3 ms·
> Winternitz signatures are fascinating because they're secure while still being within the reach of most programmers and--as the article points out--they're qu
by refset 4y ago
> Winternitz signatures are fascinating because they're secure while still being within the reach of most programmers and--as the article points out--they're quantum safe.
Absolutely agreed, Winternitz is very approachable!
At one point ~10 years ago I was particular enamoured by this "Dahmen-Krauß Hash-Chain Signature Scheme" (DKSS) built on top of Winternitz. It is a stateful scheme optimised for signing small messages...appropriate for things like lightweight sensor networks (e.g. 8-bit sensor readings), but I was imagining possibly also for quantum-proof p2p systems based on replicating event logs :)
https://web.archive.org/web/20110401080052/https://www.cdc.informatik.tu-darmstadt.de/~dahmen/papers/DK09.pdf https://web.archive.org/web/20110401080052/https://www.cdc.i...
...and from there I learned about "hash chain traversal" algorithms which are slightly trickier to reason about, but still within reach of a casual programmer.
At the time this really felt orders of magnitude less intimidating than any other options for adding post-quantum signatures to my JavaScript app :P