Stateful Hash Signatures Using Master and Slave Merkle Trees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hash-based signature schemes face challenges in allowing multiple entities to generate signatures in parallel using the same public key without risking the reuse of One-Time Signature (OTS) private keys, due to the need for sensitive state value synchronization, which can lead to synchronization errors and compromise the public key if not managed properly.
Innovation Solution
A method utilizing a master Merkle tree and multiple slave Merkle trees, where each tamper-proof computing device is assigned a slave Merkle tree, allowing parallel signature generation without state synchronization, with the master public signature key verifying all signatures, and ensuring OTS private keys are used only once by securely updating and tracking their usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If state value synchronization is implemented to prevent OTS private key reuse across multiple entities, then security against key reuse is improved, but system complexity and synchronization error risk increase
Solution Approach 1:
The system divides the set of OTS private keys into multiple disjoint subsets, with each tamper-proof computing device assigned a unique subset. This segmentation eliminates the need for synchronization because each device operates independently on its own keys. The Merkle tree structure further segments the key management hierarchy, allowing parallel operation while maintaining security through cryptographic binding of subsets to the master public key.
2Productivity
If multiple entities can generate signatures in parallel using the same public key, then productivity is improved, but the risk of OTS private key reuse increases without proper synchronization
Solution Approach 1:
The system performs preliminary assignment of disjoint OTS private key subsets to each tamper-proof computing device before parallel signature generation begins. This pre-assignment ensures that when multiple entities generate signatures in parallel, they inherently use different keys without requiring real-time synchronization. The Merkle tree structure is pre-built with all necessary authentication paths, enabling immediate parallel operation while guaranteeing key uniqueness through the predetermined partitioning.
3Reliability
If state value protection mechanisms are implemented to prevent tampering, then security is improved, but ease of operation decreases due to synchronization requirements
Solution Approach 1:
The invention extracts the state value management problem from the parallel signature generation process by assigning static, disjoint key subsets to each device beforehand. Instead of maintaining and synchronizing dynamic state values during parallel operation, the system removes the need for state synchronization entirely through cryptographic binding of predetermined key subsets to the master public key via the Merkle tree structure.
4Ease of operation
If a single master public key is used to verify all signatures, then ease of operation is improved, but the complexity of key management structure increases
Solution Approach 1:
The master public key at the root of the Merkle tree serves multiple functions: it verifies all signatures generated by different devices, binds together the disjoint key subsets assigned to each device, and provides a single point of certification for the entire key hierarchy. This universal verification capability simplifies operations while the underlying Merkle tree structure manages the complexity of distributing and securing multiple key subsets.
Data Source
AI summary
Generation of stateful hash based signatures of messages to be signed in a key management system including a plurality of tamper-proof computing devices by a manager device of generating a master merkle tree, triggering generating a predetermined number of slave merkle trees, for each message to be signed selecting a tamper-proof computing device for signing, assigning one yet unassigned generated slave merkle tree to said selected tamper-proof computing device, generating and sending to said selected tamper-proof computing device a command comprising said message to be signed, data enabling to obtain an OTS private key of the assigned slave merkle tree to be used to generate an OTS signature of the message to be signed, and a state value associated to said assigned slave merkle tree and keeping track of the OTS private keys of said assigned slave merkle tree already used for generating a signature.


