Paper 2026/2360

One-Round Threshold XMSS and SPHINCS+ from Fully Homomorphic Encryption

Jung Hee Cheon, Seoul National University, CryptoLab Inc.
Kevin Choi, Seoul National University
Hyeoncheol Joo, Seoul National University
Taeseong Kim, Seoul National University
Abstract

While hash-based signatures such as XMSS and SPHINCS$^+$ are well-established and play a key role in post-quantum cryptography, thresholdizing them to enable use in distributed systems remains a challenge. In particular, their lack of exploitable structure prevents any algebraic attempts that are otherwise possible in the context of classical signatures such as ECDSA, Schnorr, RSA, or BLS, whereas general-purpose MPC techniques are costly in round complexity. In this work, we construct and implement the first one-round threshold protocol for XMSS and SPHINCS$^+$, with concrete parameters yielding full backward compatibility. At a high level, the secret key is shared among the signing parties while the signing algorithm is evaluated homomorphically using a threshold fully homomorphic encryption scheme. Any $t$-of-$n$ parties, via threshold decryption, can collaboratively derive the signature, which is accepted by the unmodified RFC 8391 or FIPS 205 verifier. At a technical level, we develop efficient homomorphic SHAKE evaluation over discrete CKKS for varying batch sizes. Analyzing XMSS and SPHINCS$^+$ signing reveals parallel hash computations and data-dependent selections, which we handle through batching and homomorphic lookup to obtain end-to-end circuits. Our implementation amortizes SHAKE256/256 evaluation to $3.4\,\text{ms}$ per hash and completes online threshold XMSS signing in $0.69\,\text{s}$. Threshold SPHINCS$^+$ has roughly two orders of magnitude higher signing latency but over an order of magnitude lower setup latency than XMSS.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Threshold signaturesHash-based signaturesXMSSSPHINCS+Threshold fully homomorphic encryptionCKKS
Contact author(s)
jhcheon @ snu ac kr
kc2853 @ snu ac kr
wnguscjf01 @ snu ac kr
kts1023 @ snu ac kr
History
2026-10-07: approved
2026-10-05: received
See all versions
Short URL
https://ia.cr/2026/2360
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2360,
      author = {Jung Hee Cheon and Kevin Choi and Hyeoncheol Joo and Taeseong Kim},
      title = {One-Round Threshold {XMSS} and {SPHINCS}+ from Fully Homomorphic Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2360},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2360}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.