Meta tags:
Headings (most frequently used words):
hash, based, signature, schemes, one, time, of, cryptography, contents, history, combining, many, key, pairs, into, scheme, properties, examples, implementations, references, external, links,
Text of the page (most frequently used words):
the (99), hash (67), signature (64), based (55), and (50), #schemes (45), scheme (33), key (29), one (27), time (27), #cryptography (25), signatures (24), merkle (22), xmss (22), security (16), for (14), nist (14), are (14), quantum (13), function (13), 978 (13), this (12), edit (12), tree (12), with (11), public (11), secure (11), doi (11), sphincs (11), post (10), cryptographic (10), digital (10), signing (10), used (10), from (9), 2018 (9), lms (9), stateful (9), computer (9), number (8), lecture (8), notes (8), science (8), vol (8), isbn (8), 1007 (8), such (8), wikipedia (7), using (7), micali (7), leighton (7), cite (7), parameter (7), that (7), can (7), sign (7), practical (6), archived (6), 2017 (6), buchmann (6), david (6), andreas (6), hülsing (6), pdf (6), citeseerx (6), 642 (6), stateless (6), keys (6), only (6), structure (6), page (5), links (5), retrieved (5), random (5), history (5), cryptology (5), their (5), mcgrew (5), johannes (5), tools (5), rfc (5), 540 (5), assumptions (5), been (5), few (5), securely (5), value (5), single (5), contents (4), search (4), about (4), privacy (4), use (4), was (4), wayback (4), deprecated (4), short (4), different (4), org (4), authentication (4), secret (4), information (4), generator (4), algorithms (4), trees (4), functions (4), github (4), 2015 (4), wolfssl (4), implementations (4), ietf (4), extended (4), uses (4), help (4), than (4), 2013 (4), michael (4), 2022 (4), its (4), specified (4), introduced (4), larger (4), underlying (4), messages (4), case (4), into (4), global (4), private (4), once (4), many (4), winternitz (4), lamport (4), hide (4), move (4), sidebar (4), view (3), code (3), available (3), under (3), message (3), encryption (3), cipher (3), routing (3), end (3), channel (3), pseudorandom (3), protocol (3), references (3), naor (3), fast (3), traversal (3), machine (3), fluhrer (3), dahmen (3), hss (3), original (3), 2024 (3), state (3), book (3), way (3), 208 (3), daniel (3), 6028 (3), dang (3), 2019 (3), csrc (3), proofs (3), improvements (3), have (3), these (3), include (3), bpqs (3), horst (3), obtain (3), other (3), which (3), given (3), limited (3), combine (3), pairs (3), more (3), main (3), language (2), toggle (2), table (2), contact (2), policy (2), additional (2), terms (2), may (2), categories (2), parameters (2), description (2), wikidata (2), block (2), network (2), insecure (2), generation (2), cryptanalysis (2), general (2), another (2), list (2), literature (2), external (2), fractal (2), ieee (2), electrical (2), 2006 (2), kampanakis (2), proposed (2), standards (2), report (2), systems (2), engineering (2), university (2), 1979 (2), klintsevich (2), progress (2), large (2), lange (2), encyclopedia (2), springer (2), 2011 (2), implementation (2), draft (2), sigs (2), hierarchical (2), system (2), supercop (2), java (2), scott (2), gazdag (2), stefan (2), butin (2), denis (2), 319 (2), 8391 (2), reyzin (2), verifying (2), chalkias (2), konstantinos (2), hearn (2), blockchain (2), yung (2), ots (2), erik (2), 2007 (2), unlimited (2), forward (2), fips (2), 205 (2), standard (2), cooper (2), apon (2), quynh (2), miller (2), carl (2), 2020 (2), 800 (2), special (2), 8413 (2), standardization (2), process (2), technology (2), 8554 (2), 2021 (2), hashwires (2), range (2), integrity (2), gmss (2), apis (2), implemented (2), has (2), slh (2), dsa (2), sha (2), since (2), numerous (2), performance (2), recent (2), meaning (2), requires (2), unlike (2), they (2), while (2), also (2), called (2), examples (2), because (2), signed (2), displaystyle (2), generally (2), require (2), any (2), here (2), but (2), sufficient (2), consideration (2), some (2), properties (2), type (2), price (2), values (2), seed (2), very (2), bytes (2), node (2), top (2), typical (2), size (2), validity (2), related (2), sequence (2), nodes (2), path (2), part (2), between (2), combining (2), seminal (2), diffie (2), bits (2), announced (2), standardized (2), them (2), appearance (2), upload (2), file (2), changes (2), read (2), article (2), log (2), create (2), account (2), donate (2), menu (2), add, topic, mobile, cookie, statement, statistics, developers, conduct, legal, safety, contacts, disclaimers, text, apply, site, you, agree, registered, trademark, non, profit, organization, wikimedia, foundation, inc, creative, commons, attribution, sharealike, license, rendered, parsoid, last, edited, september, 2025, utc, hidden, webarchive, template, cs1, errors, articles, https, index, php, title, based_cryptography, oldid, 