Paper 2025/1398

General Review of Hash-Based Signatures

Halil İbrahim Kaplan, TUBITAK BILGEM
Abstract

The advent of quantum computing threatens the security assumptions underpinning classical public-key cryptographic algorithms such as RSA and ECC. As a response, the cryptographic community has focused on developing quantum-resistant alternatives, with hash-based signature schemes emerging as a compelling option due to their reliance on well-understood hash functions rather than number-theoretic hardness assumptions. This paper presents a comprehensive review of hash-based signature schemes, covering the foundational building blocks (Lamport signatures, Winternitz one-time signatures, Merkle trees, and FORS) as well as the three standardized constructions: XMSS (RFC 8391), LMS (RFC 8554), and the stateless SPHINCS+ (FIPS 205 / SLH-DSA). A systematic comparison highlights the trade-offs between statefulness, signature size, and implementation complexity. Furthermore, the paper analyzes several notable cryptanalytic attacks, examining for each the attack model, applicable constructions, complexity, and known countermeasures. By discussing both their strengths and vulnerabilities, this work provides a unified reference for understanding the design landscape of hash-based signatures as practical candidates for post-quantum digital signatures.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-quantum cryptographyHash-based signaturesXMSSSPHINCS+Cryptanalysis
Contact author(s)
halil kaplan @ tubitak gov tr
History
2026-09-10: revised
2025-08-01: received
See all versions
Short URL
https://ia.cr/2025/1398
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1398,
      author = {Halil İbrahim Kaplan},
      title = {General Review of Hash-Based Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1398},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1398}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.