60 likes | 234 Views
Hash-Based Signatures. Johannes Buchmann, Andreas Hülsung Supported by DFG and DAAD. Part X: XMSS Security. X MSS has Minimal Security Requirements. Security Requirements of Current Signature Schemes. Intractability assumption. Collision resistant hash function. Digital signature scheme.
E N D
Hash-Based Signatures Johannes Buchmann, Andreas Hülsung Supported by DFG and DAAD Part X: XMSS Security
Security Requirements of Current Signature Schemes Intractability assumption Collision resistant hash function Digital signature scheme
Minimal Security Requirement of Signatures Digital signature scheme One-way FF Naor, Yung 1989 Rompel 1990
XMSShas minimal security requirements XMSS Existential unforgeable under chosen message attacks Second-preimage resistant HFF Target-collision resistant HFF XMSS Pseudorandom FF Rompel 1990 Håstad, Impagliazzo, Levin, Luby 1999 Goldreich, Goldwasser, Micali 1986 Digital signature scheme One-way FF Naor, Yung 1989 Rompel 1990
Security proof [BDH, PQC 2011] XMSS isEU-CMA PRFF [BDEHR., Africacrypt 2011] WOTS$ is EU-CMA [BDH, PQC 2011] SPR-HFF [ DOTV,PQC 2008] XMSS isforwardsecure XMSS-Tree + WOTS isEU-CMA