4ZkMk81Nv7k-Cs7m3Qi47HeMA6dcbLHpq30UtNCnEzgI2-S-ZIB-m9Tno\
   \AenT3evvivdrK-B3Gg6n0N0xmhxM-jlH-Ad_9gio3Zqd0vIz6LSJZ6QbZmXewjCcehh\
   \hiY8-iHWw3eYZ8MvxkfgcsBtkxu2jRhHYM-nftbFt6Cgd2Yu47P7lK9Als8lhG6gjao\
   \hh_mVLq0BaHTrgQ7DO-D-9N-BJSrXWe-Ev6hx_NAQjmDuYa2ReGJnv0J1CHxeau9Bsw\
   \ZzRB3EwcnlevorMhgDWSnOYmM60wGiwAswssoe17Df3wcdt-sDyPBUqVPRaXGm88GPV\
   \xEJNESK6Zi92OH2r6u8JehAejnr2OKt3-sCEEDIpR6K8lgo-TaMTiF8WUylUWTfpym5\
   \veaDqFmp_AooB_OqPLDCp1TLPetVImQh1T2tg0DM5AdtJuz2eQ-jog_ENCIeofo7Og_\
   \QyTNR6RFGzlCVStRD7YGPozz_SC0Yn_sYpMpQ39glI0I36DXjdBOX3gcMN4esHXHHpS\
   \YttwxegCuGMbOAzMgG-ZGpC1YC5NH9VGAa2kXQwzlzuAQZP6N5YAMNbn4jJnUqbSZ0i\
   \GzN4zu7hEXlXOXvwVKLr4UJ1oxlIcVXVYFO_AjaRn-V4g7EdBCqA-FrlcXmLcGKuN2U\
   \aX0Gj-qLn9bPOrz2GlkQy5QXy32axxurIJRpAbA6O-yclqy54jzto7fg5gn1VRggMKf\
   \NPROZ9eyfQ_DmrH-60eoyJ1rDZ6NafR4gRwCXQt00F0Wze7H1bGpbbfrJbeXDbr9Lns\



Prorock, et al.           Expires 23 April 2023                [Page 40]

Internet-Draft           post-quantum-signatures            October 2022


   \1EjHzaqyVstqpKOGcxQaDsdqNciHTo-mhKGqB2LgyQ4z4iIrcmaHEfc4NIUM_MghxPF\
   \wi9w7kB89O0y41LUs6dHdu2ea-W1T_0mDXXdTW0fXNXQRdTKPwSSICi8vMMOBSn4k4F\
   \or7n73x5Rvzv8OocHA3GeE0By8ymVxuyRq2csGv2nAMIH2f8erKxh4Id_foQbnJyQF_\
   \sMZw1Fs6PC7UtRxLl6xgT7_Ynfhx-sgg38Ro_qMkwmJdBbwEPY4Vv-iu-PMKWpOXxQD\
   \_oiTjS2yuf27B729ToREZc4hUUGNnhG_6cNsCn68W-E6s-koJRg633jMcHX3Sv0IFb6\
   \DP3AggcLSaFd1s2V5zR4Y6PLUZHwg9M5kQbUl7zDpHwsI_ANmFMyf6KQU3XLiKq0g2k\
   \cvP2RyGf5CDQk5HWVXXm7TDGv7AYPKThtU4Az00HRKN8UYPjPJuOv73DRNDvxEEYV32\
   \hVlEyE3AYxRGrY6lOrAU1xXrATJBxJypIaaYXw-HVKwVcQYbbGyNCROUWRaR0aZ4LFX\
   \MCLEElVs7G6I7pIguDWKCY702dpaxBKDIOKbUPlVwWF1qDdJ2sH2iCYdfK2OZfX0FiU\
   \uK6JSaME4a2RGaT5uC7l2bGxw7zuK2n16xzH861vM_kVQzTMgYQhpS7to2_xnEvrQ0H\
   \ogrSCf6Yd215g7NtTDMjo5GgBi1TwXUdyCmGHaoFZRDCrLsyw5G0vz1oOC29Hv28ecs\
   \XtkFohjNNi_1Mw7wqBDMTRsLLb0pQ_LTMOZRwIaJfsGpa7FuCwvaQ8QTDfNMX1hdMzD\
   \e-gNpeW9gWU6hlw_SXEWKyqpsxOjqWNpTQLCJFW4_54HmVjQGs-0JqUoRwXEmoxQnEh\
   \5F5tOAepJuDeAaSnPcJHqC1G4WAPhIY4c2HiHlGHX1zjQnkMe7wmm1K5v7zsGxh1hCt\
   \pw_yCVH7_i1fB38k8XKsq2-sVNCsUWYvqAe2hVdIwv4CVNvRohkxBn9uJ-76nTxPbL3\
   \jJg5uUqD8kTpAv8LD0Hf3VlO7tYAMh4S6gbME7dw6I3UlcKAUmkXOs_AwbskXKL801q\
   \CnZlZRpJoMXbL1e-nT40pAHSzDTiVb9fWWUF5d2aeylzQxW1ucbEhFTtJK1tGa0E1EV\
   \Iz2_XfQu649ToHwsXJGiL_qLuX-v_HcO1hhm6d8_KYH1sXZm6sFVSp19QJPu5Xl6j6A\
   \wSj4A1k56nVzCYL47fT-c087s_parbwfH0WdTEfaWflXEKRdqvIW4bhzLE08XIligw_\
   \bd26QkWXWiK0CBaz_zNFptXbYIhjb599Ew_vN4jRRdU3k_UzUJIN6-3fMCImNgb8389\
   \KSzsx2VRQWN3vP1QQcS3-oxTq-dks-PIA8G_GzO7bTYli9957dy3z9kO7Z6grSNu_eY\
   \pmuROVhsc0Cr3OiXWSFpo8VkN49MAalSXlpNmQKQ9n9sYCebf1Mxz6KeTBInB4E_u5_\
   \mz7JjoinhYBUIRgmGiDFVeOkfToZToG7Qf6F2f3M3XTMDkQBH93RJBhRWXjD4gUIjTB\
   \vMehuU1Vz57CKRo1LAbiDb4f1mCrofTmXUvsX9zv7CWnMXnPgRmWVuHYsAoRgB6sNDE\
   \kTwf82i6yubpBo9ZAwtsz72LjdsQbscn35hp9-qak3ZsRhstnyApD4il6TMze7smwNb\
   \doDnXKmi56OP6-F2AcCNRqcDTXYZFfOC9qDVJQslKorZ8DGuwPNlIgnuozSTVzCNhQl\
   \ZfpYEB19FL6SYKPe1XzgSQo6s-IKo_90KbMqMpPaMwgNjGMfYAKcX4SxlFzeoVuvgmS\
   \5LEyJa_viB-lKbnrwbcaSj8pI_xqg8E2dBWu2YKJvcyxz7ZTF6YwySuVJHYIf0JVWsp\
   \_vd_LUj6ySe2NAOsMq0xceJFM6ssfhURjsUGZcQ6prm18tlAKeyWhnWl-c0ALCDyNyX\
   \UozNtO7kuCVFJtjEk5P9DdKdwgQaaTyErJcEA6fD3b3mfouZQ6PBQqTSAyEMrNARraA\
   \78_1OpZEZgone5LN3e-mhFK-NpFhteOKzV870Air3dEXVo6RodykqYCH6dberJdzdcj\
   \6COq6YRA8mdiXXcaZE6a1fkuEwRTFPBd9LZojPTfqh2ooo_MZ8h4qD-Ky4ixKZMWiwX\
   \FAWE7JicpFC94bZqK_XQ78n9HIytd6gLh5UwIhHrShfNwOunnT0yaV4e_Abf73zxmV8\
   \OryQvoaDobxAnsiEBE5B-7-QjSI-2MBm3meII1GMgz-jLtz4LoT1tBKgzxa1hS83s47\
   \Ul2S0JtOnkstYtefZjKwsQOVsn3nS4ioYDn9J49tt2MEznMOKIAY3y3bypoFLlibeHN\
   \pXs6A9wREKkfd1wC2ytSZ_G1x-IRBtwtWoictr7U2uY_QWSYnq2yEC8xfpmhz9kIFxx\
   \ceZjN-QQna3xVZJWw3_0HDSQxatTXAA0cH3CPnLQAAAAAAAAAAAAAAAAAAAAAAAAJEB\
   \ggJCoxOWV5SmhiR2NpT2lKRFVsbEVTVFVpZlEuT1RBNE5XUXlZbVZtTmpreU9EWmhOb\
   \U5pWWpVeE5qSXpZemhtWVRJMU9EWXlPVGswTldOa05UVmpZVGN3TldOak5HVTJOamN3\
   \TURNNU5qZzVOR1V3WXc

8.1.2.  NTRU FALCON512

8.1.2.1.  publicKeyJwk







Prorock, et al.           Expires 23 April 2023                [Page 41]

Internet-Draft           post-quantum-signatures            October 2022


   {"kty":"NTRU","alg":"FALCON512","x":"CjcORWYeLyAc5OSAR5tLh2bn0KXRcAP\
   \cAssTZu2nYLIatsrnlb2j23yBKQNdC_ak2axFDLyj8QeWtIyNphAjVTqC8Nfz6cuoHA\
   \GIPMV7rwWxd0WYYJTWUZUHJbJGIo75KV7-eQGQ2KUDcyQgjhcBWCxOwPxyYUN1EC138\
   \onR_xvcakAhjagU1GNowliiWVwEoVvK8oPtE-m8Wz8u4TfQ6wRorRZ1MsQENBHesWEt\
   \5H5UIGYhyck7hXVF4FHpLFEIvxSTjDUm3OZQXEmRM_4WARVQQnya7MM3Z6FIzJvoPV7\
   \IXGBqsaLrqwCpH9PBkECjzK4YIilVDA5iUR9gdbjAmjJqSgpHfmFWi9OGlhARYI-j12\
   \t8f3KykkFlyqHUuhulI7Y7Az3nAwXgePqsise7fSMIssXmtaFUag4g0k1QBklpwUiY4\
   \h9aNN4SjYKZQO7m1ZU9YJK7bVG3hmlaAKDiUXmas0tUTkh8Kld_oFS9BtOX15Q2oOEq\
   \Yd6YAJhY5lebavuaVtWTO9U4uzhPQtljcoRZkITdB8igKbrjxgxFdJ6mU1IuvFpE6eQ\
   \qAZ4M6U6jRVmzWZRScP0C0WXSPnlxrfJ1bEvhXNIepUmLsjjWKFuMbYcEjo2e4g85KA\
   \2bBsgfmqoUVE7M7KHrqUKdMZjkXd0nOaEg41gRmSUC3ASK2oqlWhV1H1KlrzDF01hBp\
   \L3yErDiT_Ng4Q6yrcE9rjAv2qSdigBwK3Jujeh50GFr5eKZR1570OlApp_Bs5v17CqJ\
   \8Q3VSUbKu0WT2HybcjOKpgnm0WM8Zn6IxeA9AOTfc8CRNwUMwZYWoLVSmvkBTYAAUSK\
   \EGmmRy6cCXZJ9zv580TOQ5Bm-bMSnydrY4ZOlaWthXDElEWMFK23zQyYHkPzG1JvIuf\
   \AUagNCQGQUy1_iWdpNOZ5DlDSJ1CIpWHASdrvnJ5gqUeYh-_1Bt7wVV9rknBQHQKe6c\
   \9rxgJhLq0erQ4BkyaDwWF6EDMUDJ9gLE2oDcnYJK6KuBsTjzZRIPWi5TANMQQWgZlgC\
   \mVeZQ_Zt6wB46mHKFxMzkQgIwPLVmVLt5dWJS1Cf8Bn13yYqc0R59cifsW61GTnmiqk\
   \LLKeU6Iu3eWo2OLhHXIUSLeGJWwYV2HzjNirrV12LdRzo9oqkb_EiLagseRL6s4vaPq\
   \BB9uIvQYuRDXRJxJUNSj2yNREPNDCICOAiJYRx1ZHCS_46kGKkDs04t4Z1SAdGXWAEw\
   \Ns4o-GWwjKyok6EYT1pa5mc6CEdp5N3A2h6kvxRPSZcD8EfKB3cWzQsbWkGbvoNXaxa\
   \HWkbEa0kZIDgKiRiInC-iVoRzqqXRBKFBMLG6QPJm61pK2VLxrJCjP9qw193OOyUKif\
   \QzgswOnYwDamsekYHOAmfL2b_kciRZl6EaVSlbnCYBkLVyiU0uTrcigrWLRtG1OJUkN\
   \iYCVF2AGx8TihI86WV3BZFCrVNjsyqucRhmOxxd6RqEZTge7i4bzWx4zAKzRZKJyovV\
   \1VtoX8Ct36hVtXVKsFn9vxqz6OdZtaWV12PG7CFCLGVnYKCONsX2s9YHo2AhxXRE74s\
   \hAUaD2APOKPXT0laA_BvgcssHJ3Jqsdy72JTImu24-mYpFLn8PIAk0Y8AGGnYmFNXdI\
   \z6ONvSxnH6T-oapAGJ8EYaTtsXDy25cJkaUyBanxiIW20CuoDVzu7jiPjwUuGLMUc27\
   \EpJAr2fGT3A5okzEdXN-Iiof3iwm5GfBUNRkLiD_kbIve4nOb_RkEVkRDY2i51fRKwk\
   \BxTptO3Po6rlZRKyr4SDgaNNwVljxc-Rcy7V9RDWkjqesoR_SkNy_e-lBev8DexEAHX\
   \crqhqifuLCa0fzn5GC6t-ai0my_tvMTKVsMBfW11SRfYKtw3vILELOLGJirsl1zGyZp\
   \wYHmHK9Fk0TPLnystG67flhWb0RM4awAyh4UZUK1QYWyEk-okmRtSmbJCCkoXFcRX5J\
   \BlElSMgWGaKGLt9AYA0fMoRNMStBXHU9dTJ0V2oLvITAfgS3K0aHEW7kI0shtPP6SPh\
   \XyYql-ijPQ3aPBBldkhfi21WiDBmhLA-yxUxcrVlZ2NkZtj34Qch0rzQoNLLVDpqLsm\
   \Z9yRNiXzEMxEaKmY5rXhngKhBcXuRP2p7SUZN5L6pEqaYncYWqUi4XAD1iYHxngDBdL\
   \kKyUhqWDcRZacAKLuK5NWjcNXce5RNDVMti5WfguGRNZ5Qu8xsK6X1Ez9k0lNKVTUnV\
   \SQtBbFbGYwIFNl3KYcgHEbMpSS5p6oYQhHl_8eqqIrWCvrC413ENMeFnHRsqrErnlZw\
   \SmSz4BDFA0GcuyNvVWt5_BUKx94IqY2ra_LQ-Lz8j5JDSzNxWJORBAA2S8o3m1teTEg\
   \KANewDdZTcvsVA0"}

8.1.2.2.  privateKeyJwk

   {"kty":"NTRU","alg":"FALCON512","x":"CjcORWYeLyAc5OSAR5tLh2bn0KXRcAP\
   \cAssTZu2nYLIatsrnlb2j23yBKQNdC_ak2axFDLyj8QeWtIyNphAjVTqC8Nfz6cuoHA\
   \GIPMV7rwWxd0WYYJTWUZUHJbJGIo75KV7-eQGQ2KUDcyQgjhcBWCxOwPxyYUN1EC138\
   \onR_xvcakAhjagU1GNowliiWVwEoVvK8oPtE-m8Wz8u4TfQ6wRorRZ1MsQENBHesWEt\
   \5H5UIGYhyck7hXVF4FHpLFEIvxSTjDUm3OZQXEmRM_4WARVQQnya7MM3Z6FIzJvoPV7\
   \IXGBqsaLrqwCpH9PBkECjzK4YIilVDA5iUR9gdbjAmjJqSgpHfmFWi9OGlhARYI-j12\
   \t8f3KykkFlyqHUuhulI7Y7Az3nAwXgePqsise7fSMIssXmtaFUag4g0k1QBklpwUiY4\
   \h9aNN4SjYKZQO7m1ZU9YJK7bVG3hmlaAKDiUXmas0tUTkh8Kld_oFS9BtOX15Q2oOEq\



Prorock, et al.           Expires 23 April 2023                [Page 42]

