On the security of the WOTS-PRF signature scheme

Philip Lafrance and Alfred Menezes

Abstract: We identify a flaw in the security proof and a flaw in the concrete security analysis of the WOTS-PRF variant of the Winternitz one-time signature scheme, and discuss the implications to its concrete security.

Category / Keywords: public-key cryptography, digital signatures, hash functions

Date: received 25 Sep 2017, last revised 5 Feb 2018

