On the security of the WOTS-PRF signature scheme

  • We identify a flaw in the security proof and a flaw in the concrete security analysis of the WOTS-PRF variant of the Winternitz one-time signature scheme, and discuss the implications to its concrete security.

    Mathematics Subject Classification: Primary: 94A60.


  • Figure 1.  The incomplete $\alpha$'th Winternitz hash chain in ${\mathcal{A}}_{{\rm KOW}}$'s experiment

    Figure 2.  The tree of $w$-keychains to $pk_{\alpha}$

