Paper 2026/1708
Prepared Episodes for Short Online Hash Based Signatures
Abstract
SPHINCS+ provides stateless signing and self-contained verification, but its signatures are large: every message carries a FORS signature and a complete WOTS+/Merkle authentication chain to the long-term root. This cost is repeated even when messages arrive in a bounded episode whose maximum size is known in advance. We introduce prepared-episode signatures and instantiate them as SPHINCS-PE. The construction splits a globally addressed hypertree at an episode boundary into upper and lower trees. Preparation authenticates the boundary root through the upper tree, while each online signature traverses the lower tree back to that root. Because the upper tree is computed before messages arrive, it can use fewer, taller layers. This removes WOTS+ blocks from full signatures at the cost of more preparation work. Full signatures remain self-contained, while recurring verifiers may cache the upper certificate. Our fixed-count exposure analysis pools colliding preparations and bounds post-selection of the target episode. The end-to-end theorem reduces unforgeability to PE-ITSR and explicit PRF and hash-component games. Compared with the matched FIPS 205 SLH-DSA profiles, SPHINCS-PE reduces full-signature sizes by 3% to 12% for the short profiles and by 25% to 40% for the fast profiles. With the upper certificate cached, online signatures are 24% to 48% smaller for short profiles and 56% to 70% smaller for fast profiles. These results show that prepared episodes can shorten hash-based signatures without giving up self-contained verification.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- post-quantum cryptographyhash-based signaturesSPHINCS+SLH-DSAprepared episodes.
- Contact author(s)
-
rcx23 @ mails tsinghua edu cn
kaiyizhang @ tsinghua edu cn
cuihr22 @ mails tsinghua edu cn
yuhongbo @ tsinghua edu cn - History
- 2026-08-18: approved
- 2026-08-17: received
- See all versions
- Short URL
- https://ia.cr/2026/1708
- License
-
CC BY-NC-SA
BibTeX
@misc{cryptoeprint:2026/1708,
author = {Chongxu Ren and Kaiyi Zhang and Haorui Cui and Hongbo Yu},
title = {Prepared Episodes for Short Online Hash Based Signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1708},
year = {2026},
url = {https://eprint.iacr.org/2026/1708}
}