Internet-Draft           post-quantum-signatures            October 2022


   \Yd6YAJhY5lebavuaVtWTO9U4uzhPQtljcoRZkITdB8igKbrjxgxFdJ6mU1IuvFpE6eQ\
   \qAZ4M6U6jRVmzWZRScP0C0WXSPnlxrfJ1bEvhXNIepUmLsjjWKFuMbYcEjo2e4g85KA\
   \2bBsgfmqoUVE7M7KHrqUKdMZjkXd0nOaEg41gRmSUC3ASK2oqlWhV1H1KlrzDF01hBp\
   \L3yErDiT_Ng4Q6yrcE9rjAv2qSdigBwK3Jujeh50GFr5eKZR1570OlApp_Bs5v17CqJ\
   \8Q3VSUbKu0WT2HybcjOKpgnm0WM8Zn6IxeA9AOTfc8CRNwUMwZYWoLVSmvkBTYAAUSK\
   \EGmmRy6cCXZJ9zv580TOQ5Bm-bMSnydrY4ZOlaWthXDElEWMFK23zQyYHkPzG1JvIuf\
   \AUagNCQGQUy1_iWdpNOZ5DlDSJ1CIpWHASdrvnJ5gqUeYh-_1Bt7wVV9rknBQHQKe6c\
   \9rxgJhLq0erQ4BkyaDwWF6EDMUDJ9gLE2oDcnYJK6KuBsTjzZRIPWi5TANMQQWgZlgC\
   \mVeZQ_Zt6wB46mHKFxMzkQgIwPLVmVLt5dWJS1Cf8Bn13yYqc0R59cifsW61GTnmiqk\
   \LLKeU6Iu3eWo2OLhHXIUSLeGJWwYV2HzjNirrV12LdRzo9oqkb_EiLagseRL6s4vaPq\
   \BB9uIvQYuRDXRJxJUNSj2yNREPNDCICOAiJYRx1ZHCS_46kGKkDs04t4Z1SAdGXWAEw\
   \Ns4o-GWwjKyok6EYT1pa5mc6CEdp5N3A2h6kvxRPSZcD8EfKB3cWzQsbWkGbvoNXaxa\
   \HWkbEa0kZIDgKiRiInC-iVoRzqqXRBKFBMLG6QPJm61pK2VLxrJCjP9qw193OOyUKif\
   \QzgswOnYwDamsekYHOAmfL2b_kciRZl6EaVSlbnCYBkLVyiU0uTrcigrWLRtG1OJUkN\
   \iYCVF2AGx8TihI86WV3BZFCrVNjsyqucRhmOxxd6RqEZTge7i4bzWx4zAKzRZKJyovV\
   \1VtoX8Ct36hVtXVKsFn9vxqz6OdZtaWV12PG7CFCLGVnYKCONsX2s9YHo2AhxXRE74s\
   \hAUaD2APOKPXT0laA_BvgcssHJ3Jqsdy72JTImu24-mYpFLn8PIAk0Y8AGGnYmFNXdI\
   \z6ONvSxnH6T-oapAGJ8EYaTtsXDy25cJkaUyBanxiIW20CuoDVzu7jiPjwUuGLMUc27\
   \EpJAr2fGT3A5okzEdXN-Iiof3iwm5GfBUNRkLiD_kbIve4nOb_RkEVkRDY2i51fRKwk\
   \BxTptO3Po6rlZRKyr4SDgaNNwVljxc-Rcy7V9RDWkjqesoR_SkNy_e-lBev8DexEAHX\
   \crqhqifuLCa0fzn5GC6t-ai0my_tvMTKVsMBfW11SRfYKtw3vILELOLGJirsl1zGyZp\
   \wYHmHK9Fk0TPLnystG67flhWb0RM4awAyh4UZUK1QYWyEk-okmRtSmbJCCkoXFcRX5J\
   \BlElSMgWGaKGLt9AYA0fMoRNMStBXHU9dTJ0V2oLvITAfgS3K0aHEW7kI0shtPP6SPh\
   \XyYql-ijPQ3aPBBldkhfi21WiDBmhLA-yxUxcrVlZ2NkZtj34Qch0rzQoNLLVDpqLsm\
   \Z9yRNiXzEMxEaKmY5rXhngKhBcXuRP2p7SUZN5L6pEqaYncYWqUi4XAD1iYHxngDBdL\
   \kKyUhqWDcRZacAKLuK5NWjcNXce5RNDVMti5WfguGRNZ5Qu8xsK6X1Ez9k0lNKVTUnV\
   \SQtBbFbGYwIFNl3KYcgHEbMpSS5p6oYQhHl_8eqqIrWCvrC413ENMeFnHRsqrErnlZw\
   \SmSz4BDFA0GcuyNvVWt5_BUKx94IqY2ra_LQ-Lz8j5JDSzNxWJORBAA2S8o3m1teTEg\
   \KANewDdZTcvsVA0","d":"WiAGIXAgz4HzCD33-d9wvue8JPxC-AIO-EEIN-__Gx9AI\
   \g_gB3Ih-AIHfc0MQf-AL4v7L7wdfAAYOhEL__jEP4idAXX_f_0AAmF7v9mAMpQfB8nM\
   \ED7pPh173wi90IA_KIIQ-D8IRf4T_hjCLyCD58PQd98w_A8MIwh9_wAB8QJBb___dk-\
   \Mmeh8EIwA73wwb4EXgfEUgP-8D_viEPwBg94H_hIPIfeED2wD_7wwBAIPdDB4fggH_3\
   \wAJ8YBbCEPxc6L_fhEIASd8Dnfh__mgi__4_eEH5Q7IEiv-_4PQ9EQBObAMBfl1_4fh\
   \GkgA_-fn_CAEBu_Frv-jDwJOeIL4_cB7g_5CH_xB-EPyC3_3RDEDgN7FgAgb70PAj_8\
   \XSB8DwvgAHwRc8D5wDEEPQEEL5CAHwXwhH8XNgKDggE0AGi_7coP_GUG_hFwAQCH73w\
   \cEMnh_EEZSB6QG_87_4PA7_2QfKEI--Dz3_-AIIvDDwfii2EZAB4EIyBCL-y_IHwQh-\
   \L_ygKIg-jKDoe_-IJgB-Dvu-CEPwA-AZf_-MPvCKIBRf8YHRE8L3vAAD3Ah8Eg-E6MP\
   \wiIH_U8OLZP-EEgAjCDvRkIMIPgBz3fC6QHA9IJCPE-EQQE6AgQ-__-wh90XvB6IQAE\
   \AL4Ri934Oh4MPyC30eejB_4g9D__vhGIXiE-MHwi-ARAhBsYQZ-HgO-6XwAkF04PbCA\
   \AxfGTXdmF4IvaP4Hx8CIfOBAL4eeGAXw_H33xdGAY-A-EJRbIEYv_GAX_B_3wxhAAHR\
   \e8ERjDDwJP_EDWwfCAwdi4Pv-k9_5fCD7XdhEEPwg-AffC7_3AcB4wQ_BwPu9F74d9J\
   \wX_eB_f-cIHnvgF0n_AB7_tf_z_wfBv3B_7_wO9ALxfCCUJgg_35BbCHfe_4EQiD3zQ\
   \_a78HthGXZeB9wAsg4EYBCCIBN_wH_SB_4PieH8HBcGLwfBTvnf--IAPe_3YA-8Dge_\
   \KE4CC0X_ygyL_h74P4ff9sOyB98AwBMIPxiMDAfjCEIvBF8HR-F8Pf9__3xc8HgPgEX\
   \3wfF7wvlED_RBB8P-CP8HS86DwRZ5_4vn9_vuCAHQg-IMQMACIPxD8PofkFwYPfB_wP\
   \kD3_wA__2_i7zgh_-YgfgD_5ScH8Ht_CPQP-AHo_DAL2gh8D__dCPngc78nQAAMHwhB\
   \7f-9_wYwjEHQCDHvwPgIMYiaEHgt8CLwc_ML_A9F0Qxl6AIyiGL3yB8APC-AEgQE93f\
   \g92EQCBH4XO-B8Ygd1sJv_GDv-8CT4_k__aAc8DwgkD_H_i9wAPhAEAfh4D4f-CAPxB\



Prorock, et al.           Expires 23 April 2023                [Page 43]

Internet-Draft           post-quantum-signatures            October 2022


   \AEY-9AAHjd_zXhjELpfdAToAn-cvwi8YYAfEUg_FH_v_gJ4Hw9AAQgCGHgej93wO-D8\
   \ohg-EXh_EMH-7GL4Q-4EAOi5sQ-hBkQAlHsBgg2P4x_IA397ED2xcAMWxA5sPBX9vvf\
   \ACX3heCDwR_AEQ-g6P4gBwHn-94AIBi8MXff4EHPCDwey8H_4x95_gBe-IPxaAEYxeG\
   \HgwgCHw99J3YNgJ83wDJ4ARjJ4Oh-18exez_wRgEAIBeAf3vjGDoffAMH_a6P_P9GP4\
   \Ph8EgwZGAofk5wfiB_3fAeMAGwi8MAOHD8HgfF8AehCDo_A4LYA_MHvyi_74BE70v_7\
   \AEIS_D_oAED0gPi-Mv-eCEJBhB3pC_94wMiB8ARF6AAOh4TwCB__RO-LDH1_h_05_8O\
   \19gT8-QaAPLq7xvz5gop5Qf--Of-JBQKDxP_8eXU-Qwl2Q_uzO7lAObM-evnKd7lQPc\
   \CFQfsLOb-4dI0-Q0SEhPs0hsBQxTh1uwRA-QS9QYBFv8KAwIU4er8HAAOHOALBvTnDv\
   \gK9-P3yiA48gcOCxYs2vAG9OgnGiTMEysU29r9-uIS8dX5--0E9P71_gI2IDUK7-HZF\
   \_UE3fL80uEK7vX_1BfbASAK6QPpAwP5B-nsQOcJ7QH_MgH2ycgrQSX1CVgn9QwAuvwi\
   \7BLdGR4f70DS-gAQ7-MQGygSJAYMAu3y8CUGDywPBSwl-xEXG_vYDv3PEQj8FgX60xP\
   \_9ifi1O34Dvv5CPvVEhDY-gYHEwTC7P8R6-HJENojDBMMGuks_cvoIQgP9_cA4wYWF_\
   \T3FwbX3hznHOgpFiL03-sF7uYi-g3g6vAT59z5GAET_BzpCN0GAwkHHtgTIPr55d0LE\
   \AwD7iME__khGQYYK93c0Cza9OEN2fHt8vM0_wT88ukP7Ov8AfU8GgjtFQPh8Qbu6gjv\
   \8_AISA8m6iz3_w00Aesb5O8HFQ4zAegODxIMBPcCHuzm-yfbBvvr5vP0A9fewOkRAuU\
   \HBssYFrkjERIZ9h3r8CPo3dso9gUK9ecJ8toQ2CEe2f3hEBLz7wASDwMbBvYCFPsl-w\
   \r49tvp9CgE-xQT8PUQGdviBxnY1xwWBdX-CAvxJu4MLgP07x7oKOzW8REIORUM-vsQE\
   \PLi9Qj94u_3CezpABPk1AwZBAXbKOcn4O76F-4W5w4uzPfqJw4qAfcm-vLVIu3FF_H4\
   \9N7CHvIJ6AzwAPkA-w_UCiz4FT4D5-IBAukSEAIR-vDr8wPpBsgKA_3_5v4LDxMX4fk\
   \bBw7wBvYNBAAC4_UU7Q7uKM3x_g0BD_3m5xn86wQH4e786O8hAfQR4_0DDg717N_0Fd\
   \73E-sBIAP1ABH99BcgAyfH_-vS7uLcB-3u5fjvIfAyERbtB_8g_SEu__zvNRzrAA798\
   \TLu9RLU-BP7DRbnC-kmxAcAQRDsFwvuGxf5A_QA3BTnAtXuFNv48ePawvi_GfHwGfHT\
   \NPL7--nj_Rzu3AnsCuoTJAX07Q_q-fH7BCcXHOzzHOcs-eDYE-A1J_H39t3-zPgUBx0\
   \I30oSMAUH9vMS1BAC9vob_vMRATHmBfv48R_ZAu7k39spBvUU5xX5ACwB-fv-Hu8JHQ\
   \DoJecN7eAzJuDuDhkTE_YT-dS7-gYaFCLg9fcO5RT-6h0WISJBAOtY5BkLsvoX4gThG\
   \TEEOPQQ-v_gA_sP9BYk_AsI_N8EGxUIHAny5A4J6k769_MB6-8Z5wb6BSkp8vn4FBQK\
   \9_XZ9-YUCP4AJA"}

8.1.2.3.  jws






















Prorock, et al.           Expires 23 April 2023                [Page 44]

Internet-Draft           post-quantum-signatures            October 2022


   eyJhbGciOiJGQUxDT041MTIifQ.OTA4NWQyYmVmNjkyODZhNmNiYjUxNjIzYzhmYTI1O\
   \DYyOTk0NWNkNTVjYTcwNWNjNGU2NjcwMDM5Njg5NGUwYw.9AQ6wQ1M_MmPTDw7hPx_Z\
   \905wyLaeoXIFfI_hQr97PwDG9uzKFKZTotDdde_4_zuBTc2u25bdkf9JCm2m6QVzYza\
   \O83MVOGzGLiqICdSm1WxOHP_7bT9w4fMGq2PcOzMaak9wNG6pFblUnciqruqaJcv9DX\
   \q00tZs6efS2d2LT3FSmkMzC7rSTypHF2bp3PsxJHox33Z3uVDTxxHTZt8hFW8DUJLBD\
   \Nt5p2IG2Kde50a2VIHhUnYnaSaZb9HHR2PQ4Myv5irbJfsoRjNJ5Mxe62sqGnKxOXjj\
   \q_BRfTtjKSp9V5ZGkccNjPTXIZZ9jCqGS-tzNoXzMDBYnmU4gqa11UFTfCOhVsSqeIl\
   \9NNVe6_8zZxaQUt5qE1cj76P4n-onBEkb_RTE7xuhJ3Re9lGW-dRRVOJAYXVJv_bkx2\
   \QrUOZNp97TajO0bODnETJwm7Mt1nzorVYfNBkbd5FkIPX872zJNJtyuTRNUcVCyT7mK\
   \MK7EQ1qA52yZR1HEnTg9OaffxQsTG1_3cjnM94_NG8IsvjwxKcTO0O626pvoZ2mnysr\
   \wYhZ0C8tMlPOUrMnSLDQcIpRGDMqV5YEltokXFdTdGrZ6Em4yXleIiZkFDzKPvDc8LO\
   \WpbBf_tcrrzuT3G_yhJFsTquL0z-bsjaKf45tjCKw5GhoOiSi1M6hDUsm7TLSjyyyxV\
   \1Iiakh2k67tN42MWBlpcdBrKavE_ZN1VZwpjnzNdBL0izesskTk7-UE3_hy6UyKbLeg\
   \BfdusKv83Er7lp_oVdYorMQVCNzl9GPVQdnd8SA17VpZgraUHu-aAcVKdlr4XaWLdO8\
   \FMPC1moVTny2SHKe-BK4xTPbdtpawprm1aYsWW4zaUhMdgZNtPQnGIy06bl8UUbJEJW\
   \O0olG2Uu3cnPfIYLgUXM_FYrUetHpp2G7NG3KrwBeumirL0D1YUnTEIsf2dRyMbBfGi\
   \9NFqziixaursfgXijDuq-q6PQqAv9h_TikSMbElHa9qi-a-VVbmsT0UisEldN6yk5OO\
   \tTFmsqcecBiVTdukZXR8yG8SJUDt23fIb0z_Idj5TnFLiRbYLjaWgNyz-aw_hxBNOMg\
   \cQ9ughpAMjIFNarTpPTLDv_n9JHUMJe_m1abZJy9tKFaxCIIExw3cvyaORIkN1a_r9S\
   \SIoVAjRkmATi06v10lxjy6jMlT--MN3J2RYGFuttORy5LG9WPR8fF1f768iVD40a80O\
   \QI7A_dd3bmFlMY5lpSW_dvW5pG4Vyc5kvvh0k59gYVoJJfJEjzpoZQUFtuzlFI3slVz\
   \a07WJo3SRopHMARrkOlwnLXD0e4iLJrx6XHav2bVT3vxqVTacIC4b461AUHQVhzcX3T\
   \uTzGTs6kHF4jrMFNDNbXOPVDvtoGriHtu-FNYVdOjSTHBcIhn0p-fzaAxKDIvVsSSim\
   \pXn9hJfdJTQ0_duWWXgtZaXibdpBikU3nk90puTUttVUJJuXSxK2TTpT-JIRwkcVpBo\
   \s37kK8myWo8Qo4b29hBs1RcClD1PjXfRvpEX7bfVuhaY9ZVu6cHmdRK_RKvwqfyMASX\
   \nMit_doSmbnBrpWelzdcZpyOg9s7xCIUVjZhCYegS5otA4ygmvxu69BBcem00aGGJ3h\
   \fnysq4Ep0uMzQgS6dafqdQFJwsPZmLGBocYPKgTHIRNWfZCzzrqNZ7-hYYhcNWp5AAA\
   \AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\
   \AAAAAAAAAAAAAZXlKaGJHY2lPaUpHUVV4RFQwNDFNVElpZlEuT1RBNE5XUXlZbVZtTm\
   \preU9EWmhObU5pWWpVeE5qSXpZemhtWVRJMU9EWXlPVGswTldOa05UVmpZVGN3TldOa\
   \k5HVTJOamN3TURNNU5qZzVOR1V3WXc

8.1.3.  HASH SPHINCS+-SHAKE-256s-robust

8.1.3.1.  publicKeyJwk

   {"kty":"HASH","alg":"SPHINCS+-SHAKE-256s-robust","x":"C_NSiMVMN6kpAv\
   \1O21izzVkl7cN0ls-tX3xL8VeIOHWzfwmMJ37LvTLVXZQMFyXFTilBcLjcbPNqRCMXi\
   \z_c1A"}

8.1.3.2.  privateKeyJwk

   {"kty":"HASH","alg":"SPHINCS+-SHAKE-256s-robust","x":"C_NSiMVMN6kpAv\
   \1O21izzVkl7cN0ls-tX3xL8VeIOHWzfwmMJ37LvTLVXZQMFyXFTilBcLjcbPNqRCMXi\
   \z_c1A","d":"-gEaHimlK26FRDpf33I6BKsfT3muN8xdOyonuYSgHtEoDxDBsTe30nU\
   \O8OWZrfwJxvKyVxo6HCThjbMJX9LqSQvzUojFTDepKQL9TttYs81ZJe3DdJbPrV98S_\
   \FXiDh1s38JjCd-y70y1V2UDBclxU4pQXC43GzzakQjF4s_3NQ"}




