RFC 10033: Assinaturas Baseadas em Hash: Gerenciamento de Estado e Backup

15/09/2026 às 00:0079 visualizações
RFC 10033: Hash-Based Signatures: State and Backup Management. Stateful Hash-Based Signature Schemes (Stateful HBS) such as Leighton-Micali Signature (LMS), Hierarchical Signature System (HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT combine Merkle trees with One-Time Signatures (OTSs) to provide signatures that are resistant against attacks using large-scale quantum computers. Unlike conventional stateless digital signature schemes, Stateful HBS have a state to keep track of which OTS keys have been used, as double-signing with the same OTS key allows forgeries.

This document provides guidance and catalogs security considerations for the operational and technical aspects of deploying systems that rely on Stateful HBS. Management of the state of the Stateful HBS, including any handling of redundant key material, is a sensitive topic. This document describes some approaches to handle the associated challenges. It also describes the challenges that need to be resolved before certain approaches should be considered..
RFC 10033: Hash-Based Signatures: State and Backup Management. Stateful Hash-Based Signature Schemes (Stateful HBS) such as Leighton-Micali Signature (LMS), Hierarchical Signature System (HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT combine Merkle trees with One-Time Signatures (OTSs) to provide signatures that are resistant against attacks using large-scale quantum computers. Unlike conventional stateless digital signature schemes, Stateful HBS have a state to keep track of which OTS keys have been used, as double-signing with the same OTS key allows forgeries. This document provides guidance and catalogs security considerations for the operational and technical aspects of deploying systems that rely on Stateful HBS. Management of the state of the Stateful HBS, including any handling of redundant key material, is a sensitive topic. This document describes some approaches to handle the associated challenges. It also describes the challenges that need to be resolved before certain approaches should be considered..
RFC Editor

Esquemas de Assinatura Baseados em Hash com Estado (Stateful HBS) como a Assinatura de Leighton-Micali (LMS), o Sistema de Assinatura Hierárquica (HSS), o Esquema de Assinatura Merkle Estendido (XMSS) e o XMSS^MT, combinam árvores Merkle com Assinaturas Únicas (OTSs) para fornecer assinaturas resistentes a ataques usando computadores quânticos de grande escala. Ao contrário dos esquemas convencionais de assinatura digital sem estado, os Stateful HBS têm um estado para acompanhar quais chaves OTS foram usadas, pois a assinatura dupla com a mesma chave OTS permite falsificações.

Este documento fornece orientação e cataloga considerações de segurança para os aspectos operacionais e técnicos da implantação de sistemas que dependem de Stateful HBS. O gerenciamento do estado dos Stateful HBS, incluindo qualquer tratamento de material de chave redundante, é um tópico sensível. Este documento descreve algumas abordagens para lidar com esses desafios. Também descreve os desafios que precisam ser resolvidos antes de certas abordagens devem ser consideradas.

Fonte
RFC Editor
Abrir original ↗

Conteúdo traduzido automaticamente por máquina.

Esta notícia foi útil?

Debates 0

Seja o primeiro a contribuir com o debate.

Difunda suas informações e promova seu argumento

Não se acanhe de publicar alguma informação ou dado que possa ser positivo ou útil.

Para participar do debate, entre com sua conta ou crie uma gratuita.