RFC 8391: XMSS: eXtended Merkle Signature Scheme
In plain English — editorial summary, not part of the RFC
This note describes the eXtended Merkle Signature Scheme (XMSS), a hash-based digital signature system that is based on existing descriptions in scientific literature. This note specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. Both XMSS and XMSS^MT use WOTS+ as a main building block. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems. Instead, it is proven that it only relies on the properties of cryptographic hash functions. XMSS provides strong security guarantees and is even secure when the collision resistance of the underlying hash function is broken. It is suitable for compact implementations, is relatively simple to implement, and naturally resists side-channel attacks. Unlike most other signature systems, hash-based signatures can so far withstand known attacks using quantum computers.
Document record
- Document ID
- RFC8391
- Published
- May 2018
- Authors
- A. Huelsing; D. Butin; S. Gazdag; J. Rijneveld; A. Mohaisen
- Status
- INFORMATIONAL
- Stream
- IRTF
- Area
- —
- Pages
- 74
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8230Using RSA Algorithms with CBOR Object Signing and Encryption (COSE) MessagesCurrent
September 2017
- RFC 8812CBOR Object Signing and Encryption (COSE) and JSON Object Signing and Encryption (JOSE) Registrations for Web Authentication (WebAuthn) AlgorithmsCurrent
August 2020
- RFC 8032Edwards-Curve Digital Signature Algorithm (EdDSA)Current
January 2017
- RFC 8937Randomness Improvements for Security ProtocolsCurrent
October 2020
- RFC 7748Elliptic Curves for SecurityCurrent
January 2016
- RFC 9496The ristretto255 and decaf448 GroupsCurrent
December 2023
- RFC 8387Practical Considerations and Implementation Experiences in Securing Smart Object NetworksCurrent
May 2018
- RFC 8463A New Cryptographic Signature Method for DomainKeys Identified Mail (DKIM)Current
September 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?