Prorock, et al.           Expires 23 April 2023                [Page 45]

Internet-Draft           post-quantum-signatures            October 2022


8.1.3.3.  jws

   eyJhbGciOiJTUEhJTkNTKy1TSEFLRS0yNTZzLXJvYnVzdCJ9.OTA4NWQyYmVmNjkyODZ\
   \hNmNiYjUxNjIzYzhmYTI1ODYyOTk0NWNkNTVjYTcwNWNjNGU2NjcwMDM5Njg5NGUwYw\
   \.YHQAElZyZybZFn_t59KRVgl0AjA5g-Jp10exC8JGFsv8kMeyWoroy-T5ANx2lkE-cz\
   \jnnGMZdyODF_-ykpLqGisuXJwaHjZtelsN9-XwzAHp7wUR7GMw3Y0YLlNWfRSSz7cq6\
   \Vx9IfzmVgfc3LqG5OKJZQ0LIjliQGEoKiIm4dDZDurJgN7XJACWBFTd0Ashktv5IC_n\
   \JE8DGqDOoPuqYVciWmnD9ljFZKVniEM1PcFAsuQZ66OfPsEF-0ZXSMvWyHwcznw50o6\
   \RPQXlbwF0IYyOrhBitNtoKDZ3f-hJ7NleYVLbuztFxw1ewf7iEA1oxRQq6fiE2J7YWf\
   \qQO67KdeH2f5jzsiwrKUqodc43emKyTlW6_ckqaYfrtSp1JN6JnoE5vbKFeGD08fCW9\
   \02MvGXSJKHwj8dRi8D4-JuGwJ6u04XGj3y5sBc0VnwMAFJ7nSemX1uRzr1teFp_WhRy\
   \z2u6xpMhNJudKi0aVgE2Yk3U7ae3yabwQqi5euxLCbHVYHrr5XfJHgRTuiZcHAxERMf\
   \cpy6lEfHHtp6wQJWJz56mtovuhO8a-H7RWjAUnIBy-I7lokJyHbFAisR730qsVDgsEF\
   \Qv6CyFEcB3zvzb0C2uPXzlKOnc8tu1hSBt4fGV1k9DOJ8Fy6YFZM780O8i0bSWdel4-\
   \F4lV7ZWfYhPSfiCYI1nasM6ghQj1DhWRY1izr9NHcNxS2aQmQ4BfDtfooYIsvRidfKz\
   \V8QG3p7aCoLUexS8qiQfZ86U3ROjgStSH1FZlgQ67Dj1pUifCTlqfdoxaosE8tkYD8t\
   \IO-zYwZ2uGvWbqHevCbV2GGwJUmnjL5zkMh8ilNbDGaK2ZJ4s-3cu0Q-NY6e9ot-IHT\
   \1whbSzWNUpvEVNd4780rRKcGRtydP-vJ8yOCqvSecWxvnJH02ib9JzymIEtUF0mkdpn\
   \Wk8KzUpX79C0snMvj0KeKp3T6aK7xZK8pxbHoqFzXPD_Jl8ffUDVbQ-QQOT1aMqfQyM\
   \P7vn2xLdYCgBKAch8AY_UxZR1QnnfWXV70L4GenM-xW8fo6kKrieqhb7dnId4jZyjot\
   \KNaEppowLnG-nw99EH4zrR5MLOYavvQwxi2XOOfuPeq_jjZC0IgpliRIVoysR851W80\
   \olsvCOFY-6dWrvSQ5bPttFnfXTDkjmOpZPDUt72F2JCjb8f_Cp15s7tFlQ0RCDYmBLX\
   \UvcqOmHrbx9vqMackDoc00FOQXAkfmDSQM3DeV7FRHASBS8tHILgVGtnY8t20ZaBJ98\
   \O1WVOd7bHpz0bFX9Tmx5tBqb6Vi15J-KfJtvG2iL8D8Cg5EkfaoVwA_0-tNUdKIvMuA\
   \EPC3vdkXNHwWQ_4GOf0fSmNzfda2mLbjbMRFlKyOZvNw9OC11SP-fpo_m3pD70qtyUg\
   \GtIs4CuQyV9-PaVelivFtuozvYgloDISDcB57oGtPr4CenMT5LZT4XpwnlFgvv0qi2-\
   \-tbxiOOrvBicACQAVZ0m-H5k7mz2fKSO7_CNCKOxD3tY75Av1Mg62qdaf_BNT3ajkbH\
   \jkOJx53Ua9NmX3H8AFLYdvUTraQ3NtXQ016jCTniEaPwDQingrJk7F-ITKuPD0tMGSJ\
   \AZDSssmokG_BrcMQ78cxv9jB1k_vejN298uE9blH9fs7Sjssmppt3htBQQ3nQ2KVHdz\
   \EmMcAh93qS909BbCVuzbm1idgzf2rQoET9I2-1840m23fP8wD8WlBTyIK0dtDM50Pth\
   \rNX4CVUZBX2xTsAoweCMcQEbJF8JRpdqpPB0VdWWzOnACUStrwRBf1DhgveQ9jQuHYN\
   \YlnvtPBITqVCFtEFyHhI3y3a53IKfY14GVw2fheWTs92fXHzCleQ4BPxL1DnCY4NFIx\
   \uSai9Gbs_0ozowx-Ye2CgbEq8ZSvE9xR6wntSP5ls_AUXBPlVNTxYGVT9QixqqpWLPg\
   \RQMtBnuUkgbLYMHxCzNoPEv6qhrzRHq91VVHCgJG7AyRaLrZXPruoD7inByh1s1Q3n2\
   \Rj30WKTKfohX4hX2LDOvwIeVHHA7Kwg1qT0-iC-CKGZ5TcWSP3kkdXN9pTMseD8-qEN\
   \XBpb7KQsaFlxvE1Hx7KwAEJIojkvLeoIQJuYWXrtsuN05LA_iNJgA36T1siC8qankLe\
   \EZpojLyYT3yeu1A0zjZlZ3-qE9kdrPqxcDpcpO5voJgtf-SM0bkqZT-H7o6izX1ayEs\
   \LGzMNJdKZUKP18aoD8u9SpaXTZS1-feXln7ibWQdt5khqCWSpszryb8KtJ4S1vhEnU7\
   \cYbx6X3Z6KkAH7_XTpD5jfei5_BvciIimy5cBcsp8mxO50miNto8031ODd5d5FoBr5r\
   \xt5_6vICoC-Pu42WPIQCHx0WZljKu-6VcV-BIIA79BOwK4RoFNRRu7J0kY_YbO3WNdr\
   \kJzj2U0UFZZLZ1FtfNMe6P3A8MlLOnYcQtHD7da03ieM1jmA0wgB_GcngOnk93fYj2Z\
   \NT-5lllPEYke0ZDfiK205nuIbI276RlC_PrnmxvQrb1MH_f7rDXIEV3nZ31w7M8V-P2\
   \zATU-NeUnQKdiNBoM5J7_zJWoief6--E1DBUSQqCc8qIDy1QMKqm7frexH5hzS9pwK7\
   \YOi8LkRGDI_sVpbbZPDR4tv7xV5VZySndXbhCYzCyYsRY9N1IUvp4iXJqhELzpRw1GB\
   \CrId4AReCqDkyoV7Byu7i86l76m-1a3YR7clsFQpTEkWxMeUdDZjCUdi_GxQfj_2w7v\
   \HYzdIwZdxK0OxVXd9x8KlZepTXeoDqqhN0DDfEL2mbAx2l9Hi2_CHNGRKf7560Sd_zt\
   \q7k239-cfpSwHBEYPKwJspntVvYuXxarGWc4efY1QPFvYHJtolc9DlkPQ3rP7jHtpJE\
   \nHPJQZ2dhP2flG6NPl4cCxBzJ5aXY6a-tEbjN1sCpKexLP5LssLJ_NPUPKHPmClqlbA\



Prorock, et al.           Expires 23 April 2023                [Page 46]

Internet-Draft           post-quantum-signatures            October 2022


   \SKlbirgVrBZ8ZhqNKeJYCgjnm8ePNtXKxcSfNuF9qinuLpiA1JymXi482eahnBWZETW\
   \HIHdTEc6t2Tx78y6xhgjo-EhgFyZFAN56fnZNSA3LMLtd7hDmB39nR7H8pfE0MQqpKM\
   \ly5HYHjx1UgHvwOUGfBt5QVWIQoh-NE_7tdT9DLvEcibRxqQMA_b80YYrSQqtrxUf7s\
   \kmtgDMQKbUCaTWHlZPJweG2tGHJHlSxLSy2QR0ToNydni2g9ho3GcyocB2ECFOCne2Z\
   \uIDiWxYuRQH-1VefZq9iQ4Piq8q-vyyTubb8ggASddroyAePF9R4fzRGtianrrQ8NR3\
   \3lIjC7QcfNhjCi0XXjvqP07xUiu8MklJDfhbjTA2ZXzKu1PkykNUBxMDtwMXt5tfYH-\
   \lrNsbvhOgFh2S8eyzd82yAb-oFYa2bZFuVyIVFkB8xIa1huMCgQDDRBk8HjGm8mfKtc\
   \8cwh5dr9QYM6_z-id4rddRebN70GKwxuFqQoLSsNCjRos-xd-Es-uP-pJG21XxBVaB5\
   \2IQFly587eszxddDL-k3mnZ6tDybDI-B0_kupXZB04N4uEHlWe-3MKv833VGSbsDZoS\
   \6tOV9rrKST__MoUBmDI0AiP1pRzKGUIeMpeiG6td1KbaRCcJS-_nhjrgGX9OrF-ADvN\
   \EUl-_gkOt0UlkcEcPED8BKFH2ZvTzKzKYJjYdu5RS72ihlJE3TJjy1bg8SMy5CbBo5y\
   \DLF-QZ1vaZpbps3QlbF_Ch-6oHBa0-wuUUVr6Z4SUERLVg3pqVjI5xXNY26LYWViKcf\
   \93TU0EAMjWkaVJFsWiPx8NVDBr5z-sic08YP1188sJD8RMBB8AR5ztHOl3sEutrTQT0\
   \ifa1ni1hrn58wsmy75diavaGlhr6Illvw2qqUTLtLNDxh7Ocwxzztw1_NG5CdpHDyie\
   \4l9aAp-DlK1NxzYRGh3jwpF46YVEegsTJsqRr2gkZItDSSowbG6XC6S9vcusS_mlKqP\
   \UXmmSnkKx7O4vztv_hxOOIMDYLj3UQ141QPtBqktZbY8PeUhJFhLwYgET5opR7XEhpb\
   \s32al1Ndnf1cUvgsGitG7CCfBzpgnokj1X2J7rnNZItBrZFLL-VC3dU0QaEfi4Njv4G\
   \aouAo_QpahzNX2JlueYpP1Jk3alb3nPOGQSeeBfC6hxf9V9ycMC8uTAc7ocWlXcQOOF\
   \igMK_3nVF3hxpoqggsFjHeHbSdWufdXyTWhzzHZSdgAi_HegEEjX9z2xpjoK6wodCY-\
   \-jZolJtY4v-8-Wz_Da8-KRsJZ9rm8PI_uE5f25QOsilThZxYotTDK0YiTMVbGOF9iu6\
   \nJmFPc0nneYcxlEKdIiQjncrkS5biy8JbOi7jzTU1BeHxEebpTYYHhg_x3Uo6JxYywP\
   \LAlrSHQAQBu5jl_X1utf-J23FhuObJ_qsVLX_WvpIHCC-BkUZXqFVslzRoViCW9ieM1\
   \QNVv51KqCP52fbNvqt01KUQq40l7dQY9ra-M9l-5ZtW9tGbKx7ABEHu0VSDWK0GVUx1\
   \Cf68EZxo7enX4cGVryI4F6XR02RID5qrKYFGC8GEi166fGYJ_5WtzP4x3sYOAfURcyf\
   \N1AXMCwelARC0_PRjwCGi48WDCVD4vv9L89bmShz16kAFQndX23eAZFfuI2xeE3sLfZ\
   \mlSOGbCaeWKY-TUVydW7WA0QS_ZmovMxIgjGYMul07lzVPEdtduONei6chmMKVg19ih\
   \44pzfRFInVw97IaegYTCaOIZZnrm0xacfOdP6CpnzvrIQUlL9lQpk3en9y9C7PdbOr7\
   \5IKN99dRgQu4wLtSquAsfPs2hm3owhF9J4y1xxjrtbss0-XMV9IV4LDQ_Mcn5mbMuDX\
   \iM_537rnsjZyTxxBLW7CQkF4SDzcEewhLIlPoDrI0cLyNjU0I9gu7imXWqHVMjwpaz5\
   \VzATGxR_t0lnIkoMtpPJpO043ySpzRd2z__SFa7K35L8j3TnQImZzwq85Q8b9NJcwu4\
   \ZeVbcUIdBaQ0ZCERdfOhPARSjY1Ksh4hjDL2MvFRfriA6owP4pNNl4vTNDbk009Cx1r\
   \b5nAh-ZiD5ciUO0Bv2o_kFT4v32QZATCv3uR24W4G9IMYOb4gy9ebctix4zgmMM2WNX\
   \tKAllSlBHFh_VpSh85X1dOuiowXVILy5rdopqr4UZ9UUHO_BSAkf5rshuxUUYJoyebl\
   \ZOFMAWMaO_vtC12ipLetGIqBqV8I6TxM6u-Z3fKLqFWT-kN1lnnG_0ZMcuEyG44kHoG\
   \oZy6-9S3lu7lPxNBYIJ0ZW_Gs6uJj2pIDBJHNxoibsHXLGGdmHOPrgmiMP9ZTXav6P9\
   \woz_Xzkah4nJ7lqF_0vxGji4-u84wW0NpAIV9E8aOuoM6kCYFbPZJgUk4SQetVAdrYV\
   \IrDGPxyz0m7SEQy7hqLLzSHCciO2uHlK8nKrfEIVu4ksTyKCNxYUR3E762bjfiJe2xv\
   \a7S-5KQAycPIAqIEmzzkVlqyE0VDX__T84oPveatwSOoeD6bbMhn3nre-qtrznKh39D\
   \_Y5u7KZ2RZZKkHsNII8etDBQlktETHJugNXykdYVd6JmlTzBWfXjFBL2Oty-S5I_a8R\
   \6Auanp60QmcXoguPNjGbHQnJfeCe0V4c4nhe0nED3Kv3LydR0VfpigcOz8-HIL_Vmft\
   \26KbqMwR85Torez0wlI8Mq1IF7ybSoKnjnpz8Mn6XTntqM-4GMxcfgoBVliMd5WmmZF\
   \HEYgBdbddX2jtyglRwlZZdI7lc6URL9obvEgjMjEWmCXlHWxg0diRehr0vDvawuRyaj\
   \TkXpvU7HD4fZfqNYy-JbmdEIGVpH5p5gbefzRLrZ0ljCd0enT6FM248h4X9MWO1XwFB\
   \pL9yJXVaiDtI-lWmT544SrD2mSzqc_XumTrFkB5c95SpYwDba6TFpLehrtGcliZYt2t\
   \0CShjHPm0PYK4z6NUiNETHQ2LIjkHTfCcNKIf5HobmhcMk7PD8Ed_Lxv9AllTPnOyr1\
   \UHm0KFAuRz58tVhlcgmHMnpZ8V8AgEdDQ8f8ml4FzPzvseYoYHByeBCVGVYX_DwZOyT\
   \_ANH9iqebJeWBjowSf0CgSZunvK_o4qOJdg70cZ6DbyKUFfhcRaS7M10ekkZpoxRLRY\
   \EfwZ8U9OXx68Vhw9H9IPSJ1D4cp5Gxu-Hk9l23XTMsoYeGfUAy920mo3Zfw3DsxwYvS\



Prorock, et al.           Expires 23 April 2023                [Page 47]

