6 ms·
I was part of a project that knew this siren song well. Here's our Swift implementation: https://pastebin.com/eAFYgqvL https://pastebin.com/eAFYgqvL Winternit
by gtrevorjay 4y ago
I was part of a project that knew this siren song well. Here's our Swift implementation:
https://pastebin.com/eAFYgqvL https://pastebin.com/eAFYgqvL
Winternitz signatures are fascinating because they're secure while still being within the reach of most programmers and--as the article points out--they're quantum safe.
We never got around to implementing the Merkle tree portion because while it saved space it added more complication and still didn't quite solve the "one time" issue. Instead, we implemented a simple blockchain. Users would sign a block containing the signature of the content they wanted to sign and their next key. Again, within the capabilities of most coders to verify themselves, which was the goal.
- refset 4y ago> Winternitz signatures are fascinating because they're secure while still being within the reach of most programmers and--as the article points out--they're quantum safe. Absolutely agreed, Winternitz is very approachable! At one point ~10 years ago I was particular enamoured by this "Dahmen-Krauß Hash-Chain Signature Scheme" (DKSS) built on top of Winternitz. It is a stateful scheme optimised for signing small messages...appropriate for things like lightweight sensor networks (e.g. 8-bit sensor readings), but I was imagining possibly also for quantum-proof p2p systems based on replicating event logs :) https://web.archive.org/web/20110401080052/https://www.cdc.informatik.tu-darmstadt.de/~dahmen/papers/DK09.pdf https://web.archive.org/web/20110401080052/https://www.cdc.i... ...and from there I learned about "hash chain traversal" algorithms which are slightly trickier to reason about, but still within reach of a casual programmer. At the time this really felt orders of magnitude less intimidating than any other options for adding post-quantum signatures to my JavaScript app :P