Post-Quantum Inference · ML-DSA-65 · FIPS 204 · Patent Pending · Filed 2026-05-08

Inference receipts with post-quantum signatures.

smshPQTM brings ML-DSA-65 signed statements to pilot inference integrations. Retained operator envelopes pass local lattice-signature checks. That authenticates signed bytes, not model execution or every call in a workload. Validate the selected endpoint, trusted key and capture path before relying on a deployment.

Illustrative fee$0.00018
·
IntegrationPilot
·
SchemeML-DSA-65
·
AnchorSeparate
·
Raw signature3,309 B
Integration targets OpenAI Anthropic Google Kimi Manus vLLM SGLang Self-hosted
Cryptographic migration · Authenticity and confidentiality

Post-quantum signatures and content protection

A sufficiently capable quantum computer could undermine Ed25519 and ECDSA authenticity by enabling forgery. Existing signatures do not universally stop verifying in a particular year. ML-DSA is designed for post-quantum authenticity, not encryption. Harvest-now-decrypt-later concerns encrypted content and key establishment, which a signature alone does not protect. NIST FIPS 204 defines ML-DSA.

Property
smshPQTM
Classical-signed railsEd25519 / ECDSA
Unsigned inferenceToday's default
Signature scheme
ML-DSA-65 (lattice)
Ed25519 / ECDSA
None
NIST FIPS status
FIPS 204 finalized · Aug 2024
Pre-quantum standards only
n/a
Deployment acceptance
Endpoint and key specific
Endpoint and key specific
No signature acceptance
Quantum forgery posture
Designed for post-quantum resistance
Vulnerable to a sufficiently capable quantum computer
No signature integrity
Content confidentiality
Requires separate encryption and key management
Requires separate encryption and key management
Depends on the encryption layer
Sign latency
No accepted deployment benchmark
Implementation and hardware dependent
No signing operation
Raw signature size
3,309 bytes, excluding receipt fields
Ed25519: 64 bytes; ECDSA varies by curve and encoding
No signature; record size varies
Audit-log lifetime
Depends on preservation, trusted keys and migration
Depends on preservation, trusted keys and migration
Other audit evidence may exist
Measured bytes
3,309 raw bytes, 4,412 base64 characters per signature. FIPS 204, Table 2 specifies the raw size. On 2026-09-05, three retained afir.attestation / 1.0.0-typed-pq artifacts measured 11,532, 76,325 and 22,232 bytes as stored complete JSON bundles. Their compact envelope objects were 8,057, 8,057 and 10,865 UTF-8 bytes; compact {envelope, fragments} verification bodies were 8,495, 8,495 and 13,950 bytes, including encoded signatures and keys but excluding HTTP/TLS overhead. These are sample-specific measurements, not a fixed product receipt size. The former 384-byte claim had no matching wrapper, digest-only object or amortized artifact in the reviewed implementation.
Calculator · Your workload, your numbers

Compare your current costs with a modeled alternative.

Estimate cache and routing effects using your assumptions, not guaranteed savings. Routing applies only to traffic left after caching. The model assumes uniform tokens and cost per call, full inference-cost avoidance on cache hits, and one receipt per original call. Add cache serving, selection, retries, storage and other monthly operating costs below. One-time implementation cost, taxes and quality changes are excluded. Confirm pricing and workload quality in a pilot.

Modeled annual net benefit N/A
Net / added cost N/A
Scenario outcome N/A
Monthly receipts N/A
Pick your scale
your number, or pick a scale above
e.g. 800 in + 400 out
e.g. $3.50 blended
assumed share of original calls; validate eligibility
after cache hits; quality must be evaluated separately
illustrative assumption, not measured performance
illustrative rate; replace with your agreed price
cache, selection, retries, storage and operations
Current state Today
Monthly tokensN/A
Monthly inference spendN/A
Cache cost avoidance$0
Routing cost reduction$0
Other added costs$0
N/A
Annual modeled cost · baseline
With smshPQ™ Scenario
Monthly tokensN/A
Monthly inference spendN/A
Cache cost avoidanceN/A
Routing cost reductionN/A
Other added costsN/A
smshPQ™ receipt feeN/A
N/A
Annual modeled cost · with smshPQ™
Modeled annual net benefit: N/A · Net / added cost N/A · N/A
Three integration uses · One signature primitive

Check the evidence behind each claim.

A signature authenticates the statement the signer made. Cache eligibility, routing quality, payment status and model execution need their own evidence. A receipt helps preserve those assertions without making them true by itself.

01 · Cache evidence

Record a reusable result.

A matching digest can bind the exact inputs defined by your cache key. Safe reuse also depends on model version, parameters, freshness and authorization. Payment requires a separately bound settlement record.

Measure hit rate and serving cost in your workload
02 · Routing evidence

Preserve the declared model and route.

A signed model identifier is the signer's assertion about the model. Stronger execution claims require an identified provider or hardware attestation and verification of its binding to the call. Compare answer quality and full routing costs separately.

No model-execution proof from an ID alone
03 · Audit support

Preserve checkable statements for review.

Signed receipts can support an audit alongside access controls, capture monitoring, retention and recovery evidence. A digest can limit content disclosure but does not encrypt data or establish regulatory approval.

No automatic approval or utilization increase
How it works · Integration sequence

How the selected evidence is captured and signed

The reviewed typed signer places a full base64 signature in envelope.envelope_signature. It signs a 32-byte digest binding base envelope fields, the selected-fragment aggregate root and policy digest. The retained artifacts use linear aggregation within each envelope, not a detached or shared signature across inference calls. Verification needs the envelope, canonical fragment inputs, exact digest framing, ML-DSA-65 implementation and an independently trusted public key. See endpoint capabilities.

01 · Call
Inference runs
Capture the fields your integration can actually observe. Test capture failures and identify any missing records.
02 · Hash
Canonical SmSH
Canonical fragment digests and their aggregate bind selected content. Unattested fragments and external data require separate checks.
03 · Sign
ML-DSA-65 PQ
The reviewed signer uses software Node on Render in Oregon. No deployment latency or HSM claim is made here.
04 · Verify
Signature, then anchor
Local signature checks need no chain. Any anchor is separately selected and specified. Submission, preconfirmation, inclusion and finality are distinct; a USDC payment alone is not anchoring evidence.
Pilot scoping · 20 minutes · NDA available

Estimate costs for your workload.

Bring call volume, model mix and non-sensitive workload requirements. Scope capture coverage, cache eligibility, routing quality, storage and verification tests before sending production data.

Book the pilot scoping call
smshPQ™ · Patent Pending · Filed 2026-05-08 · signed off-chain and verifiable offline; any chain anchor must be separately selected and specified

Reported benchmark records: smshPQ + smshPQMax

The cards distinguish live service records from bundled fallback data. A metric that rewards signature presence against an unsigned baseline demonstrates a feature, not competitive performance. This display does not authenticate the issuer or reproduce the run. Read the methodology and limitations.