Optimal Parameters for XMSSMT
Abstract
We introduce Multi Tree XMSS (XMSSMT), a hash-based signature scheme that can be used to sign a virtually unlimited number of messages. It is provably forward and hence EU-CMA secure in the standard model and improves key and signature generation times compared to previous schemes. XMSSMT has — like all practical hash-based signature schemes — a lot of parameters that control different trade-offs between security, runtimes and sizes. Using linear optimization, we show how to select provably optimal parameter sets for different use cases.
Origin | Files produced by the author(s) |
---|
Loading...