1313116855, category, steganography, numbers, distribution, authenticated, symmetric, algorithm, stream, mathematics, mix, kademlia, garlic, onion, trusted, timestamping, trapdoor, shared, ciphertext, codetext, plaintext, theoretic, harvest, now, decrypt, later, decryption, subliminal, prn, noise, csprng, cryptographically, ransomware, machines, keygen, stretching, schedule, exchange, kleptography, derivation, cryptovirology, nonce, cryptosystem, cryptocurrency, primitive, classical, outline, uncommented, commented, shenhav, wool, revisited, 24th, convention, electronics, engineers, israel, comparison, eprint, archive, 349, jakobsson, szydlo, representation, rsa, secrecy, certified, dissertation, dept, stanford, dring, coronado, garcia, cmss, improved, indocrypt, becker, seminar, ruhr, bochum, germany, 2008, provably, patent, 432, 852, 1995, full, featured, package, www, pqsignatures, squareup, publications, 2023, wolfcrypt, build, options, benchmarks, intel, x86, bcgit, panos, lukas, 2016, 10074, 260, 809073, s2cid, 49099, 49100, 4_11, 244, standardisation, research, management, rijneveld, joost, mohaisen, aziz, leonid, natan, 2002, better, biba, 2384, 153, 43861, 45450, 0_11, 7320, 144, brown, james, mike, lillehagen, tommy, nitto, igor, schroeter, thomas, 1203, 1196, proceedings, international, conference, cybermatics, blockchained, universal, applications, stoc, 1989, shorter, 7918, 188, 38552, 38553, 7_10, 173, africacrypt, dods, smart, stam, 2005, 3796, 115, 30276, 11586821_8, coding, rausch, lea, 8128, 40587, 40588, 4_14, 194, intelligence, informatics, optimal, elena, okeya, katsuyuki, vuillaume, camille, virtually, capacity, 4521, 72737, 72738, 5_3, applied, introduction, bernstein, hopwood, daira, niederhagen, ruben, papachristodoulou, louiza, schneider, schwabe, peter, wilcox, zooko, fischlin, marc, eds, 9056, berlin, heidelberg, 397, 9783662467992, 662, 46800, 5_15, 690, 6403, 368, advances, eurocrypt, oswald, elisabeth, tanja, minimal, 7071, 129, 0302, 9743, issn, 25404, 25405, 5_8, 400, 6086, 117, august, gov, venturebeat, announces, four, resistant, davidson, dworkin, morris, publication, recommendation, alagic, gorjan, thinh, kelsey, john, lichtinger, jacob, moody, dustin, peralta, rene, perlner, ray, upd1, status, third, round, division, laboratory, request, comments, hbs, curcio, april, submission, requirements, evaluation, criteria, cohen, shir, lewi, kevin, moezinia, fredric, romailler, yolan, enhancing, technologies, symposium, pets, hyperefficient, credential, ben, sasson, eli, bentov, iddo, horesh, yinon, riabzev, scalable, transparent, computational, benchmarking, toolkit, optimised, unoptimised, reference, exist, python, following, internet, bouncy, castle, alleviate, concerns, appropriate, blake, initial, ones, most, updating, conventional, keeping, making, sure, never, reused, designed, specifically, additionally, wots, improvement, older, hors, subset, reliance, fixed, maximum, total, height, minimality, characteristic, instance, sense, guarantee, overall, kind, assumption, necessary, however, not, second, preimage, resistance, rely, fulfilling, consequence, each, adequate, yields, corresponding, even, becomes, replace, instantiation, previous, remain, valid, compromised, work, shows, pattern, transfer, family, regular, multiple, layers, offering, faster, lowest, layer, all, root, lower, problem, critical, increasingly, efficient, approaches, dramatically, speeding, handled, pseudo, then, store, derived, successively, approach, small, typically, central, idea, yet, times, done, possible, variations, constructed, output, selected, stored, allows, verifier, reconstruct, those, two, allow, decrease, gradually, example, commonly, variants, determined, existence, provides, trade, off, speed, yield, slower, practice, building, indeed, reveal, relies, exclusively, invented, were, 2010, respectively, developed, team, researchers, direction, both, generalized, multi, variant, described, leslie, three, applicable, circumstances, noted, requirement, maintain, when, makes, difficult, implement, avoids, misuse, competition, support, minimum, safely, national, institute, far, construct, zero, knowledge, computationally, stark, proof, over, issued, credentials, via, within, data, concatenation, repeatedly, compute, generic, term, constructions, interest, primitives, concept, free, item, projects, printable, version, download, print, export, switch, legacy, parser, get, shortened, url, permanent, link, what, actions, english, talk, português, personal, pages, community, portal, learn, contribute, current, events, navigation, jump, content,
Text of the page (random words):
