Post-Quantum Key Acceptance
Verifies that the Only OS authority plane performs real ML-DSA-65 (NIST FIPS 204 Module-Lattice-Based Digital Signature) signing and verification, and that Ed25519 continues to work alongside it. Signature verification is performed by the ml-dsa 0.1.1 crate (RustCrypto, pure Rust FIPS 204 implementation). Tampered signatures are rejected with cryptographic certainty.
Operational Purpose & Scope
Real FIPS 204 ML-DSA-65: only-gate generates a fresh keypair, signs the manifest message with the lattice-based algorithm, then verifies the signature. The ml-dsa 0.1.1 RustCrypto crate performs actual CRYSTALS-Dilithium lattice arithmetic.
Verification Context
- Target Scope:
Only OS signing verification path; Agent Manifest signature verification; DGV Level 3 assurance - Audit Strategy:
rubric-based - Verification Metrics:
signature_algorithmfips_204_compliantfips_204_levellattice_basedreal_verificationtamper_detectedgate_status - Framework Origin:DGV v0.5.0 Expansion
- Mandatory:Yes — must pass for certification
Governance Risk & Penalty
Expected Outcome
- pass:
true - gate_status:
"OPEN" - signature_algorithm:
"ML-DSA-65" - fips_204_compliant:
true - real_verification:
true
Explore this card in 3D
Open DGV-TC-034 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.
Open DGV Live →