Internet-Draft           post-quantum-signatures            October 2022


   \KLMXKyqYF6yFqd60tG3OIuJvYbzD1ccQl7n2cO3AlDnN8PpJTWuBaj72dDrff2ovrKF\
   \mJrYd7L2a4ikx9f6WY1oxvg7kJt-8SQ77oqzwJgCLT1-kiRyhBEomAantO-opEtpKJU\
   \eTFnQJD785M7j0P74-5kpuIBhcQ0xseXLDgSjW5XjoAs92CHE_C0n1oXtqEd6lpQuqI\
   \mhEyH47EBesknBmMQFe1O1Y808HlA81orOQS5qeJUtMxbo577joC5iHOKBZyAzJaYtG\
   \bUNc7zd7L8ZZ5Aqa_AtaRYRLyb6yQCg3QT7QsPvjg7jpyAIwdxymChBsrqArA-zYs6t\
   \EtNBMMuJsimhTmxZH-xNfyn78FjGq73d55fCPFyPo7ImSXn0i0lTSahJIk_zjczHgUV\
   \bEwm_xEG1HdEMES5C9GnetuhhyW--pRyKeluIkSVtbbGnzUEUHjaLnV5B9PNbkcqP--\
   \4UhvZJGy-nSHcz4ke-bQ3ElvkHdvSWYMWlxhGgfAmUTMHqfPFuY8tylkzCTix9_28H8\
   \tkVGQjO0ag4ytYnD8eQ5b9lPwB55E9VlnTIbAOW1J1rixK9szX1ybM-lHVWQiraVN5F\
   \Q-UkxW9Wdgx-U0Ms6FXK2J0tZFE7RdJUQBfni1fkgkj7RUAs5gELsCgoykXUyGHt75A\
   \R2JSGSNhWBfm7PtrqO5zk7rNCOIjAyUgRnk0HA32satspJZb1XAagRvI2-fhWEiAmX_\
   \DM31wRTmF8rzVidudr55IjDQxUGWOkx8Hm2jWdkZiLCeYUaTLY7aFCL05z8EZj76y4r\
   \oi2tjmfoI2wPkXoSdFCTIpadCyNtR6uzHDGNy5uOGOHJIsyT4fM9RiPs6qOGVnod-r8\
   \Gm49IP7tqjBVbHPLLJ30oFT1XM_LvW6gKYzoh1WNuguO9Wwf3hFlFYcn3qotB8tCe4G\
   \7aPQH9bnmrGrkTQKA36wvZVcNicLba2j79iDR-nwVoahnJSkeoUsARfTYIYWVtU__SM\
   \E4mx5z75rJIglgYnxZWrLrwKfzD8piDmtHkV45cI59HJv7b6PfTDgdlUAp-sAEv7hEQ\
   \f-u92rnVHtNuvYuNovqGqQ0XERuky4dWNLGbGhjXwKtyDVSuvbdnMjKaUaZZlZYBTY_\
   \dgM_UgvWTWV8Fo7OIZVLAXKId3RNVFFcep78JpopACIoyzxPQSxwPYCsRR1GX7J5NVl\
   \nxzTaEIa2E8m3c00Ky1sTyIFVsuttwepiqm3l3pTm8K76IY152ugc5oF4Gf4Ib51k-m\
   \GgnBV2OvJPV8ZmXD_OshtjWofFrwFiiOPCWfvTwuzD6az0iiZFIOGsT5lWIQz9eIJJg\
   \3eDZ6rJmV6SPT2mH-F2900y6v4MTpCPeItCEYMQ4LVXZ0lGSh9OcFubbhPDMZJ1Auey\
   \hcD5CT16Xok-QuDoepyWMJILo2I_cTNdm6E9KqNXSKIBxydrQqkEYTB2MPr1UB9HhSA\
   \ebkkJFxKKH1tom7OpSBgCRSU0GXHHOUySyElyFeaXSz9JJtHHRXlBh5S39b5JV5YClW\
   \YO-L9CqWNa5h-dvZ0wRGcLcRjub6O9guAbo4aUrh3Rtpy6CeB0qPFiqk05giWwTKM1r\
   \wFAH6KhEIb6NNbYeTvfIIeVZ9CfMTE6Sx-dKC4yvehO2Q1S2FC_rZW8yW7ohcc9FDg2\
   \0bKK8zby-JrxO7NSej6LjEHwPQkkdVSGkdLD0Rwr6hC1bKEu_13VGVJUgiKe489tk4v\
   \V_2S6dA5vFhTv9iKnyOyD7lhim0lyVCYnRry_rfLQj9qvvPQP8EasXK5ljK-Qj1BJj_\
   \D8BBgVecLiYnovPYhe9EZ9IG17X6qOVeGcRcXDT9L7DHP_nwE5sDvHNorvHjyY13AK3\
   \yv86T1DNr9pY7GybmvgaG5bYxSTOO0EemkkNUlVLX8rTTDZL7Ciml6IrGZO8wioccPH\
   \VfvGoi07bIeA5i1bodamBiHAlWTSX4gEZQ5DX5uIAkmYa5ryt0ObkLWHYkeEaEQqv3L\
   \H5TMSRZs7dJHD0Sr9HSrX-Kk4dOKNOe7WKsfepjkERFMEf6ndAdwCtcW9HWsPVplnW4\
   \JTUNhw1FuzBuHCQ44YHzRW-UYLtK7gE0vYmrNjvrNfze2zWKzi7Dpt_EojM2tYZ0Otb\
   \_iTEn8kdAxGXhuguG12OwTy1JwPBF0tv9u-EqP93OVFmiFi5LaXX-KiJACoffdrfSTl\
   \JbS0-xZJeXxUuKufNEUQebRlLOE5osYgcPvwhLYFn9RFqR-2xre4NvQfbBLI8cc3G86\
   \8Taf7NU83fXAgQg52z4qVS1VjldTZ0y3aa6RiFqu3cVNqKuq29XCHdfjFfD2JbT8WLo\
   \Unp2VScOr0ERmnVylBRXDtcsQr4POFLA3u3iCmMCFKRQv1s5i7EZ214GpqeHZcfu-nq\
   \ODcEeOtHQHdN1ZWRXoM0ru7LukFgy24iDX0vG1OyBAPbgzlAIbQpju3uaXkUTGjt7Nm\
   \WSXiGhQX49Gaa8-ySWm7q75Dvz4c_OnZcaLFW3Qtaky75qS7feF1G6RB-lyH2MWvlJd\
   \UI-3q7WVagdIO4c-HzwjxVXI_SmVcOw_Pk8paUDSnWXvtMrXYDf5fPL2xNt2OVlXNhM\
   \TuGH8z2sqt3Eij4VDQtHlwhb01OwI-yN6D45rUvTaVBoSLS-tAwFOenPkmY9-s_Kbke\
   \p5s3lSP-D-QaUc7tInceXgusnAEz0ysJTDVmRyoqc8BvN8bBk-MjQ3ETSWfJ3R_UA9g\
   \_d8CKpVG3m_Vuz0A1lucYIfC6KNsCu9ATt69TZHE5VCE_GFLPiZiQGAFTroVAYSZ-BI\
   \Rd9EI-oj9jmWeoS_4LLe39h8Fb2Vd8YgGNfjVgSnWd_PzQnwFYgoRf8lYbvb278y7le\
   \OY-Piz8_s4BKZt4eu21MRrFpcBgyy8m_1_AAv7ShqeY6Yu7HIonFzSRWJGUAiQ2shy4\
   \Lge6N-SZr2bOU9zjnpqxM4UjqciylTLy1_xt9Dm5gLBICL4QdjbwhWktC4VSOvvNHFK\
   \uroTRpyQKosoaN5NY80nMR5quSyfX522djGWnY-xBy274QWc57WoXUIwOYQVmhOd03v\
   \-alAJc1pgskd3kj1EF2xlW3j3pMwTd5Z24bBcqossJ-SGmtJEFfLgTIH-rPZD9qqTqh\
   \1nSeOuS2cpBvNfGMmCTIn2HOwIdyyOAzXeWu4YzHdkpT2fruOMpJnQdriwmB_B_PgWW\



Prorock, et al.           Expires 23 April 2023                [Page 48]

Internet-Draft           post-quantum-signatures            October 2022


   \JThK1DyknoX4OeMBAv1hRvxlC1zGwkK_WyJfWrgNtFNswL2-_VMWMe_LnZGLLn4lY-v\
   \J4CMzGA5sWuDrjEljv2lrbXQC0rocov_kXG4KzaS-OB_GddA5woNPbRVkpo0ste0d1J\
   \RlhU4V-DOokb5E5kKDRARy0VCYhKmxDeURqu7POGTwQchf05aQFNiGa_9d8d1pJGnUc\
   \KvALh_QjoCa3rU8w0PnQDCXoDtGDGb79TCVjavr4A0r640fol13xUJZuwTykpffRWPd\
   \61dsiYs_HLs3sZmoESw3kE5jrnvJ-TGcXnwf0-QouTNIjoGhwB2_cyV6I2HAjxpFpzf\
   \JY9LiBP-svHzQQxmz1Cba5SWxAf0g4mVLTkbeMBzIltc-o7fLvQ5vbcJNTBoPVOBi9q\
   \_W8RY7PFJF9ovF9mJxy_Ya2UPRG2kNl71yDR37RcDJMvdgXkNcXd8FyG46ygqvg7xYH\
   \dJbdrIITbBHl_JwQmooYTxULKTORg1my2gFO-5Ix3MUYRRsrcn1Dj8kVdEZwYc0nSK2\
   \TG5_xCTo8IPwPlMpUOplPps9azE9BFuVz_2lf8ckVTOc-AfFSdJfBrhITSVEhRMwqIH\
   \CR_yr6vxfomoyYVKFbilaNLEkVL9ckAmU6WnnpksgPxUu17ifNO7POY4UYrjDAaunxb\
   \Nutr0H9oBgJbATZ-PYVlHNYGSSByflN2gQ4zERMXDwSdPd9JGw3kB7QidWWRFa-tMjX\
   \LXye30WEpoTeV1cGDaBnB1wzq7uFfq5V19ajR8acLMoGepsXlm4HaDN2AE5U2mbQwwI\
   \npav8wb26RdPoPt2Bby4kWrAzOKZUONDbQeBNmGQkItvWkSNbKSgFEqcwEgHKbDzLZG\
   \UNFsKKZfW3HhP_oiAZCYTQ0QYBuL_6QeGZYvzmDQPDVSf-kKGRxt2HELcfyi8FoLwgE\
   \LlMCLaGB8dDovm5zbo8Y42UMP_l-ZmmgaXVNwp-tzEJRkzwYQLwV2mvuKBJHCgueLoV\
   \GnQKoYH6JYqcphBnQgYKyfzIRxkx49rnJjKVrRoHVTmKyMjGRvkPnOkWeO_WLrLP0jy\
   \HpnyUE2X4Ib8jqxyMnPxKb_X0t3BGNz-NRwdpqhN0m9MKa4lOU6UifxkRXTkhWWXH2j\
   \TWAtqihHh8GtcB8njXYZ1fRNv5YRbhMnf71bF7UHMKlBHaX4fhEet_3cLL3uLV4tSrd\
   \HVZY7VXUShmYvkX6P37MNVzCo93tBIpfEGP1z9jzY_F5_-SoFKFY8VIxnsc2_k5JywS\
   \Z7ZdYoJPOZXeE8T51-ySE4Cfv5DWNu1czO9ft9HQnRZhLMobhTVqAa_V8XErVItVVhw\
   \zR7EnK8bR3o6S7EyV5e2LSQICdMtu3fBKhijAcCU6-BeS4SlzBFKOnOY7cqRk6WvQsr\
   \3ZkoHom1zyNeTZ2u5Zj7xTKoT458g6uajKDj0pnpboegUhMFazddWQiLhEGDgt1UfWN\
   \vV1fJp-uCGtS38AIXhOx9NCf7jDzrVpF4LaZ1DxDy64ktZR7OSfkhVuonXswBzsC4e-\
   \u4ObOp63pvdgnEmaUMuS15Yyrm3s8iQvl3bFXHFb7TxwbVSrRhT9EnwmcP88x7hULPG\
   \DGrqiFvzwNHWxp7SVh_WsjhqCbaBRA0LKKWTd0Rc8xsEfjZFIHgsyIei6LS-fQL6Fmr\
   \uzZ8K75VKjSkv6Q9hMfQHX-TDXQdIg67MuE2Ae7fwVOVVgNy1UHWMuESbIj6XeXDUGs\
   \Gj419_7L3uoUtMEKodXxhuidWxYpDq10ymQxRDxbCKE3CAVNPt_n0AwTXAtFaRQhHjd\
   \cgKPUsS0MXUwb3SMC6glz5I4MkYS1sGupNLed7j7_nrv0gcvz74z6O11HGxxNqRz6Ts\
   \TULxyDex9cUg8mc1uH6dsml1kamYRiCBqN45N05UgnopgmCq3TM7Mc8TQasheAwiTyG\
   \lqmwn6-Dz-soMJBQiz3VitofkOQHw9PD4Z9n2krHygIvxx0-s9x0glCmjmX6r2f0ZOg\
   \57Gh5GMR_DlZAzpaENi5CqJQQEL4kYomn1YEaiHV0iqq9j6n4FG_Z3KPRMLfHfWu7w7\
   \zdFTAto2OUBEtVSkng6lwCOiUgmqucVoOKRvx3SaqAJAesHXLbYuORHdTePKDtNLXci\
   \CZn-rdqPgN6OQiHX_UjakCSieFu_2LfGZXfiuu63UH_gIvTlGNdtDwf3q62QGCJlXxA\
   \R4ZdgeJuz9hHlg-PtgHj0aknC3QnkoYB4UOikmVaDoYMWXWI2ajrXWt_45YDGHRvwNQ\
   \Erroyd-wwz-yX7zXU6DsEVDiAEutRbgjgLN-4CHiHv3XOnKBe0_Q7CuuQztW8PAblmf\
   \D482lGgXFQvQ6sV29v47me4S2MU-D_Wcd3eMCRQNi_hRrJQT8F9xupJ6plYhhFfIPUD\
   \Mkgqvg0ekO_hZ-M6yeVXZfSfc9micnMnkyBRViA7RpwM0O_z_L6yBzAv5xlRm3CXE8i\
   \1pRx3ec55Ts8_EPO-38WZyIudcLuQtY1FwJX7d67zSvoN9H0H4R3c1mra86wn0ujWgI\
   \NXga_kXWn5vKP-WgGrBoviRE2ZaScSvQI_3EoxGNLraY3Z2w9w84uP2jOe-WGzxIT3A\
   \7s-eLIq18p0fspiMsl-GDiBCQV1a5MDNV2en1EPImbCS8luUmvV9pXDLMFRTpH1ClLe\
   \Lx7aJr0SLJJC5FeO8oEHnJC-J_NPYU8aT0TYfvFtV7e2JZXAm_BoBLEpWn7MIGK7HrD\
   \6PgaS3xkIbToJwvpX2tSfW-yXLyaepdKptcCd-ZExlqPaY9fCJP_BKvHDa_CTP_zrQz\
   \PQOlN7lZKPegro39XpWuLyk_DxgfCVeaWAJ_Ni6bggBWLMuVhYfZqXFcYKbLorjG1Fu\
   \nwxpZqnAyjF3sqfTziHIvGY0V7SJycjBMYLetR9eenJS_GVx3g_gUX1uXfghDG2gHm3\
   \mClr-SIOAsUBxoiUpWsHiVny9vdULRJBLAHF5F_ITUlWtuYWm6YMhrQ2SDE5lWYbdOu\
   \tg7lUGU9hN7iPTSjHNqItc182aL7YIxl0UfQTq8HyETMvfV2LzbO2UpWErVNEqkSxGf\
   \OAMsTt2OF05O7k1Pfko_5DkjlRmYxh8n_Vl81iiR0XXPbtpvEjssJOu-gD-OnDSCsfO\
   \dwwjoEtaFB07Woz-33ek6RPRIRfim8hErzhbLVcgv9gN6Yk8gMUraMFZapciWAdNinf\



Prorock, et al.           Expires 23 April 2023                [Page 49]