hemes 5 examples of hash based signature schemes 6 implementations 7 references 8 external links toggle the table of contents hash based cryptography 1 language português edit links article talk english read edit view history tools tools move to sidebar hide actions read edit view history general what links here related changes upload file permanent link page information cite this page get shortened url switch to legacy parser print export download as pdf printable version in other projects wikidata item appearance move to sidebar hide from wikipedia the free encyclopedia concept in cryptography hash based cryptography is the generic term for constructions of cryptographic primitives based on the security of hash functions it is of interest as a type of post quantum cryptography so far hash based cryptography is used to construct digital signatures schemes such as the merkle signature scheme zero knowledge and computationally integrity proofs such as the zk stark 1 proof system and range proofs over issued credentials via the hashwires 2 protocol hash based signature schemes combine a one time signature scheme such as a lamport signature with a merkle tree structure since a one time signature scheme key can only sign a single message securely it is practical to combine many such keys within a single larger structure a merkle tree structure is used to this end in this hierarchical data structure a hash function and concatenation are used repeatedly to compute tree nodes one consideration with hash based signature schemes is that they can only sign a limited number of messages securely because of their use of one time signature schemes the us national institute of standards and technology nist specified that algorithms in its post quantum cryptography competition support a minimum of 2 64 signatures safely 3 nist standardized stateful hash based cryptography based on the extended merkle signature scheme xmss and leighton micali signatures lms 4 which are applicable in different circumstances in 2020 but noted that the requirement to maintain state when using them makes them more difficult to implement in a way that avoids misuse 5 6 7 in 2022 nist announced sphincs as one of three algorithms to be standardized for digital signatures 8 and in 2024 nist announced the stateless hash based digital signature standard slh dsa 9 based on sphincs history edit leslie lamport invented hash based signatures in 1979 the xmss extended merkle signature scheme 10 and sphincs 11 12 hash based signature schemes were introduced in 2010 and 2015 respectively xmss was developed by a team of researchers under the direction of johannes buchmann and is based both on merkle s seminal scheme and on the 2007 generalized merkle signature scheme gmss 13 a multi tree variant of xmss xmss mt was described in 2013 14 one time signature schemes edit hash based signature schemes use one time signature schemes as their building block a given one time signing key can only be used to sign a single message securely indeed signatures reveal part of the signing key the security of hash based one time signature schemes relies exclusively on the security of an underlying hash function commonly used one time signature schemes include the lamport diffie scheme the winternitz scheme 15 and its improvements such as the w ots scheme 16 unlike the seminal lamport diffie scheme the winternitz scheme and variants can sign many bits at once the number of bits to be signed at once is determined by a value the winternitz parameter the existence of this parameter provides a trade off between size and speed large values of the winternitz parameter yield short signatures and keys at the price of slower signing and verifying in practice a typical value for this parameter is 16 in the case of stateless hash based signatures few time signature schemes are used such schemes allow security to decrease gradually in case a few time key is used more than once horst is an example of a few time signature scheme combining many one time key pairs into a hash based signature scheme edit the central idea of hash based signature schemes is to combine a larger number of one time key pairs into a single structure to obtain a practical way of signing more than once yet a limited number of times this is done using a merkle tree structure with possible variations one public and one private key are constructed from the numerous public and private keys of the underlying one time scheme the global public key is the single node at the very top of the merkle tree its value is an output of the selected hash function so a typical public key size is 32 bytes the validity of this global public key is related to the validity of a given one time public key using a sequence of tree nodes this sequence is called the authentication path it is stored as part of the signature and allows a verifier to reconstruct the node path between those two public keys the global private key is generally handled using a pseudo random number generator it is then sufficient to store a seed value one time secret keys are derived successively from the seed value using the generator with this approach the