Skip to main content
Quantum-safe signatures

Sign today what must still verify after 2030

Releases, firmware, contracts and licences are verified for years after they are signed. QuantumLock adds ML-DSA signatures to them now, alone or next to the classical signature your verifiers already check.

Algorithm
ML-DSA (FIPS 204)
Modes
Post-quantum or hybrid
Interfaces
REST API and Python SDK

The problem

A signature is a promise that has to outlast its algorithm

When RSA and ECC can be broken, a forged signature on a new release looks exactly like a real one to a verifier that still trusts those algorithms. Artifacts with long lives, such as device firmware, signed documents and software licences, need a post-quantum signature before that day, not after it.

  • Your files stay with you

    You hash the artifact locally and send only the digest. QuantumLock never receives the file.

  • Hybrid keeps today's verifiers working

    The classical signature stays in place while the ML-DSA signature is added beside it.

  • One service for signing and licensing

    One service covers artifact signatures and licence validation.

Fig. 02 · Long-lived trust: Seal · SHA-512 hash chain

How it works

From artifact to verified signature

  1. 01

    Hash locally

    Compute the digest of the release, firmware image or document on your own systems.

  2. 02

    Request a signature

    Send the base64 digest to QuantumLock and choose post-quantum (ML-DSA) or hybrid (classical and ML-DSA).

  3. 03

    Distribute

    Ship the signature with the artifact, as you do today.

  4. 04

    Verify

    Verification of a hybrid pair succeeds only when both signatures verify.

Options

Choose the mode that fits your verifiers

OptionWhat it doesWhen to use itStage
Post-quantum signingSigns a digest with ML-DSANew artifacts whose verifiers already accept ML-DSAIn production
Hybrid signingSigns a digest with a classical key and an ML-DSA key; both must verifyDuring the transition, while some verifiers still expect a classical signatureIn production
Hybrid licence validationValidates a software licence under classical and post-quantum rulesLicensing that must move with the rest of the estateIn production

ML-DSA in QuantumLock comes from liboqs. It implements the FIPS 204 algorithm and is not CAVP-validated.

Questions

Signing questions buyers ask first

Does my file leave our network?

No. You send a digest, not the artifact. QuantumLock signs the digest and returns the signature.

Why hybrid instead of post-quantum only?

Hybrid lets verifiers that only know classical algorithms keep working while you add post-quantum protection. A forger would have to break both schemes for a hybrid pair to fail.

Is the ML-DSA implementation validated?

QuantumLock uses ML-DSA from liboqs, which is not CAVP-validated. If your policy requires a validated module, raise it before procurement.

Where do I start if I do not know what we sign today?

Start with a cryptographic inventory. It shows which systems rely on quantum-vulnerable signatures.

Sign one artifact with us

Bring a release or a firmware image to a demo and leave with a hybrid signature and a verification you can repeat.