Internet-Draft           post-quantum-signatures            October 2022


   \xyrpFlm-LI2WEbqzyd2ObUnRSyTV_ijxZvU3216spIzbElzwr5RVE3UEY8s91UlAsjG\
   \lZ_75AWRWMaZ5mo_phJEZkK31ICUJGQABPgMU0eWrs-5FWucJh6AzRe4mUqmXo8VkNE\
   \f1hAXDaIFdYlbbprhkdZBUN4adMl_OzMtk0mDmqO8j8AckYecZ6Io7TuyvRWDf8iMGc\
   \H9-YxeBAqBv4cvhhiUvTsaMYlOOY0_wzj38TlSnTRAll1BFeP9D0gyi41X4L7GgScJI\
   \kGsCOt2Nme4R_hXBIruV7XNCG0ShAIows-mkuhntGvqirH4IiCsKXpYIu8nA1eo0YRG\
   \SZVjAMMsZHY95ba6KyJImdiTlEQYnmlwErJp9KncBBhMs7ue7SC_hyqx5jY1ezwAS4_\
   \rCFM2IkHyoagwQIiGATc0AIHvMpQlbbDGuwqW2xTR11jQXLcM07oO2hLQUgmJuT3pD4\
   \J4p9tLuBnmBNkKFLnRYV0PztbKM_GHVUVPFPC4I3qr9YpHm8vZocFVkeO6ZBEuz568z\
   \sGqAiNiVu7gTR3B8o_JBi80kSJRVGA9tbJ8ULEtGR31mKjhyfhK1sca__7Hep-6sR2v\
   \prg5cIl3xCooRa_dp--HW3KyqtqVrR4KY4LGrfP0lu1uQpzqnn2I0nFQS1iL6pI5od1\
   \_mShLeX91JA8rTkFUKDIC4QnTzlieCqaA34rTcfqx0kFVyV5kCOBcOXu4GxbIcuyDv4\
   \qsi3FSmFQRSxjk2Xt8sevZx3onBSXUPCWzp-cLg5TBvW38ZxnEon3oKY1nnWM2-eR_i\
   \e80BnBUOi5GIWHw_scGJjgVeM6lxwWS8PCR7l02YzRioJZuSONusI_IzWg4SjiOLajw\
   \mzdjYSqeAiYJKO-BDUMt_bYggHPHNyHsYzRjvouaizrGLxMwamIHkPvjgDzhJ0UF0wL\
   \aAXo9ujZtk0GI9mIAOy-squRxiPc7vuoC8vJoXisKVE6d1D9fl5CW2914DxOqoymiwZ\
   \vCCg2pBe4flJAiWLAmG5h-Q6lFUc13rMdJYL679t3OmSoCQ1Xky7cIXb1x26jSXOp4p\
   \8_yTmiBru13PYPb0n7_YJ3O3fQ63I8C4tDwRsSz_p9LcmGFemzYS9qsXA-H5YnpsN9R\
   \boq_ubxuOtayWrr3aN0RCu0cexQva781Ga-65w9pMxak3mfjrFWI33zJeYH68qg-e-g\
   \YZJWvvVYmNHJ_xGOKQR4XIa3l5WI2GAilSZ1Fla5jaPcv2LUFOXYKl5In-jWC3YgY5M\
   \VDO_qZ26urBZcw5btBWWTS1fFX-lP3Ai6Dx_vdo5x0cUcetsV16E7_yQFIJ8vpt15ls\
   \d0nCI1XT7kZwtYgNvS7pADPs5xMYtM_42hrucLdMfnJHlKY3DlS0jmbIFVslmgjAuws\
   \OrCG1ziMkC3kOvvljgWrQWDl5jFAjQ1lX8k7l5hejynao3GeVxnne-ERVskNoIXDnEw\
   \C7xCmPcaF-f1hCnXjKTTol4o1SuN-HZdIS47zgZr2OyzyiRQVMG0pQqLPdqBLmuAFuY\
   \hlr8mqrvgOQ8Ty25zikECnlNUMPCzCJ7O8hgna6SN4bzxq6IyB9l6ToUhhLQt79DDUa\
   \htDwZO4CqkLnamMatp4Xlc6uLx2DCMV0__zYnfsg1Sc8TLLGBLa1OgGwQwXzZMrQn5Y\
   \CzB5Q0aiJBCucHXy3E2tu8Df0bjPv3--dUM1PcPDEEyXmA63I6j_Ib96HrYiKYXBAuv\
   \AL5yO6wrvnYHE4K5TrMp4P4p7i6pVZpGsbHfp69BnQ99zEkX695RhUqh7d3CT-DmJ89\
   \JfYus_yBt70rEYXs_1fekY3LZjXY6ElPtqLMCpJhRtMiAEdkP6HzlbYTvS7EiRvoEjr\
   \Uyh-Zv1D7lM9sWOJUYH-SCrHng4TNSCiYAlcJ-h-liZ6eLJhDHGZuX5ErVeiL5YoreM\
   \rWvnVXVtif7DaGxAVsMSlDFMppU69LPKArm9y5xaeNBAjmd3Hky0i77qgXlLvVUL-L4\
   \fVK9dwXCKAocAj9rIx3k5yJCvoVtdDWTfziip1JWYO6FzVwuu61KfpzJnlIPHtcb4He\
   \-rYCSKncs0_-vrQXXaWAHqW4Puswunvm5ZZJqjB21IRyrMXKy3t99If3htJm41eZ3xF\
   \-dl1NUoiL3hZU_u8qf67IUSsu12MRg4BLQTFpYkFrR85hnPW3gx7K5-WdiusiTzdMYZ\
   \oCMcfhYVZDaGu5aZFvNqNsNe5fY6HuxfY33Q8nJBiIueZzWwCSJpay-yuzM85AWmhsY\
   \_1KBZ2rtI4Y_DpIj7mfT2i2w2xiD6Lzx0OP3mC8R2amjDSUNqYVY_NJOkir73PfTTf3\
   \kDg8Ip7i2KsuiZj7KoYJxhloxC1Bc-Bj8DOBUi1K_JDdvr5KvPs_y8hb3u6ejffwkiG\
   \_R5SFV6bfGh6pgNMcSjPkO5Xai9QHlArFFmWcHukyy2VA3xfp1wxVYTMZ5zECUl_SFF\
   \7vqRoLha2a3Qu2rm5y-qKu4ERxYA6h6te2oRzajFiaoy8vlLEoCKoiq4d48q_naB0Hv\
   \6WM29u0ofdsgRF-E4usdN-b9BuCwgldRFGT9UzxY35O3FjrljMbMgVIbf-yFS_1uYqR\
   \zXV3kxW7A9MnF4UJ1TRLH2eYV7kFz6gTcBBo0YtI3jybkkf_qzil0uCzLu_tFVk1ETU\
   \bbFR5DW0DBY2_KpOv1sw4XPZYToeIyiCGm0W3qSjnOvIvJQPsoTyn1RAKEAJtPHiaTE\
   \nnB0H72ZYVNbNod1UWWs5K99ED14nJeVSkiEiBQdtltJkUFzPWXdo5Y9I7NRdesRHma\
   \6-L58s0jFaKoYryW7tO46QAcnXmBi3XTVLP78tOR0UmHqTP7kQCdIMcccyDXt_dnnjl\
   \-C0mDyThVzYlMVmbZNIHld5TgXrnwSSZ0dO82YzOcxAANmGzFW3ZfbEloZwwqZQOpEl\
   \CPdOuE4MqO2SwXlyWXukvlaAI7pfp_ZkceNSRmQQZ3SBGRgJ2ecJoHwG1nH-1P8IhnX\
   \DuRc4qH8VUhGoyfOELnwiyOkESEeBwodbvTGrm3nzdbk7dxkSgMOZ-EDpigq0xWA1wD\
   \JaQ1p21p8izGroiPtkXGSkaRa5aIor8aWYPEeOG2HENAqqHp_n5MtMxAr84uxaDVQSd\
   \NyVyFzXFpBepE8n0Fvtn1aVcYgsa4IS71KEbBhSIEzi1BwtJUw65C5mB4p35grAouwO\



Prorock, et al.           Expires 23 April 2023                [Page 50]

Internet-Draft           post-quantum-signatures            October 2022


   \W0bQn1ixPbN9LxqUb5a_BifZ4kDeTg2IXB6NO9MEim_KTrO_mJPEldcbDNqrRCZog7u\
   \ZUEW72Zh6xGWntNVoa5TbtO2QDW5X2_QX34EPU1yvWABb-tEPmVFwcGo9PaMQhJtOlX\
   \MP_FWiy5I2Hr2BZhDD2amscOeTAdOw-aKMnIfZdR_zu-L2Zwga75B7v3rQ51AQvPvGk\
   \My6b6JXIFmYFNPzSZ2oCFRQMVFgXT0mBf57lOt6axwubSim03ANeLOrBve6EvDFZRUG\
   \Fl5VQDOXdfIzboIV0vaEkThKd9N3AcyWwxa44rz5J86VYIWyVohlg27CNs4papd1OWM\
   \AhrLnUObaE9jBr6LK0divmfxQp_A6oyRTcu3toDVVzq9f0Ae668DApsxNc6aUgVxyh9\
   \_I4ZHpzkoD1x6d2hWFWgJUVS_pS4qYZ0xK1bvvEjkmDZnH2QyJxTc7arwureP5kI36_\
   \OIH2vvtu6BaNgiwnu-GyzaneGsf-6wTk3XGJ9nqfzJsbP9NJm8u5P8u-kFw2GUsVxXT\
   \A63aw_TN_S4OXTZnkW4OYr5PLF-DZNcsoLqZyPbnv59fWys1PAGZpNKAQAkobMj1gsM\
   \QvZJc0zVIQ0Pq7o1vPZPusIwpuGilG-yhpiJdj7QL-LUCmqROIG42wOrz2cN0TZSdBP\
   \MKAl2SY5X87Uwns8zk_v4B-qv8brqNL7C4uPBDX2_Api5O1J1WQS_hS8iD1qCSRq0bo\
   \GYE_ZvEWmFZzriaVlfsja8Ee6gyl0jI8sduABAxNsQKvqaz_9JQY515xoH4F5DjQt7s\
   \v_RTbucpV3uGSVkQXaxs6teYEJym0Zy8_PO0qoTk52Jj9ohEwv4ohqXNBQsimhMH0g6\
   \CLHr-5lO3-JU2H4_R5eGEmV16CWsKhmdgGLf3PshANQ_pdabw9yfWtEVif-vBglndZ_\
   \126615okK_fadTKRVBFrGUYSpCG_b3HJpAl475rmULWV_-oYuviZ3YLahdlQGpOVyEh\
   \xFbFHNUPeYJ6FFlxpb1vXq-9tHvoxb-YN9DlLZl3e8kyj01m5vVY0efsFkx9Z9qcfgz\
   \bTH353Lessv0NcprRKzSeq75QykDQuxDdJVOZrVLDuYTsj0jNFECzzzqMeQrCAClxOR\
   \8Ofo4CkseLHqr3BWzno4t2jLW4RpfTss2YmRbQKuJBCaehqjOVOIx7EtsPM5AuAymoz\
   \EXUS1R7kpovI6Vm3i4OvyygG810m58bSEWr-MwRSgtgaVpe8kRFFFQ7YagIqLMuq7By\
   \uY3vc00lhKdDDuqwXb003dHAmENIxY-PDseHsVTmsb2QGo2PT_L-ab5v0aWHyAi3evF\
   \K-RDKTLXK2RRC9mE2KQpPOQXNI5ZQgZw7PmaxtSOlqSuK2xw7flJZV0ARnDD5IjFzH4\
   \V2HqZS_G2tttE1J-EcSB76fe7wY_TFmkBAHNMc055x4a9WZ2f87aOb3thOYUHNc-zJK\
   \eyn6EHs2UmANY91n1F27s1SdtF8Anrfkz9NArLCGX1BZ70OJzJGZaX4ZtQ-631k25RX\
   \dBLCo-yStrSMmY9JYA2vJWtZceA8fkvCz5r7ZNdiPGet8nvibzahXBqvh1jzgtn7PFM\
   \7f3eI7fGArOPGGyFPNrwmEzOIiwIUg9oVvhrVh6LeYYC0P5tXiofmqqcP4ypGuGwb48\
   \UOeYG7Ue0bVXEPeCzluVh638feCnRnj2czo17oVD27ILaboIhSfa3ZVt2dsCLGBfTJ_\
   \7DtLiH_ujl2dE3SkSyE7PN_qGpDzvJCsqb8QtNookMD0akFc33zFDi2w_mnp1Ocluvu\
   \M1qT1qIPArFme8djvfEidT8QdV8zK0T9xbiz7znp6p4ds2I3kdc7eXs2NDUlsr8IpDo\
   \3JqJw9qf4oLVz2rBfEcDcojwWJUhX8HVVS0_Um9lJUh94-75JdrnWBdylYlt32Vf6H-\
   \XATGg4HAIGvhfhWOrK8lnRFfY-rj4czTAyJizb4LwCm1bBpoHV2azTK7qcfHgWKnJxu\
   \5_FxK1ubv4kWMv2GH4R4UPUIWC6Em8ZfaKbMZ0lo332WvBBxmHMBh-SBikvt8KAYqTJ\
   \c9YyUuphfwl2rQwPFPtGg9bnaIIcijSNL7Crujyi2y45p92cpOY55mKunugqOXsk5B5\
   \JkZexQCPiT_XfmkDGZLj-kKP0vS6CQK0KwMRxMsKxaEYn2v-OCoW1uTBlvwfqG0UYPv\
   \zuEfpl3vGAWPOjOYmOWBEhA0BkXgI1Qoi5dRZ0iQd3OLmDJ1u8GK3PfqP7uKDppeyKH\
   \tQaphqXBPD6HEBRenbbWJFRBwnWLQkCSMy5zE8TdZIWqehblh7hWp2HiHl5r1SCNG51\
   \9bc7R6JxLFSgG1fJn-u44A24VudlkYD5bmpCXjiN--dY0DBjFz2pCcue8NMwRD9F8ir\
   \Xa9BBojwmpnz9hd-ZNjYn-kgxOyTXsOd5Rk2P3zily8RfbSYaGzF35g0o7GdmzGxYaO\
   \-HqMMMxBmHoKG8tYyPx3Sj3UYxO5N2MD5uRWDdycsJk_c86FRXQt-j3b6WxZn-Aw4Q9\
   \-_ZDzg-j8eCEJ9DSvKAvVsxSHW8bMmfSGU6pNK2dTEDdbzo-ot5EBcDaQ7pvcXlu3yI\
   \s6BRvVuLc1jGqp6IAgCeuYxTIfpl3VkKPzsWZFZpQJMyByKPUWJdsJAw-goyRIvpetp\
   \ujbYgz6K1dEWQ71o2AWXONLm_-uBW56JiOtHe1l6jYPbuhnS9jvE_YPIByUWaN7AH5U\
   \CVEZioodxAnTbUPYGkf9LJaM0-sdU0LHMBqAEHVQvr9zGYhjxZ5rU2AOUEZkFlKWDbi\
   \RQlDEhxaXAJrWhYQxLdxj9vpEGMmXVvfhJknw9Wz42pYy-iERxH3AV8wrzGmuojEivG\
   \KIsV25ILTxRCubqyzREzwoEaFIL35uXI4o6-qt1JJfnjQzomLn0_fu2Vub4EacIgEIq\
   \H7nBjc8DXcWrFGnOVFjRTnVzHmOCEWsGZnHQaYa0_nUIQ1QFkSYHIp8ZrW9L-HsMX7Z\
   \ptZUqsgFz5lphspjAioICBmGTWsyQQAvmMJcEQlh79ediVD1wCciPecIVzFXoMNrtuh\
   \DITJJyL3EDKZ92zC3PsrDS0TiGbXYCvyDZCH_Ffok6VszejaaDfq2TlzSE8ij5B9YwL\
   \BNBRO9glScoiPTb5NWgmGTz1f8V_r6nnKf3LkcO3JgP6brFnp5Q3weFjf98mmoTADOa\



Prorock, et al.           Expires 23 April 2023                [Page 51]