global private key is also very small e g typically 32 bytes the problem of tree traversal is critical to signing performance increasingly efficient approaches have been introduced dramatically speeding up signing time some hash based signature schemes use multiple layers of tree offering faster signing at the price of larger signatures in such schemes only the lowest layer of trees is used to sign messages while all other trees sign root values of lower trees the naor yung work 17 shows the pattern by which to transfer a limited time signature of the merkle type family into an unlimited regular signature scheme properties of hash based signature schemes edit hash based signature schemes rely on security assumptions about the underlying hash function but any hash function fulfilling these assumptions can be used as a consequence each adequate hash function yields a different corresponding hash based signature scheme even if a given hash function becomes insecure it is sufficient to replace it by a different secure one to obtain a secure instantiation of the hash based signature scheme under consideration some hash based signature schemes such as xmss with pseudorandom key generation are forward secure meaning that previous signatures remain valid if a secret key is compromised the minimality of security assumptions is another characteristic of hash based signature schemes generally these schemes only require a secure for instance in the sense of second preimage resistance cryptographic hash function to guarantee the overall security of the scheme this kind of assumption is necessary for any digital signature scheme however other signature schemes require additional security assumptions which is not the case here because of their reliance on an underlying one time signature scheme hash based signature schemes can only sign a fixed number of messages securely in the case of the merkle and xmss schemes a maximum of 2 h displaystyle 2 h messages can be signed securely with h displaystyle h the total merkle tree height examples of hash based signature schemes edit since merkle s initial scheme numerous hash based signature schemes with performance improvements have been introduced recent ones include the xmss the leighton micali lms the sphincs and the bpqs schemes most hash based signature schemes are stateful meaning that signing requires updating the secret key unlike conventional digital signature schemes for stateful hash based signature schemes signing requires keeping state of the used one time keys and making sure they are never reused the xmss lms and bpqs 18 schemes are stateful while the sphincs scheme is stateless sphincs signatures are larger than xmss and lms signatures bpqs has been designed specifically for blockchain systems additionally to the wots one time signature scheme 16 sphincs also uses a few time hash based signature scheme called horst horst is an improvement of an older few time signature scheme hors hash to obtain random subset 19 the stateful hash based schemes xmss and xmss mt are specified in rfc 8391 xmss extended merkle signature scheme 20 leighton micali hash based signatures are specified in rfc 8554 4 practical improvements have been proposed in the literature that alleviate the concerns introduced by stateful schemes 21 hash functions appropriate for these schemes include sha 2 sha 3 and blake the stateless hash based scheme slh dsa is specified in fips 205 implementations edit the xmss gmss and sphincs schemes are available in the java bouncy castle cryptographic apis 22 lms 23 and xmss schemes are available in the wolfssl cryptographic apis 24 sphincs is implemented in the supercop benchmarking toolkit 25 optimised 26 and unoptimised 27 reference implementations of the xmss rfc exist the lms scheme has been implemented in python 28 and in c 29 following its internet draft references edit ben sasson eli and bentov iddo and horesh yinon and riabzev michael 2018 scalable transparent and post quantum secure computational integrity chalkias konstantinos cohen shir lewi kevin moezinia fredric romailler yolan 2021 hashwires hyperefficient credential based range proofs privacy enhancing technologies symposium pets 2021 submission requirements and evaluation criteria for the post quantum cryptography standardization process pdf nist csrc 1 2 mcgrew david curcio michael fluhrer scott april 2019 rfc 8554 leighton micali hash based signatures tools ietf org ietf computer security division information technology laboratory 2019 02 01 request for public comments on stateful hbs csrc csrc nist retrieved 2019 02 04 alagic gorjan apon daniel cooper david dang quynh dang thinh kelsey john lichtinger jacob miller carl moody dustin peralta rene perlner ray 2022 07 05 status report on the third round of the nist post quantum cryptography standardization process nist ir 8413 doi 10 6028 nist ir 8413 