Stateful Scheme Comparison

Comparison of stateful signature candidates. You can add and compare your own by clicking + Add candidate.

Comparison table

All cost columns are SHA-256 compression-function calls with the PK.seed block midstate-cached (FIPS 205 SHA-2 layout; the original uncached convention remains available in the scripts via HASH_CONVENTION=uncached). Cost ratios under each value compare against SLH-DSA-128s. UXMSS signatures grow with the signature index: the size column shows the first→largest range, and all ratios, filters and verification costs use the worst case (hsf auth nodes, reached by the last two of the hsf+1 signatures). The Signer selector switches SigGen between the cached signer (BDS-amortised, tree state kept between signatures) and a state-minimized signer that rebuilds its trees per signature. State shows the cached signer's memory — UXMSS: all hsf+1 leaf hashes; XMSS/XMSS-MT: a BDS-style estimate; "—" for the stateless SLH-DSA baseline and in state-minimized mode.

All stateful candidates

Pre-swept over h = [10, 40], d = [1, 10] (with d ⏐ h), OTS = {WOTS, WOTS+C}, w = {16, 32, 256}, plus the 6 UXMSS variants (2 OTS * 3 w). Every candidate has signature size strictly smaller than SLH-DSA-128s. UXMSS tree height is capped at hsf = 255. Tighten the bounds to narrow the pool; click a row's + to add it to the comparison above.