# American Institute of Mathematical Sciences

February  2019, 13(1): 185-193. doi: 10.3934/amc.2019012

## On the security of the WOTS-PRF signature scheme

 1 ISARA Corporation, Waterloo, Canada 2 Department of Combinatorics & Optimization, University of Waterloo, Canada

Received  July 2018 Published  December 2018

We identify a flaw in the security proof and a flaw in the concrete security analysis of the WOTS-PRF variant of the Winternitz one-time signature scheme, and discuss the implications to its concrete security.

The incomplete $\alpha$'th Winternitz hash chain in ${\mathcal{A}}_{{\rm KOW}}$'s experiment
The tree of $w$-keychains to $pk_{\alpha}$