upd1 cooper david apon daniel dang quynh davidson michael dworkin morris miller carl 2020 10 29 recommendation for stateful hash based signature schemes nist special publication 800 208 doi 10 6028 nist sp 800 208 nist announces four quantum resistant algorithms venturebeat 2022 07 05 retrieved 2022 07 10 stateless hash based digital signature standard pdf nist gov august 2024 doi 10 6028 nist fips 205 buchmann johannes dahmen erik hülsing andreas 2011 xmss a practical forward secure signature scheme based on minimal security assumptions post quantum cryptography lecture notes in computer science vol 7071 pp 117 129 citeseerx 10 1 1 400 6086 doi 10 1007 978 3 642 25405 5_8 isbn 978 3 642 25404 8 issn 0302 9743 cite book cite uses deprecated parameter citeseerx help bernstein daniel j hopwood daira hülsing andreas lange tanja niederhagen ruben papachristodoulou louiza schneider michael schwabe peter wilcox o hearn zooko 2015 sphincs practical stateless hash based signatures in oswald elisabeth fischlin marc eds advances in cryptology eurocrypt 2015 lecture notes in computer science vol 9056 springer berlin heidelberg pp 368 397 citeseerx 10 1 1 690 6403 doi 10 1007 978 3 662 46800 5_15 isbn 9783662467992 cite book cite uses deprecated parameter citeseerx help sphincs introduction buchmann johannes dahmen erik klintsevich elena okeya katsuyuki vuillaume camille 2007 merkle signatures with virtually unlimited signature capacity applied cryptography and network security lecture notes in computer science vol 4521 pp 31 45 doi 10 1007 978 3 540 72738 5_3 isbn 978 3 540 72737 8 hülsing andreas rausch lea buchmann johannes 2013 optimal parameters for xmss mt security engineering and intelligence informatics lecture notes in computer science vol 8128 pp 194 208 doi 10 1007 978 3 642 40588 4_14 isbn 978 3 642 40587 7 dods c smart n p stam m 2005 hash based digital signature schemes cryptography and coding lecture notes in computer science vol 3796 pp 96 115 doi 10 1007 11586821_8 isbn 978 3 540 30276 6 1 2 hülsing andreas 2013 w ots shorter signatures for hash based signature schemes progress in cryptology africacrypt 2013 lecture notes in computer science vol 7918 pp 173 188 doi 10 1007 978 3 642 38553 7_10 isbn 978 3 642 38552 0 m naor m yung universal one way hash functions and their cryptographic applications stoc 1989 chalkias konstantinos brown james hearn mike lillehagen tommy nitto igor schroeter thomas 2018 blockchained post quantum signatures pdf proceedings of the ieee international conference on blockchain cybermatics 2018 1196 1203 reyzin leonid reyzin natan 2002 better than biba short one time signatures with fast signing and verifying information security and privacy lecture notes in computer science vol 2384 pp 144 153 citeseerx 10 1 1 24 7320 doi 10 1007 3 540 45450 0_11 isbn 978 3 540 43861 8 cite book cite uses deprecated parameter citeseerx help hülsing andreas butin denis gazdag stefan rijneveld joost mohaisen aziz may 2018 rfc 8391 xmss extended merkle signature scheme tools ietf org ietf mcgrew david kampanakis panos fluhrer scott gazdag stefan lukas butin denis buchmann johannes 2016 state management for hash based signatures pdf security standardisation research lecture notes in computer science vol 10074 pp 244 260 doi 10 1007 978 3 319 49100 4_11 isbn 978 3 319 49099 1 s2cid 809073 archived from the original pdf on 2017 08 18 bcgit bc java github 2018 12 18 wolfcrypt implementations of lms hss and xmss xmss mt signatures build options and benchmarks intel x86 wolfssl 2024 06 18 wolfssl wolfssl github 2023 11 22 supercop archived from the original on 2015 02 15 retrieved 2017 05 31 code andreas hülsing archived from the original on 2017 08 22 retrieved 2017 05 31 squareup publications www pqsignatures org david mcgrew 2018 05 29 the hash sigs package an implementation of the leighton micali hierarchical signature system hss github david mcgrew 2018 11 22 a full featured implementation of the lms and hss hash based signature schemes from draft mcgrew hash sigs 07 github t lange hash based signatures encyclopedia of cryptography and security springer u s 2011 f t leighton s micali large provably fast and secure digital signature schemes based one secure hash functions us patent 5 432 852 1995 g becker merkle signature schemes merkle trees and their cryptanalysis seminar post quantum cryptology at the ruhr university bochum germany 2008 archived 2017 08 30 at the wayback machine e dahmen m dring e klintsevich j buchmann l c coronado garcia cmss an improved merkle signature scheme progress in cryptology indocrypt 2006 r merkle secrecy authentication and public key systems a certified digital signature ph d dissertation dept of electrical engineering stanford university 1979 archived 2018 08 14 at the wayback machine s micali m jakobsson t leighton m szydlo fractal merkle tree representation and trav...
|