What IETF RFC 8391 XMSS eXtended Merkle Signature Scheme - Stateful Hash-Based Signature Specification requires
RFC 8391, XMSS: eXtended Merkle Signature Scheme, is an Informational document published in May 2018 by A. Huelsing, D. Butin, S. Gazdag, J. Rijneveld and A. Mohaisen. It is not an Internet Standards Track specification; it is published for informational purposes and represents the consensus of the Crypto Forum Research Group of the Internet Research Task Force. It specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems; instead it is proven that it only relies on the properties of cryptographic hash functions. The controlling operational obligation in this specification is state management. The schemes described are stateful, meaning the secret key changes over time, and if a secret key state is used twice, no cryptographic security guarantees remain and it becomes feasible to forge a signature on a new message. The document states that developers should not use the schemes described except in systems that prevent the reuse of secret key states, that the API MUST be able to handle a secret key state and MUST allow an updated secret key state to be returned, and that an implementation MUST NOT output the signature before the private key is updated. Where partial private keys or copies of private keys are used, for example for load balancing or delegation of signing rights, applications MUST establish means that guarantee that each index, and thereby each WOTS+ key pair, is used to sign only a single message. Parameter selection is governed by Section 5: parameters with n = 32 provide a classical security level of 256 bits and parameters with n = 64 provide 512 bits, which considering quantum-computer-aided attacks yield post-quantum security of 128 and 256 bits respectively. The REQUIRED parameter sets all use SHA2-256 to instantiate all functions and are distinguished by the tree height parameter h, which determines the number of signatures that can be done with a single key pair, and the number of layers d. This node covers the specification of the scheme itself. The separate United States federal recommendation on approved use of stateful hash-based signatures is held elsewhere in the registry.
Pillar: Aviation, Defense & Quantum · Authority: Internet Research Task Force (IRTF) Crypto Forum Research Group, published in the RFC series · Version: 1.0.0 · Last updated:
Primary source: https://www.rfc-editor.org/rfc/rfc8391.html
SHA-256 integrity: ed46346cfacc5f59fd83041c402b0c5639176fb2bd2c58325d2bef7249b8b8ff
Primary Citations — 10 traced to source
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/ietf-rfc-8391-xmss-hash-based-signatures.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/ietf-rfc-8391-xmss-hash-based-signatures.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/ietf-rfc-8391-xmss-hash-based-signatures
- Back to registry: Browse all 10,099 compliance nodes