Merkle tree signatures

Build Merkle tree of one-time signature keys. Signature = OTS + authentication path.

Advertisement

Stateless

Older hash-based (XMSS) required state (used-key tracking). SPHINCS+ eliminates via hypertree structure.

Advertisement

Trade-offs

Signatures 8-50 KB (much larger than Dilithium). Slow signing. But conservative security — only breaks if all hash functions break.

XMSS

Stateful predecessor. Smaller signatures but requires state management. Used in some embedded systems.