Hash-based Signatures: An Outline for a New Standard Andreas Hülsing∗, Stefan-Lukas Gazdag†, Denis Butin‡ and Johannes Buchmann‡ ∗Department of Mathematics and Computer Science Technische Universiteit Eindhoven P.O. Box 513, 5600 MB Eindhoven, The Netherlands
[email protected] †genua mbh Domagkstrasse 7, 85551 Kirchheim bei Muenchen, Germany
[email protected] †TU Darmstadt Hochschulstrasse 10, 64289 Darmstadt, Germany {dbutin,buchmann}@cdc.informatik.tu-darmstadt.de Abstract. Hash-based signatures are quantum- and runtimes, present security reductions, present safe and well understood. This paper presents an implementations, and finally lower the security as- outline for a new standard extending the recent sumptions on the used hash function, i.e. provide Internet-Draft by McGrew & Curcio. The goals of this new standard are twofold: collision resilience. • To extend the existing draft to include XMSS Recently, McGrew and Curcio published an and its multi-tree version; Internet-Draft [19] for a hash-based signature scheme. • To prepare for possible extensions to cover stateless schemes. Their draft essentially covers the scheme proposed by Merkle at the end of the 1970s. The advantage Keywords: Hash-based signatures, Standard- of this scheme over newer ones is that Merkle was ization, Merkle trees, XMSS. granted a patent on this basic scheme that already expired. Hence, there cannot be any IPR claims for I. Introduction this scheme. However, to the best of our knowledge, there are no active or pending patents on XMSS and Hash-based signatures recently gained a lot of its variants. On the downside, the scheme in [19] has attention as a potential replacement for today’s large signatures, relatively slow runtimes compared to signature schemes when large-scale quantum com- other alternatives (especially for key generation), an puters are built.