Internet-Draft           post-quantum-signatures            October 2022


   \58FZEwzZG6tee21mQmAcL1YhTTfgvLDHs6aBEy-5yyQl4orYZWLehesffzNOHrHfII7\
   \NoNBFxMWUJ8128EwpVOECwrpWucl9jNiMLGQEZzkmdDk7ypODLE5DR3RXEfboR6eMJs\
   \X7LshP3BQxgUYjQvSD96qlCYmHren9y6sVzIYxSfCERonG7hj_tzUtv7KbpZvOeH4As\
   \YgIJkmcU3RADO3FwFlepw4Ug4s-vYQPN8Zv-7mSsvl2EpZlZWpC4Ay905G_2itedYOZ\
   \ZXq_aCRIrSFfrbvFCW1SIVuWRkXP78DJkpfEtqLDW2MFo7LeZPmpizoFLrW450u4FzP\
   \EQs2HOjlIQ6usYKPatG9ERy-8RevFsO7ryKsE5C1sd5KojQom1dmKgkqxDv12aFqFag\
   \PFKtieJOaSM9d4tdNd4vHmuUcxYNL4SRGqXbokdvgWlvt8o7HnSSOLHJjNPLCcdb_rh\
   \T7p2OMR0JiUYlWQZzCGqN7dqg19F__NugLty6sFNBF_86hO4DfjGsnfRzOO9QYPjgPo\
   \7ddClw2sEBEIlSspuKlqWKroRGGHY3NSyv83A7KOdAbpxlpFz0qjYnpBrCXGSc9FP4-\
   \4q81Bhu2OBn1eFR74ND4jqZirl_0fMHAYzrpY6cN_ZhUyAFkcaMy-eUUUWUkcFJjaxd\
   \xreVSCZaYzf8LQkzHqibP3BPD60dSN1n0YQSikgHSfY1q5SqVv9xLzLT4qOxxE-LiT8\
   \V8bBdBxDJD7nHtP1UFqcFmeYn9Sjntg5P3JCD-dMhcxcDk3ZsS9CSrsxjnvK1ocwrp9\
   \azt-0Z7KdEr2Gr4MNvi78zWTH7DIG359VALiq3Z1yntb4UwZz_SnSHyfm_bN-GPmSrQ\
   \ZMH_h54yyNbIm6atI96z56V9IYbhuOoO0ujm8o5_lJ-EbOWdb4DIYw3URcnAIe0dqUP\
   \FIwe_HbzB0jjx9tonNrz9BeQTOdTxjgjAe3kmf_nR9DmJ6UecTkFiLb_ZstGqWtIdMK\
   \FO4zr94ZoKnIU76oXPpidr8JHVVQKXnT8xZ3_GiVuN-N63IA95F-F7YWy4aRtQtLb5E\
   \SF-noSkzMzNgpwZozhafh-sm71AALQav0mh4T0iLggpHeh2EEZi97HsINF9UjDO6t99\
   \AvWbo9IFsV3GWR-0rSgnvg2p6yGcWdga_fuMlHtBS_hAVCf4EC3NxeCTnU9WWbehxoa\
   \Z-2cyb1vTdPs9mUCY4bwSoEVo_IM6lORT7FVdFRrfsZXfNxEOOLgQp_uSN1LiMWAe-c\
   \EnLTxZERcQNdZUoXNYs3x_M-q-B28vSaKAicb2TPAeFmQo1otq7wx6YyCTlUTM8tvo6\
   \nBg5mpjWpHoTmDpnVp7WL-clUf0r3BUFozI66v82fFZqW3R9j1AT3Z5P9nTiV_GbHHO\
   \2lK-4kX4aMO5jKjrZd6j6TCZvfGslZU9HQedECj8erKQDgCK02t8xOHtu553JAwLjPL\
   \xkzeasYq5e_UOFbRG6S-dfWWV7lI7vMw94k2nEQfZnHLPuKwUUe-wi_0wRX_CGUnq8C\
   \Kklz8RrnNLYd8YiLqQ3VO7iUzrYAFTzemYlf4rHencJ7xdGw6TQO97UqgMkEdUa8meR\
   \uSRsng0dd8_mJmFsvB5cMiUwP3laEFhlH3PCtKH2-2g3tVi54fFonD-v0CDacAsfxMe\
   \2cntL6-M6BRaT5wsjFjhwQsKff9BQz6TCHBYat4fqLq7DGVJt97sKtNJ6xvfMUNeCoP\
   \ejC04IQTjWsriDalsDo2sIpR0zbFsJfc58N2cjI9FzZqSkw4rm1Yd9YAH3FQw9BXgPe\
   \O1LbS4Ph2-Dffdyom8gqEf_qId5xNO43H6wmugZllGr-ZAD1E-g2HDdkwnwwQrKP_nt\
   \PLuIvFbb00B47dqQ2Vfy2Zyr1vZko3Ji_OpJjaYOlKHJJP3JV6iHjZrdWK5MFOB0Hto\
   \umy8VTIDkPEmsj5GM5Hf53qmU3cTt4gIPEEHvr0q0v_rmSxQA1ejZAtskqco4UYW9zU\
   \6OSgmtolEoc2j80ZQPLdtpfJ6kRbx-3QyQmS7ivnXiTv369Zngt_zC6t_O_rweYRZeE\
   \akSstJiibX1ncvadoNhwSKQdGSCll4MzbI8et2kBrWoqI3zNbkPR-dyUQmiz01YKWz-\
   \_gt-ycAYyJStswspncSLLpNXACVDCzX13aPhxUk-n25X4ZFlYlbzxwoN1TLeo2FGluc\
   \50Di1SBzyu08TiVJ9asnPw9HGuMdlyqK7gwGdUmHQr99jIeI5aD0lJQskIuuDJcFpXi\
   \iZZqhIZjKVzTNs_WOHUGPFuBhVmqxKwcDaaDfH5cQn2Hqi_SfZZH0nXC2Wyu8GtBPIo\
   \Vh2jYtrUM6ltX9l3DB9yRKZkx-rZKRgvqTIpf5gPh4RmNjJ46P3KClUphL06qsJtQ1Q\
   \XvzmA0bA-rYKwz63100imj9iAlnZadz-muL-kucY-w3R-waKbq4klttfzvkPgLytyCc\
   \ucQOAXKpomcSShduS6Z22zTC0-TSycdViTXLxFSoSWE6hMbbhBHtEzSqcbif7ZhEXT1\
   \1Ya50jHupF2SH1Tz_BkZI9dktnwUMufsgcMoKKL_duh1TaCNSd4qDVC2x5TgizKRMEQ\
   \rPztild0vPePgsLeLL3GoHHtwQwKR4fHbbTTlPLb-2e-VQvZAHEdVC5qcfMbr3FrU81\
   \pHcrFsrJ9AxVZuspAt3oRchWkdg4VjnEAvgL8S8kox7Mh8bmYbFXEguAIZjG2bd0GDY\
   \m1i-8Pbu-BeGi4GHo1gB_lskTCSbBCh7nd1tpSQS4T-uf8GcZHLWVGlwDYfg7_PpI7X\
   \jmaIJ7yApfq46AUTxaU8sDKQYefD_zH4sP3v74ULs21ofksmcjEjZi45Pwygal9X4tj\
   \uAHAeD31a3ISPvllwLY3xPo_7gzZ9v0PZNcBl-o9AXeIq1Ejy5b7aTzYuLSbdAC7WPv\
   \F7Tx_ER5sWpXPtlxaYQ0PPQdL-PEUvp6tdV52jThnsJiow5mIVasR5P-tPulwPZVF30\
   \bYr_c9pjvk5gn8ueVx_dnhaF8eaH-SOjm6C1mvbSzIaQtSM1k_dbjnZCK6cF_xkIU25\
   \r7Z9j0otCEytHzCBEOdLjPTaKDY7cpKUT-oiRSGc448N6GRPt_XxQPe6tReIL3TkjaO\
   \p_JXFMyJMRLTsWUC6ezTEd3Jdl_jbD-iGtxpFMWtVA4skkKrBHS84Ph5B859jWT0KCA\



Prorock, et al.           Expires 23 April 2023                [Page 52]

Internet-Draft           post-quantum-signatures            October 2022


   \gKl56dR9VdC2umQIX7bsuS3zfe_MY-y3ITdzCDcCeIMDXklGsXxIf0M4SweSKQkAwmV\
   \KB1xaZtrV9lR5a--cY2abWF3tdPKYqeaWxH6f1kvqDdmDLihSOeQrFZLgMoKrKEvZL8\
   \aN_HS8rieM2TgZaWHFo1tD0oIOs8KUZnXEmbk_YBxJ0PNj4DRpvGSIZn0qSymoL2zga\
   \lL_ubUQpg7XINtXwvNh4Af_jKyjnZ9AdnLTidltRhXHMo6-Nyci-DIC9TIdhedi_Pb0\
   \JrA0R0RH6T2iItunckn7qFmEu1mBHyEHYleDLdcwZZdu3T-6ljqJHfm3FZ0Hc9oTg6w\
   \4x_s1OfJZ5rJvutiV_Gh9bVcJudItUw8-y8EczF47w1Mrq5THUVhwSJn_dLtpARWOkR\
   \o--mnKPdFXxb7aSifHtKbgWFs61Cx3OGdaRbVyfMGD4b1SCTO9dYxmvM_OqTpsvIynP\
   \avnNxFU5U-whJo-EYbJAaQ2DJfFwJQ-ulYFAllDQZLQzI9KRHxuk_JNILr0ddArcw9f\
   \qCn73z9izFHZ5ScmBzdGQE8-JUJBkuPF3mLWJkVwh5_firzp1CKb4hwyrjAOKQO91SX\
   \QAwHb-d9KeFGSO8a0DP_aGmbzLUfTPMpPuRi7p7KqGC9y--K5deV-lhXf7o5UJlhXZU\
   \JWBNYMoAcdzGhQjp6Rmgotg4v5FL76vKFp9H-5iRQbnTxwFdAG_epJeQ6LjUc0p6-E_\
   \rBYBVRBv9Lp_ltRdlbtBTzgfl5ExVGtJzpwr_qXLLffO0R_ntfBw1oEtAn3ZaNukVK2\
   \-0syppR8hq2CbmeX1emvDOYBZSkS2f8UQ3nT6x7WAoKARbXLVpj6YOBXh7E5KjRpwKE\
   \b_PiixJ99I6JGUu3Jyk8A7ZGD-R0G3pI64ph3Qjq3GC466VuuNpbByTBFh3L4Ifwe96\
   \qpL-p0Y1vN3qcZt_kukEP9JaB-RF5BCiEb55M6J_olB6gGbX_OEXSsT3KHK2t-5RbJp\
   \na8T1tBeBo0WcV-EnOU3H3GpRQR4ZlgNUGR_UDN4EwlCrK2PV2F0PiDGmH8xKMUgKjs\
   \K2Fg19yqB0-HbAgeELOjcgmOk3dwYZ0bR-IUt46mgxKwCDlfp5PsumjCs79lRDuWzyO\
   \o5YQsXF0WQewOlUmi5HFbVY0eNue9rXHql2mPjT80hXOX3miYrJU27tMKcMkhSWAmhl\
   \qHvvHH1Jm4qMGxBOS18sB8it8RcdYy8woiheURxlU9-OZqG7nMam7R12mvvNytIfpds\
   \eHG3zrFlkHs3Xse1uXQiiVFooOGyb-2szxKxBtbnxbMfeyKSaLTTZyyizGEbrzoZ5Rv\
   \P3CVYJ6Nh29YLTejagzH96aI6ackJ7pX3Q7TwIXPILEh48Qt7uxe9suhZAjHMS6CsN7\
   \19axp_YZPZ67yDhnDqOCMb_pUqiekQu-xs681Z0ZDJ_3DQeuqMBSWaL8u1AVcGOLUa9\
   \KGSa-N2VSMSUyVBHly6pKQWhe3YmmyjJQbb3teZDSPU-AMDy0aWUbfIo8udFWdmoJrB\
   \ClVdC75qYyECQHM1RfhK2zpBdK0lCnTgrJIqRlpCl1_odx9fEuJd2UPAzH3PhmkNnlu\
   \HVeHFfyDWKfiDsT1BM_oN1rW29ds2RfdYHxZVYrlf45XAyPlUB223h7ngpai5uAjCEF\
   \kK4vzSfmwZNpMY3JhFSk_7IcEZuZzDs4sxWUtZosEdQQsfRNM0LhpaOgf9-kX7GV9Y7\
   \jAQczEj0vtvYK6Vj86PAcLMRfMri-ShBEriFdltr0a_jDjVT3Bu2W8AUTh3vqMMrND_\
   \F5zT5zBws0nPIzgD8YXa39zGvBvU4fUZusB83IZ4AYphcxIVsF4vl7uOpk81YvZsL63\
   \wE2Zif-9dbL9L56MSJaFlASbJCb6o6p1S8_vi9QqDQJHnjcvUdXmevexgDi_PHVrJ9b\
   \mO67licbb4G_wKt3O89bGi6WjBNBqyOSX-XoaAQCBYLehPa5Sf05Co_KBmPpg9P2bFP\
   \TeupYpbgxBhTAMY9hMYmCByOpQT1IULZUkJjierYiPcKyOLcZ644iGU1yeu0zvhXja_\
   \lkuwfgoDX384d4kw2YXvdqBIQOID195lgSpOYQxvSybDvv1NQksICu2fX0Eyi1SrpFi\
   \u_tHm_u2K0gml1Ljun5DcReIp-uq__XmH6EoyUdM3kklGyRGo2H5VT5ub3JCJ4zKoKs\
   \j2Se_Zo8nSCc6YLgeGTqZlODmW2U_nJF2rpBU0qfSg78Bch0I9rg9bUGjcNtVz4VT1x\
   \yKkfJc29QsvLIJ5wr_w2MY36HirFAKSHWfi-fYQmublQUEJH09MJzyMspMYojNryviZ\
   \OWx_ZBf7DbaIp3cMYCm5W1dOs5Ke7z6avkeju5ESgplAdeK_IOqCAoloi1CWBTIMJiJ\
   \0zplulvqbaJKIJc09kX7t-3DAPLCjtjyopK1bGFArb4ot3mYHXORbmCdqjF4MCdvY8C\
   \ODrnzc17LU1w2naoWZ9FSjJtTif_OWxE9KDhKsA5ZfLwMsSmqW-Z8LEB4vLIMloPs31\
   \xd2CTMhTSFRDOXKslERBu5tZvKVitP3oM5W1hBzF_WtugBnx9y22xg-BQKT9lSNzlWX\
   \nYw1kfCET4RulAW5FdseWu_L2U7L2eNULYGNjc7atooQpI-ixvkgVtlFfKRkS1oOJ_O\
   \W27IOcd87KaTcPZzQigFy0kRsxDHwG4vcv3KIRto0KRKqkKsMWwIN_fJbe_8rGlt5QC\
   \Uq4mwb7QoqVOXJrUyyAypHwVKJ7sfN_U4gEXgVbADk6gPQl6w8gi-yC_oaqLVFJnxZI\
   \lUf-7iE0_DFtup1KZNp5a7Iydv31eKZZhbKTNEhR9zDTQNzYYJPGsiAlkS9NDAzSrmo\
   \2MsALtSKLbx4eZW8t_5aIoSYS86o6sY8D11NP-hwcGaB9qyTVsNyvDIZfF1IHpU0eq2\
   \C9EEBjaS_20u_yaCHUuzB8hWZc4I3NERmAG5v69Tg04UZtP7AFw_Jx5Nf7HJlFoePMC\
   \YigFuEQAk67zdsZfkgDhqE39J4NvsAjYR_jtlkkxRf9HdOT_uWuEVuVXPc3fAwOvKfd\
   \NnPjqULHa46kw_Jwj7RA42H_Xz8McUPNQuScM87FIgiK_2TGtuK7_qiJnbv_2V6Qwp5\
   \UjqDmoQvWzfO2tH6a6m6juuGMjS_7xhxI_rZn_oQ51cug8wiS5nFqmegAR5QECLsfjW\



Prorock, et al.           Expires 23 April 2023                [Page 53]

Internet-Draft           post-quantum-signatures            October 2022


   \N6iB9OxZ7rQ4QbBVZMytOTXiytLrxrlIzRztFRPXcuw_wSmr1O7eKG_SNbt4gv911l_\
   \uBe_qaSZknH1MEJn9DABRHJ6Vj2Gvn4GCQnYf24ua2MpNrXZTPK7nd9wsIh9-2ZpJvB\
   \kqsSC7Ggk4_aaVy5BPXlvkIIfXCudYUAT1_hW58sJxRCseEVju0h8exirR0E-4K0OlV\
   \Ljq4NQ6DqICrZrkgNnlseckaH1O5l_VbnuuMBiZBpCkqgH3K3jByZDskgr7dHWnGXl-\
   \Vo6v0rklSWmaR98I6EyasgqlFTw7CmhMRvTT8Db0Ei8ZPQPmCN1voLVRgN-d9s4gveh\
   \LoOd65g1vCjmZHjUc-PK7tkC0d8ru8OUqBRXQwfvKQwSRk68g5JGnsZKFbw7kdaJTnK\
   \6gOcDbwd9ToTS_MrT7SUX6pZdVVg7yIrxhYSdZvOjxLC63KLRnPrrTBPFdSsqLupE-T\
   \uhaXBLGtGSw-n4RUBftih99-xUP811D2HO1WewPLdBU7o4WJ42hVe9V1999SUrfR_yy\
   \B_9FkoAvnTOtFKYnHg3BH4x-8XTu2t4R6DjPlNJfMWd6yvIwbM70k42B2WCxrl-FnEB\
   \e9r0Ty--Zid12pWbZPuS0BV_kFPwqK0NYs25m617GhXr4LcTWwXwAsHYSdW96KDkVsu\
   \fFY6euC88ycsx94_QuaF6IttLw51AGaloW0YkmKntxchM2tnAZQM7OAtxwWJDyyPlfi\
   \zm6OHNKI-RJY9_g3BdCawdaEvxwsEIicWD1rsXz1Q-kMmqnkPGJ31Tk6b28v1aldIgg\
   \8nvHIevKq-MZnQtrclREqconaKwlLKd9RPu-bI6N3DiEamcEDNh-xOS-0-94V37F0LT\
   \s6O6Q6L-U6RuH79I7zlShkoFWK4Yd1X-go3BMpEPLlDr1xAU8HAJAeKqkkuAPz_DHE3\
   \sb65_3XOduvtnylRUwBX6N-ELAA-Mt0kC1H4D35UaG2x3iEPa0EbE9KDU-i9dCIxmu_\
   \eMQrXT859EqAQnSq-U1nrQkLRMEr3caxH9X1iaVoT1cfuphDQmZGL_L2XRRBGABF-NM\
   \klA9kkrpPUyPQBvnROFFQgNvg_JXIN-lm4IFCnq93EewrlWUdSpleIuY2Qsd2jdOsWF\
   \pLsRMekcPCJ9QYtB_J3lmDwkk1175eZnNfLVC-ePuZMv5Sq8o31OI1PWi1nolQD6eh1\
   \FFVRF0Ea-fJxB7Fc1LBkcj4tetS-ZG5W6BefiB9t2EdM6-eK6f_UZWmMnvhwkh0lKYH\
   \DedKXX9fkXqxvFjKQMymhExPyPmyyQlHV3KrfRylV7Fl0HuBzRiWCq5z_ngmM3YQ_Z8\
   \uIbH0U4UfRjSSYbVSem9qkR96qf5mI_-5Lz_3cTYdBTm4sNOBhzD3NIJeADfoHoS8n_\
   \2XoM1YSsG3EOVzyArmdHCnzPo7btBMUXTVXXg6LGJVf3Kw6P4kzSVZ9NShdQCWnMB13\
   \DWhELPiNtyGng-77SrpOQGPEFSbvHpYzA7Uj2HD6BNTgbEBgl8-Ij5zNytfgJxhhRgA\
   \zm2DKkUZ2XzPt-640uSUjbLBZttPFr_eCvuqpLMOLM2CX70nssnjToKDzbTLPMynp1j\
   \3u0jKqRdCTc_bkfRnt1mfYRMiOjRB6qg8PP9J5yn15Y1VXwkSDx--DTJgsvtTddK4ft\
   \HaNpz6YXbx0SxHPufykzFpJkoBjKKTWsOAYOsR08HgfF2TuaDXLhXroXaxqFLBqKOb_\
   \7FVYpY4_U0sl7mGpscnWXwotKKTxKllFzE0B2Cu6vnPPczOVLsWCPpqjs2ZmpTEo2EH\
   \_06VTe-1KXej64RzJAmfBJoEBs2i3oNrPkYC-h39ZkeGzJpnc19TgMwlS6omC4uXKoq\
   \oODJ_1XLt113q9n58XHOmypOWtjHLTc7HivhmB8ODIAkfNMmdhODc_Z2wlpPhSY_sda\
   \idKoYpTOU7pSQrA1uvvRJQMYoO5dD18JtBumMaRNqRR43aKrtykYBNxkYA0x3out1_8\
   \THkYChvdC2HALtXdgP5tY4sOS7CS_W4XZhwDNZYlsobAqQJ2MuEQayjHaUDlJIeaz1b\
   \DYEJa9lcZrmzqfTz4nFeWk6PUzeQuc3YkLqOo_qOiuaJDO-sRCPPacaDM4N3RsTIQZJ\
   \rcf8R2qGaOUB8umNVo8rbfzf7H9IoBGLkNfruUkrLqzoGtsoj2-Tb7zGrQRyIO5pmVl\
   \Kfp7QEj21Xx1rJLUyzElnG8hsLiKMsC-PJP54bDt1RRESxHYLi2Okj_rA7hUQYpgupj\
   \kVQv2MhirZbgwdPKcVNn1le14DripW_E884rvUJdt_-dyWLnDuDq03kZzRqqlPpXTXk\
   \idXlRvJyKthIyFxZRlqKTFIfCHdQ8yixO94RYqz9nw6cchCo4ecuT1uzs4qlHmri3ym\
   \n6vjBGJxwFNRXUdV_OryVW7cSePzm8-5Vrd5F1qYYINA_etael5dnbafJ5KeEbMxx4R\
   \6cJA0FirFdAB7C1P6wiEfGfiBerHkyrcx8Bij5_yrirAGxi-RLzqAK-hcoeWaSg9kIe\
   \Ku0zjD_-NqUKODwWq31hR0YPOXeprujIDrSKpRmnsTIYu8hh95haPwEMcd7wCo0ahvh\
   \9EgOgvoN7KGVZcS8PxksBZBbeP3Mpl0J6nEZMWAF8Y3BKpBRZkb_NUbLFHk8QRER6Vw\
   \O8yBuvTQWr5Z_F9S7vcLIvmpxfXRLz5aPIKiL4WkaRHXHbX0YaHcxXyqp4RjqNJ3BaW\
   \YBr0x78_EKdmEfTzOeQ41SKNRlY-dOGP7ApzsRYtrzsQYA9d1n-Tb_2badRN7_YN5ki\
   \4qgFooL-e_bKp6iM11KJhP-xE8nsbblZbK_MlW5120YppurXjupEXAzEJSTI6vbCvOh\
   \WsrWJpUjU1WOkFmC-IZHL8X-HfCJ_CzxMcGoVXHMgyYKed3bR4Dx7WTFsvWfxYxHde0\
   \x8qAg1w2q5V3CoAaCAou2DqOGKBILIRNVsX0MR-16FsjLzhSMibxYDSUUPso1UnrWly\
   \uOWOLZE9itvMCZVz9lUU6CcI3CBuFbyxJsla99cKf-plqtZdIR8vcdJOBvfCagr9I-7\
   \ylpwVMl_9BMf_SgZK36W23yHObSa1yFd35LAurL15SsQuUR0w6K4nuAqvNql7pEXOt5\
   \g_tq39t2y_Hf5UjCT49Q_HVWYcEBTgX-KukrpVVuLRvp6ktlpJjBX-Bcx12hAs6IQn_\



