Paper 2025/1398

General Review of Hash-Based Signatures

Halil İbrahim Kaplan, TUBITAK BILGEM
Abstract

The advent of quantum computing threatens the security assumptions underpinning classical public-key cryptographic algorithms such as RSA and ECC. As a response, the cryptographic community has focused on developing quantum-resistant alternatives, with hash-based signature schemes emerging as a compelling option due to their reliance on well-understood hash functions rather than number-theoretic hard- ness assumptions. This paper presents a comprehensive review of hash- based signature schemes, including Lamport, WOTS, XMSS, XMSSMT , and SPHINCS+, examining their structural design, key generation, sign- ing, and verification processes. Emphasis is placed on their classification as stateful and stateless schemes, as well as their practical integration us- ing Merkle trees and address structures. Furthermore, the paper analyzes several notable cryptanalytic attacks-such as intermediate value guess- ing, Antonov’s attack, multi-target attacks, and fault injection strate- gies-that pose risks to these constructions. By discussing both their strengths and vulnerabilities, this work highlights the viability of hash- based signatures as secure and efficient candidates for post-quantum digital signatures.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-quantum cryptographyHash-based signaturesXMSSSPHINCS+Cryptanalysis
Contact author(s)
halil kaplan @ tubitak gov tr
History
2025-08-03: approved
2025-08-01: received
See all versions
Short URL
https://ia.cr/2025/1398
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1398,
      author = {Halil İbrahim Kaplan},
      title = {General Review of Hash-Based Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1398},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1398}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.