Paper 2025/2278

Secure Distributed State Management for Stateful Signatures with a Practical and Universally Composable Protocol

Johannes Blömer, Paderborn University
Henrik Bröcher, Paderborn University
Volker Krummel, Ultimaco IS GmbH
Laurens Porzenheim, Paderborn University
Abstract

Stateful signatures like the NIST standardized signature schemes LMS and XMSS provide an efficient and mature realization of post-quantum secure signature schemes. They are recommended for long-term use cases like e.g. firmware signing. However, stateful signature schemes require to properly manage a so-called state. In stateful signature schemes like LMS and XMSS, signing keys consist of a set of keys of a one-time signature scheme and it has to be guaranteed that each one-time key is used only once. This is done by updating a state in each signature computation, basically recording which one-time keys have already been used. While this is straightforward in centralized systems, in distributed systems like secure enclaves consisting of e.g. multiple hardware security modules (HSMs) with limited communication keeping a distributed state that at any point in time is consistent among all parties involved presents a challenge. This challenge is not addressed by the current standardization processes. In this paper we present a security model for the distributed key management of post-quantum secure stateful signatures like XMSS and LMS. We also present a simple, efficient, and easy to implement protocol proven secure in this security model, i.e. the protocol guarantees at any point in time a consistent state among the parties in a distributed system, like a distributed security enclave. The security model is defined in the universal composabilty (UC) framework by Ran Canetti by providing an ideal functionality for the distributed key management for stateful signatures. Hence our protocol remains secure even if arbitrarily composed with other instances of the same or other protocols, a necessity for the security of distributed key management protocols. Our main application are security enclaves consisting of HSMs, but the model and the protocol can easily be adapted to other scenarios of distributed key management of stateful signature schemes.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
distributed statehash-based signaturestateful hash-based signatureuniversal composabilitysecure enclave
Contact author(s)
bloemer @ upb de
henrik broecher @ upb de
volker krummel @ utimaco com
laurens porzenheim @ upb de
History
2025-12-22: approved
2025-12-18: received
See all versions
Short URL
https://ia.cr/2025/2278
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2278,
      author = {Johannes Blömer and Henrik Bröcher and Volker Krummel and Laurens Porzenheim},
      title = {Secure Distributed State Management for Stateful Signatures with a Practical and Universally Composable Protocol},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2278},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2278}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.