Prorock, et al.           Expires 23 April 2023                [Page 54]

Internet-Draft           post-quantum-signatures            October 2022


   \K8lUVoVlS4hlOECKAqab6n6qA1ClQL130b3XdhWke00QTLkyxWeqpKB_aBISKu-2S1Y\
   \N7l7KsYs82o1l0ZqaVWIfx9oHobxxFZM2PB_zGqyf28oZJmruIeT-V0SRYEhlmNVH2-\
   \rovSWmzQWbtMniCCXWCeXcUGJCa7un1eWFAxq6fb6x5AzD9NYDaPSE254VIBQ3P0rDL\
   \yo77FojwVY42REbWM4NdqCw0uOGVIMryoH5C-Q4USFg54kcKg5I0otL_wm0Pc7wAVXr\
   \l6v3PwIvoEGVmJEax9pqy1HEbhcXSwGzaiF-T1L2XW8w18jFfNa5UdC3My_zhp-icGG\
   \7f8-BcN4mgbsuJfHDRxULSXsPlglnLbzNYk_DaEXIwkEOfLkHk8rbnPrdXINt78w0WJ\
   \bGbB9tx8unaFdRPS2bqBYpelgBqySYI0qjdoFNSwakEjZKkBIQhHrjPcOGqj4tFUiye\
   \qKZ42S-Qoj-hbYNC8b0UAjMoUTU8KqfUug_t4wGevV6U8CkD-W00sMB22RWl_DOAKMi\
   \u40dpFGYlqGqbzzchiMg48plc0uk2JTXrRX2uV-2mbBqeGpKSRR_cflgcpberly7sqf\
   \FMBEMZzJ6lPP0K0KH64FdBB6eMgLrRx6VemABHl2A7XiKRdIbP6H7cPeToqqhnXtgZw\
   \rVSaWzFU3qKnrzXaZFeHK39VbuSdbM3raZmRhPRdeYQ1Q6joRqDhZxFdwyKhcEsiHaZ\
   \jBEZ_6A39KpJVqsoJ1TEV9zQLuPaxqO9hno-xQ0wCfWIhg59hW0MpoG227adyBVYSIh\
   \8jT7VhVEFcgNIbSC16fZAuXgvPM5_uEEPnRLtMtz8pZMQ8qghXmwYCHCzHO8gCkPSNl\
   \AMQX8llEjwHuyoNDB29vILGaANHFhBfcU7dtntpcYH7ZQZtVlwbwE3xW2qJSe8j7PX0\
   \pSwbT9IOxcMapkAZ8B1fLzYk2QH1sLHKVnCSnI_KqJFrL1FhBsthS1qrehWspH5t6EI\
   \6wZyci0deX4S48lgTTgoKeEiXzBmSd16bea8V_-ORS3jc2SD-USwx5CAxsfmPvNeyhM\
   \ZVw6ORWRpUZXXe5lYS0MxriK1yVoeaKYfvYDD7nr4VjfK5SZckMM1h0ZBvXeIHTY_ic\
   \NRTyWqfXkDPRICq3wqWpjk22iIZZv-M4Z_pjI8e7af8R6Y8ZnIKNGcI1QNmo0BxXV0_\
   \oKKeUeCZwqRDjOFu3EwcwFIuGdexvseqJ4nj7NFw_33AVQwEN2ubxxMFEmg5kOlnDCM\
   \Brre4W8rZTBWck6CSjgpQLbwBPRT7Th8q3KH3-rS2gdFQPQio7719gYjiJTcSUKMkA7\
   \OlAuH7FIYf0gd01FMwVjrCLu6SXkXKajL1n3-MTXvLwAiegOTZ2i1Y063b24AwS9I8G\
   \Epwzk4zG0BanqQaTmBxotjbiD_9j1L3MTSNGBk7KJXCn52ShPEpwHabpBCHlsH3vCgd\
   \d_tMVbLBjudv5b6sNKdqMjMLsTDZZmgh9V0v8R2lfLfZq0LOsFyvmWS145AI_rGEd3L\
   \C02S0_BMDrVL6OxZRR8GbxLYfxPABIwmKcVR42I-lQp4-ZHpO9Y46fb0JUxXRUclzm4\
   \Q9zKUEHG-QsDmVRDm019FFG-vTkUG3n2GXbc4muLSvHtd3k4D04eCvB1O85DxtJYQr4\
   \Yb-_UOdxdmSc7MIRfknb0I0CtofY5Nr_-dLx6_i4Uq-06n2Ke7FzuXspeLY1RmO_L9v\
   \Ec3GN-YQDgDShu_1OE9qg31dZ9KoUffgDhPJj8f77dTB5IibGgzAwK4zOuwTVc6Q8Ef\
   \vFNCzea4F9YI7qfNp4-4hLRyL2KKxseHra-qwYT-JiUIrHoG6Ld4-Cx30jhZmq6xhTC\
   \pm1zExjWD3XUglCKEHLHiI1oc8oFgfqZ1bXjXyYN5P00CtsVHZglfDUwsLFP2v7yES1\
   \gK006pRIYTIRAGZ0AMd86PeLn4HhQffNj5JouKfexh8VwYdRUcDTP22vVP4MFH9sk4Z\
   \fLQJkDdDhWTSSvdfYYsUmJ5jGMHMVwojHHkCg5HA1q97-ywX7BnWFUdqjUVBeFP65Jy\
   \9vgze4tbfbmj7MiR38COrIeKtO4mREs8CK9z3kqHdvAfe-TzRaCHljpeffQVLwO9fFH\
   \aQvL4IT2snCUB4No5_8EviyLHP2PfLHbMrcAIxzEnxeXC4yNDwrXQrLSKF3EEY7JOBs\
   \Vde1HOeVkfELoeiwXVte-A9Z3cOUR5gAJ2pag2BVjBOidKV1R6y_N10ZRGylXjIKrL-\
   \a1QUZpjQqFZk3TGWZ4c20zcHi_hfmh_H3Wf4ErPDj6Al08wsb6hdtZw5f1VQKXeFgEk\
   \xukNQUKKvr9t3Ic7W9_rdGVtJwq4hyACFjytsKDfdFkcRm_PgMOPh3NR8DDleR2b4FD\
   \DLkfhQYUZabgwpdUWBrkiOzBXPX96l2iJ3Y4sWjfwJc5WsvjCfyYhvX_a6CDa7t00hO\
   \UVPm1mxdfLa1nfPMrHdcUZCBh3g19I56NYXbJvnr6l8qKLwo8wEw_Q1dNNkxcdGsCxJ\
   \iBjbak9UY_qYECBM2UYCTE8jmX9U0TcE_RqmmCQ64JuZs88NAm-9r90_1HTt728VcIH\
   \3CUFpzvpgmNbT1r6rM-t4Ej3iR-3Cs61PAOHDYB0uIPvMINgOjQBTvTaQl5Q17nXBzu\
   \ypSjfHNiRwuXCG1mMxinMMNfms7VkHesP88vQmrGkMHOfjHxu__u3FM7xC9AjIQu7x5\
   \omXmUpi-9A8oCL739lASAa3-XqcCXOilPjK8mJnapnwoEp9X-qkHVa26qcyVfZoIwQF\
   \yo2FtHNkE_KnpgHNqbghP7sHMkH-eYwnLpEQtafg7Y1rQc0ZE8H9kcjmQEwkS6dE-Zr\
   \IsVFkxOfIEEDQBzXG1Zs3rKxXb3uaskzsoeo1UGr3v9rUfn7v2uc5vVPcyoT6Yq9tmL\
   \U0CDQdfDIONDa_olOnoUg3C5cCIiSFU8kWOkiwcYoEwNbycKoar8FfBTMpI5ft2_Wjb\
   \_PUBZ4_yiyY3NGHy7TwMvyq8wrjyJ4PjjmMlATHzuBNi253PlKyhhn1r2DDBXood_CY\
   \03vdoSblbnPH5RNbnfeuLi_NJFRDXP9aRmJkefU0wMnuMk7vocS4Bsneh0x-jEjh5-b\
   \ZMwC9PMHoXkHp5ujXcZd5pEgLMOjMkpi3MC-4tfzzt0YqiLhw2RRItOOs_Y8URrtzNF\



Prorock, et al.           Expires 23 April 2023                [Page 55]

Internet-Draft           post-quantum-signatures            October 2022


   \9HHEUOwijaXenns89MeU1M0lJhvc6m9QiBWGbq8_X1DlqqA2e0_Ue5cqbON37Nz8rK7\
   \OZlC--iusEJOT4UoiMIWO0VS_LyRsAMJdIMwe1LhdVvmElyX3lQAfAYbilpv_A9nwna\
   \rwJUApfuteCwgvMBQvxyUbXJ-vVyjOx1KASIBfwNP3uG13xb4bANzhlLj5Hrw_8Q8TT\
   \4WzOFsLBgcg66rFHG7B15lvHNRU860cqAeES6NEVtSO7GrrbpP3HBSFBHbQZ_zaf4D2\
   \2xvqjUTdf6SbMiCsJuJlAlW2NfvLJSeV8mrz_h2PTGT_SNMIyC8cmmmvf79R8RWtXFA\
   \fUl0PoLA58u1z-wEnHRk-DSa8_8JzP5tv6GJ5Vv1G9FyfENMqFkEziLgHfE7UtP56gR\
   \EQ4aGk7ASXQKMvXfnRYuArz8tXmyX2gOdggYeFputGv_NRv56JoBBVO-uDZAMa7qbOk\
   \uTWm51u_BykQWbxDbsFX5Mmb-3dz9Hd_sdz82BaBl1KJEHBaFWsAOec00Z8uJZpJUr6\
   \xTQZHm1Bhn_dsKQnlOUiPhk5XNVyHXUHMRy0Kn2mDbKituReiKldXC9BIQADfpcrQQR\
   \o0ePnTKGuXoq9zsTV0seXtIMC6_suHYx2Vpiq5Fl7iuhmUhUHTghuqy3o2-RqL98bOR\
   \QhXPddwMfpzk3FxMmCytLzMcJJdySW7RbCMaA0opnGnV27-EIKGqk6WSZd8y_mY9PvU\
   \Vk1K4q9fSRug_cKyVY4NY8EoM9KKKSl6RytPvMlUVhjbTOWnoy7VkTNAW929AUfFkMj\
   \em6_3DtGjdSG_hx5Fq7Qd7c-m3nG25BHidK-lQ5-tuVq5lE48pBBFgMUYpFHLZ-GL-I\
   \dCH1_lW1K6714iHfAd7ishSvuLEn-hZdXdUW7FJ_A7tUzPb5cbqDV5Lna7Hlc7Z-zh7\
   \6yoG693OgDxGTqUCH34nnPFRKxJi6CrQC1P0i45IxHDc8fgvDncuFPeqC_RueKQwLBA\
   \45t29xgJitmeiYLDcMRQmO5qVlpUKuve_pNhH3b7bE3VNXCVk6q9Y-vqnF2yV9tatk1\
   \-8Kko1fFt1a4QCTtoej2DAcGXRk7hBNrDavF4QBF1AK-aBxJdT2g9F54V8MwAv6BCEZ\
   \Ofaeb91gTGslxB5nO5pkSALNi4221zaBE_HGt1vxTaOQCFEAg0Ul4969JY4TzzyVxvW\
   \KNZsg_CbKJkmTnEmQIJg8ZqcygcTHpGMi_P6eYbAdhXBprviF8lMYG53WSGgWkrQwXL\
   \SjY2QQhKsYkTS4Su8IKy7O7sxweAXuQqKIp55reMIOUrrE5FcdI_3A_EKEAFgfh96J5\
   \A8DJ8yyMKVDLGmkE6LC2FgBx3VlZDzfNA2HB4oDTN1vu1LuJ0ynxQh2kvX3bxUyxZ1q\
   \sAA6TDEM2C08aurXRh243NMQ7y3436P9DQ5qe0WMF9CxWV8grSr3hhA6FvHpNcHBVa2\
   \9LFpPH6Gtd5l9302MM4sumcrlBdRPKN6nF79lAfPOE2LO2_pZy3qxRjosk0cPP0YRD1\
   \YFbnIZExoHB9YgaUCT6pze5IRD_uX54qbwpxImfmC_aQZyoB1b29svP7ECiw9HVHuzD\
   \PHiFfJBYSxSqGpVEMb0bzpnfGzPm7ER6BRzpKQknRIzFsmneU5oe4Lg2ZJuPxHkvvIE\
   \1QdUQZkTnbhgRzAUkJfwcKcKDlMm82CWkLMTpV4wEHT5u_mmrvoFSV7l-mbeTAINnmz\
   \RyPP7WWlNlj34Fr0NCJY8ebubsP0NqGFgRVrKT7a-PTfkBbvU1vtAJIwHang2vg3MuE\
   \ook0IQlqKUpnJHzLMeeSWCRurs3ohjzy32v6TpVKmcJ3_4Q-LBjgU07whZ9ccvy9c6h\
   \ekU9yP4PKkGlx-M_WIZYCvgIdc16vEELIclgqx3ujrqjwvrW0l1GXjASniBfDvtK6op\
   \heMgAtB3Q-H4Xq4SECIPygYhjNbsQNkixrKbHrvNBe-TxCd1_T4m9E2YzVZm0B-vgtz\
   \ih8oQoidXWA4HlfDJtU4O-diQnxc7QeVP0zZFTX83aQOKz4YFQRtQuwHILq_BXZJ0qI\
   \isIcskEOVeOcETGJrdKSlQxtxfOPEf8zL3eUKnZrpq_66IFQGdSqer-pmCpIakTGe9v\
   \Z3GN1I7z7eiGEOJ7_XRhV1Qy0vUp4-ivE4W811eyH_Gfytuj332NtQd8Nw4u6L4Jh3y\
   \URCCtA7MQONEPQXmTS2NIfK2n1qVcGtBSJmSuDFAOvbZcxao4bgZ_YCBm55Y1IcR8LM\
   \v6Dp-MSatk0R2Mo3CBkrVyA9V6yfezXfW4MlSKfiliuIu3OLgX2-ma0VEm6Ix6Czy0s\
   \XjzFiM08SRq040XwfhNox5RgdqEc_3gG4lXSt_DKQqH-2n7DpBAsUTuCdh0fs3WTCgV\
   \LYtljqyAlwzuycmB8z3f937ZN1bkxwCAqG2ccASm5Ksg5N1TW574rIqOREZ1D-S4Eug\
   \fk7YSEqjkylZu-djPU4EECHzI05hibJbOy-8e02Dvgthoy5KJTJdlFBkb5rd8COTVMo\
   \cueqVs8c42LGTBOC8d9Fy7qiwVikg4aERNRVVO-Oh0yo_LJTfD_7fZnTyscuqkRajMj\
   \pD8sF5w09LtK0y9MMNdi4v9j0Oqo0YwxWh-9iM4i2FqLLC9j-erur1O3xwP3KsTg9En\
   \E8Gle6RVZJKdS_IQfSy6Y85M2yGRRUkfdeVCFPQNFSM3vY6e3tywcJHJjZr2BPleyST\
   \BNMvZb3pEDBhNycr0HHTnu2a50HEufel1pj4goFrFAyKPDRE3FrYbQGafVaT3y__n2B\
   \MjIvxEueIpuZwBa3MiV2TEvuiAYQ_K8aIZNYVS7mWBigzBWgKDFBqBTtwUWwaUvTMYK\
   \nPYijJ2XeBgKk6Jephx3NvZESnkYEU5nYnEtNotOQWO-9KZbzyPynWlP9GzD5N9mwnV\
   \uYpe1fsTSebEwha9vsqj3sJuCrILzkJNnCofNby2SkoTJ_TGycNlYFQdVy1hvFU7jKH\
   \qBpTF2etgz_o6LJtitCbmKS0_fkvWsGstxyoOmmHBKY02eqcwWtJlUoaKZmAtn10cax\
   \fm8uxUY5UG-yEAqbny55ThLVB-jxreJrc614tK4niXZpPbTHNKfWswXbCjOsFAy3Fyr\
   \rYsLJPkIbSCbeoU-Ftjn_7kCMnKDUkk0bI8HfMyFMdYQ-nZRt0TIcjN_kXnE92qFoBl\



