[Resource Topic] 2017/966: Optimal Parameters for XMSS^MT

Welcome to the resource topic for 2017/966

Optimal Parameters for XMSS^MT

Authors: Andreas Hülsing, Lea Rausch, Johannes Buchmann


We introduce Multi Tree XMSS (XMSS^MT), a hash-based signature scheme that can be used to sign a virtually unlimited number of messages. It is provably forward and hence EU-CMA secure in the standard model and improves key and signature generation times compared to previous schemes. XMSS^MT has — like all practical hash-based signature schemes — a lot of parameters that control different trade-offs between security, runtimes and sizes. Using linear optimization, we show how to select provably optimal parameter sets for different use cases.

ePrint: https://eprint.iacr.org/2017/966

