Skip to content

Commit

Permalink
Merge pull request #42 from kriskwiatkowski/kris/hbss
Browse files Browse the repository at this point in the history
[LMS] Make it clear that HBSS are not good for general use
  • Loading branch information
auriee authored Feb 7, 2024
2 parents 9997b96 + 9e6141e commit 3ae0369
Showing 1 changed file with 1 addition and 2 deletions.
3 changes: 1 addition & 2 deletions draft-ietf-pquip-pqc-engineers.md
Original file line number Diff line number Diff line change
Expand Up @@ -491,8 +491,7 @@ Multi-Tree XMSS and LMS can be used for signing a potentially large but fixed nu

The number of tree layers in XMSS^MT provides a trade-off between signature size on the one side and key generation and signing speed on the other side. Increasing the number of layers reduces key generation time exponentially and signing time linearly at the cost of increasing the signature size linearly.

XMSS and HSS/LMS can be applied in various scenarios where digital signatures are required, such as software updates.

Due to the complexities described above, the XMSS and LMS are not a suitable replacement for classical signature schemes like RSA or ECDSA. Applications that expect a long lifetime of a signature, like firmware update or secure boot, are typical use cases where those schemes can be succesfully applied.

## Hash-then-Sign

Expand Down

0 comments on commit 3ae0369

Please sign in to comment.