Prorock, et al.           Expires 23 April 2023                [Page 56]

Internet-Draft           post-quantum-signatures            October 2022


   \fzQmzRQyZREuwz2-dXdw2B_AlOri3Mey2sf61x5fB8WML7i01umB8VZ7Cr5GecsLiEC\
   \1fewgwIKJcxlhumWBMblgpJ7CaXmFBEn_W7dTAbosjrpXHJhnw4JbniZgvb4zFFLXz5\
   \hCv-v70o0uhxca36cEwIiBDIPTbFYpvqUwYEMwFN3d246Ma4-23XDoV6S5lk62TSZaS\
   \Y39_3j8lAkhVQDUn-19WECv06kjF7SgJoSWtRXV9UMuk38MXlU9AKbkgeK6JrLjl6hX\
   \M8RWXoO6TNuXJ6gL1HwgG-hIctTkkwUQywnqe9Nh6MrO1jFYDmn43YTogkamC3nMqHO\
   \Ot8Nq6EfdPxOxsmTq-ADjt4NjsRnrhNNOu3MjCzUEFZGhNOykpeOfSqWI7sWyYMbMen\
   \5YqnnGh9UWzb1BK_TiG-jH6tFhpABVr7OCEjnVIIDjSLMdEwl46TB32pWPoyH9zxyle\
   \Gp8QSEJcWAdMVLibE1kIJZno95tbyVtSuiMa3eTr3w9izk0c1iNA3AJWezBSqvI4Q8A\
   \5q3w3vE5AJmK2Yng6HAW3p-gjRYEQHzKs8zlpg_r5eQi0uulks5zBZRJqquHnLMeCf_\
   \JKRUpHBwZ9r0Gd7FbHaiNPzZtyzBjqEjOCfbLp6BBXhqQ366gwNwTcLgh2aM0U6L-mK\
   \4FiYN_S7SjNtDnBIgLVpPPwIlPHNCSdwGaLTobR_Un2xXW8y382CF98ViaieTGysigI\
   \6mrDsZ26HYWqvr2q93afswz9jW4daIsAyjgLV-oM6w7u85nZKyyxLa9nIwAlNuw77D0\
   \YRY7ez-RMiJf8XJGOkxyUxDb4CW3iSPNqg5YXPzIuBsVXAHcds-IgLzvxWDViit6g2v\
   \KVBOE_hxGkd4oME2TMAd6fZP5QF2vzcnFOAGBp3H9WzpIU2dwRrMpKq2dGJDlWBPjMx\
   \3Jkj-Y3O8Qp-QkNXxe29OSDGgDmhbDc46WmSwLC3ApdiWxUF6qKTSujWMzSkr9eEVrE\
   \rO8PWDrqBXHPueYPTCZ9A0J4SSGPt_ARI3WKRzc_VyDNJV4PTp3O8IK_qRh8Aok3SCD\
   \YQM21pt29__-AWaCt5lwsgb4L7no5F8jvmzhbLnCpZaHkAC6Byt6gUDCJf297FN03r6\
   \H35rG1X-O6KQLh_3dpOBUehE725405XrnhG2crIBX1XoAkZRbfyuoZgOsxv-aGvmDLD\
   \koa05R9AOpK_LIUg9hM4uyU95JA7KN4wUtjHvc8BM7I3sWNxk4XIUwRGNY-TlwXE19o\
   \OSf2Dz6X9dbLHbCPKd1KzyPF3SRhN7FivY9DPJXCl95KEZcLRf72-VMLNkn2drA8JeH\
   \yHmRHyHoU9xC0Nd-XVf08liELyvafkTHf8C5WbRwPYLPTU0KceUaPzGEcwQ7hXOFE7K\
   \i2ST2YTSU-1Txg-c3lD88pxNys9BTgq30jwTr_vbEJCxJrgeFUBsqAV3Ljvpq_AT1_8\
   \ur2eY87AzKnfaVXiBhuAVIdNBev2gdSsC7vi3yN9qqBxqXh1LUOsgHbmV9_1KWmIXs_\
   \G4r7TmYIvhKTovaup3H4IvP36imfJPhGso40-WqsONOyzQ594C_XlQPaVW5GSACQATx\
   \IgxhD-WIl9ohZ5mm3XLDpHAxCUu3ruUO1VTtwbp7bS0PbHYoClqdjLMSjwmNdWLyaY1\
   \Z6-OBjlNcRM2Yjh7e_YRRtWd7Esslf1AJrX8LfBj_gKD_OeUfcy6jYKu6qL9eMn3ATQ\
   \PSSxNYzIyWVFgNeVjzLwBuo7q414aomVP0PdlpI3VKQqGBhcJP_eq08UqD6hwxlnGrL\
   \sX7B4bF0Tn6Fr2Q0CxoXv2gHjH-95yFbF08ai1oV59IU3wrrAkFBF7yHpYA5M3Q2tAX\
   \wju3DWKxuKSiEjFblcxjokhRPe-7MLH6E-WBUklf2HvU0v7zNsm9eBMfhKDQJR8XCM4\
   \YMcs01P57ggcoW_Tkfk66fymtg3LCRpJ4IVYuLmbqVUVzS2FJiBTiASG9sXgKsmMuJL\
   \6TrgoEI5yHq-KXBqKz8R2vVC4zYxPnLm46mSzYaKnfDoha5KawNO6Z1DjXTN0Bdr19U\
   \2yoGOEJwDcfGfswqeEyGJPHExQJ5ssu65LPMHBmco95R6xqLMWkGGiEkFNMMlq_T8-x\
   \GZiL9VA8WDHpMtVGMynFBYnTLSXjrxQG7Qwq69OGzkTKuBx8i8_mrN4Z2SYwR5JfEUi\
   \NS5XRnVHF-zaNIgKzZzkh4SYAeiPGSl2r-Os5ayVP7ju02Bioz0sCvLKa2ZZhP6BDlC\
   \KrgIe9k-wWOrGaijui3vgMLtK0IUDJlar6TTbPiNmpT29o87ATtuvjz-rGSrBwGWjum\
   \1_lGxk1y9o_KSCACvBQDxVj9tWqsQt28Si2KpcDdBG3ZlkjzzX42NwD_CgYZO8Rq9oG\
   \aEELXGEaEVUvfvXDo-ziVFNtBUD81w-qG6YutK3zxhQ1SHPl2NmEH7C6gXIg2BpdQug\
   \kxHFOkJaoe-87OiGIIgJStc_RHYeg_pgckz1pihA0uvIC1hHmkICCfDw_MTAmhhiLHB\
   \VAAZ4qyp3YG12xXJ5MlTPOf1-ylTsFXxo6eviH-zcfq-B3CdMDH9GGngVcLMDC0NRuu\
   \5Y6Z6a4B4wFeOc_GlgABg2IJuve99AcfsTcYQep1PcB_nQBnuO9pPEHP2Z6KeClEdEF\
   \05Ar1w0zh58a_gLyqfF5By024x-lnBUotaLDnUF6rV1JXSnVPqwV-7P1n7fBqrrIFdQ\
   \9ojrIe0cwI0jt_nj5YdcO9aqS3SveOl22prjPjo1GAxAb0V2oPVqTQEhAtzA68LiHjz\
   \pGgt7AuRaQCOR3Jo7yDc27XJlq7PK9UEWfx-MzdCG6ehtFcpnPxgqs4KbSZEJD_hsoq\
   \JkfEAP3cO8vCUECB_dVjQj5zXCqeHwMd15ue8ATLdJMAla6kQ9uD_GeUTghiDVOk3Qx\
   \Wjy1qwKUOgodkRpdOfW8npNDH4l8s3GixQ6LBn8b47iVyKIMPl2pICdz747h1MgQv2W\
   \r3y_97DysfbghM-iewTKOI-JaRcPVf0eH9ZAWORTVq9P6QXUVFcmUxTB3-4K_kWQykU\
   \1aIPerjVGo_ooju2yty1-1CtInuvLMzl7dxfsHu4OZ6AS5Fh9OaNkhPHfzAUw9D43ZJ\
   \KnGibhxaxFpbhie4Sf9p51kDBP_NoA_AVfS-jG7WXvpBbwAmJeeDlyeXcZBwFyW0HXc\



Prorock, et al.           Expires 23 April 2023                [Page 57]

Internet-Draft           post-quantum-signatures            October 2022


   \PRFhkodNhviOffaj8px5KpxMAI4qgxdSrL27C4pmlZ56NWMvuBA6So0BkOzGeXyNKyh\
   \p9ehEDcyKVgIToZcdy09EA4nOUl6CnVATCX9G13tfELJqcOx530SMQMLj0KX9jdYC-i\
   \YPBpBhMfbjFp5h7zFg7lP5agqXAqxOB5enrD1uIHfgjaoKMptEBIPb2vP7q21_pJkPY\
   \UJBAa_bsXyNjlJrU2ds6VL42aqzBd9fwk6gLJLTxXzz_w5vJAbI4laktZLu337e0tSt\
   \6zviSwdJ-z7az18F46Q1l2H6nUi3Mcpv0dU9A-6WokWHZB7Tm8v6xmImfShdvpZzZDl\
   \2_p3mwxiK8j0GuMiS6kD8Lognv-wwSvX7w6NCC2spzTofbbeDh6h_-AGXr0sxq__XCZ\
   \rqQebAqo2w6KiUimp6HOPD19yOzuDj187W3_pE39TZyQgRu4OKXrph6hURGevqf2udj\
   \9Vk4aPtk3sm-bGLD65z-qMfDvUwKqve1utKi8le0oTqDiVT92KgG4uTdbLdNZAOyCoN\
   \YVLNCm-IBGAmS4pHqdbsz-p77MNdanXVQgPyLRZzxy5CKPQvgTUoi8Y9CcBa9dhxN9_\
   \M88jIlJs1282BB05dYJVnYupsEhx_HBENzOpCEF2coLEZPEmy6CFLEtEgtq9k4Soq3h\
   \AEpFlN_nd3RBqv0M4Q4Uve5egNMr3RHghbJsovrs1bHdNDHjZ7xsacW_aSlyEuIyvDa\
   \jCLsl-GTDqb1rbarlV55zamBekyFYZzP6Demcoi7jWSlZmvvlThpZCCXtJF2n_7ozxx\
   \f-L9Boi29Cx0fsiJ5z36xhOReXVpyWw4xkMJ2ybt_zt9XqsmVZ4v3RunJ025PjWcd80\
   \hND6H1w2O0GqsUrQ8kFwwEIVS95oFXQ2ZTtaTp-XO7Dz9pTmF1pnHnefFTK4tC6SUF7\
   \dvpFiUsYU8bwI-Zwix9S7Boeksx43NOBtGxBr3l-1WBr4qx4JLxcXptoT-vqaeRnix4\
   \0kpBgxBfWvkr5w9pZ5AbL4wl42nLnTw33K6mqdW1DxVQNDTTmBuX6CjI1tTlxw8QdF9\
   \KnESRSNp-d-2O0AvDcYgDCHSr7flegjQqQIQ7Nk9CJWXzFXp6vC7-bYAAGjhkabSFev\
   \P97o-eIzfVDZZd3hp9IgnF2heMtZb9BAzy0R_XJ5W0H7tK_B9VWfrghJ9wGhQ51e77-\
   \o67okVQ8iwSkiSrs0_njVroSrvb563wy5N-SGnbA0-V4AYeDyteZ2RTdr7ouzihoU7j\
   \OHERvWFGpegIDyUOKJ4rj9_W9XznUlnzHjmIX47Wfybdn0fU3N-j9f9ZsT9YYfBSudX\
   \Woa12F8ngJc8QT6zBmnCysBwRTlcjfZdWJTaLDC0gMRXezq59U1ahXKvYwlnXiWV5Sm\
   \hiR2NpT2lKVFVFaEpUa05US3kxVFNFRkxSUzB5TlRaekxYSnZZblZ6ZENKOS5PVEE0T\
   \ldReVltVm1Oamt5T0RaaE5tTmlZalV4TmpJell6aG1ZVEkxT0RZeU9UazBOV05rTlRW\
   \allUY3dOV05qTkdVMk5qY3dNRE01TmpnNU5HVXdZdw

9.  Normative References

   [CRYSTALS-Dilithium]
              Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V.,
              Schwabe, P., Seiler, G., and D. Stehle, "CRYSTALS-
              Dilithium: A Lattice-Based Digital Signature Scheme",
              2018, <https://doi.org/10.13154/tches.v2018.i1.238-268>.

   [Falcon]   Fouque, P., Hoffstein, J., Kirchner, P., Lyubashevsky, V.,
              Pornin, T., Prest, T., Ricosset, T., Seiler, G., Whyte,
              W., and Z. Zhang, "Fast-Fourier Lattice-based Compact
              Signatures over NTRU", 2017, <https://falcon-sign.info/>.

   [RFC2119]  Bradner, S., "Key words for use in RFCs to Indicate
              Requirement Levels", BCP 14, RFC 2119,
              DOI 10.17487/RFC2119, March 1997,
              <https://www.rfc-editor.org/info/rfc2119>.

   [RFC4648]  Josefsson, S., "The Base16, Base32, and Base64 Data
              Encodings", RFC 4648, DOI 10.17487/RFC4648, October 2006,
              <https://www.rfc-editor.org/info/rfc4648>.





Prorock, et al.           Expires 23 April 2023                [Page 58]

Internet-Draft           post-quantum-signatures            October 2022


   [RFC7515]  Jones, M., Bradley, J., and N. Sakimura, "JSON Web
              Signature (JWS)", RFC 7515, DOI 10.17487/RFC7515, May
              2015, <https://www.rfc-editor.org/info/rfc7515>.

   [RFC7517]  Jones, M., "JSON Web Key (JWK)", RFC 7517,
              DOI 10.17487/RFC7517, May 2015,
              <https://www.rfc-editor.org/info/rfc7517>.

   [RFC7638]  Jones, M. and N. Sakimura, "JSON Web Key (JWK)
              Thumbprint", RFC 7638, DOI 10.17487/RFC7638, September
              2015, <https://www.rfc-editor.org/info/rfc7638>.

   [RFC8702]  Kampanakis, P. and Q. Dang, "Use of the SHAKE One-Way Hash
              Functions in the Cryptographic Message Syntax (CMS)",
              RFC 8702, DOI 10.17487/RFC8702, January 2020,
              <https://www.rfc-editor.org/info/rfc8702>.

   [RFC8812]  Jones, M., "CBOR Object Signing and Encryption (COSE) and
              JSON Object Signing and Encryption (JOSE) Registrations
              for Web Authentication (WebAuthn) Algorithms", RFC 8812,
              DOI 10.17487/RFC8812, August 2020,
              <https://www.rfc-editor.org/info/rfc8812>.

   [SPHINCS-PLUS]
              Hulsing, A., "Sphincs+ Stateless Hash-based Signatures",
              2017, <https://sphincs.org>.

10.  Informative References

   [RFC6234]  Eastlake 3rd, D. and T. Hansen, "US Secure Hash Algorithms
              (SHA and SHA-based HMAC and HKDF)", RFC 6234,
              DOI 10.17487/RFC6234, May 2011,
              <https://www.rfc-editor.org/info/rfc6234>.

Authors' Addresses

   Michael Prorock
   mesur.io
   Email: mprorock@mesur.io


   Orie Steele
   Transmute
   Email: orie@transmute.industries


   Rafael Misoczki
   Google



Prorock, et al.           Expires 23 April 2023                [Page 59]

Internet-Draft           post-quantum-signatures            October 2022


   Email: rafaelmisoczki@google.com


   Michael Osborne
   IBM
   Email: osb@zurich.ibm.com


   Christine Cloostermans
   NXP
   Email: christine.cloostermans@nxp.com








































Prorock, et al.           Expires 23 April 2023                [Page 60]