Merkle tree signatures
Build Merkle tree of one-time signature keys. Signature = OTS + authentication path.
Advertisement
Stateless
Older hash-based (XMSS) required state (used-key tracking). SPHINCS+ eliminates via hypertree structure.
Advertisement
Trade-offs
Signatures 8-50 KB (much larger than Dilithium). Slow signing. But conservative security — only breaks if all hash functions break.
XMSS
Stateful predecessor. Smaller signatures but requires state management. Used in some embedded systems.