Revisiting the Constant-Sum Winternitz One-Time Signature with Applications to SPHINCS+ and XMSS
Kaiyi Zhang, Hongrui Cui, Yu Yu
Abstract
Hash-based signatures offer a conservative alternative to post-quantum signatures with arguably better-understood security than other post-quantum candidates.
As a core building block of hash-based signatures, the efficiency of one-time signature (OTS) largely dominates that of hash-based signatures. The WOTS signature scheme (Africacrypt 2013) is the current state-of-the-art OTS adopted by the signature schemes standardized by NIST---XMSS, LMS and SPHINCS.
A natural question is whether there is (and how much) room left for improving one-time signatures (and thus standard hash-based signatures). In this paper, we show that WOTS one-time signature, when adopting the constant-sum encoding scheme (Bos and Chaum, Crypto 1992), is size-optimal not only under Winternitz's OTS framework, but also among all tree-based OTS designs. Moreover, we point out a flaw in the DAG-based OTS design previously shown to be size-optimal at Asiacrypt 1996, which makes the constant-sum WOTS the most size-efficient OTS to the best of our knowledge. Finally, we evaluate the performance of constant-sum WOTS integrated into the SPHINCS (CCS 2019) and XMSS (PQC 2011) signature schemes which exhibit certain degrees of improvement in both signing time and signature size.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ddcef77a-f8af-4ea9-bed5-065d65bbf00bRelated papers
- SPHINCS+C: Compressing SPHINCS+ With (Almost) No CostAndreas Hülsing, Mikhail A. Kudinov, Eyal Ronen, Eylon YogevS&P 2023
- At the Top of the Hypercube - Better Size-Time Tradeoffs for Hash-Based SignaturesDmitry Khovratovich, Mikhail A. Kudinov, Benedikt WagnerCRYPTO 2025 · 5 citations
- Shorter Hash-Based Signatures Using Forced PruningMehdi Abri, Jonathan KatzCRYPTO 2026
- The SPHINCS+ Signature FrameworkDaniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen et al.CCS 2019 · 385 citations
- Machine-Checked Security for rmXMSS as in RFC 8391 and Manuel Barbosa, François Dupressoir, Benjamin Grégoire, Andreas Hülsing et al.CRYPTO 2023 · 3 citations
