SLH-DSA Explained: Hash-Based Stateless Signatures
What SLH-DSA is
SLH-DSA stands for Stateless Hash-Based Digital Signature Algorithm. NIST published it in 2024 as FIPS 205. It descends from the SPHINCS+ submission to the NIST post-quantum process. It was standardized as a backup that does not depend on the same math as ML-DSA, so a future break of lattice assumptions would not take down every standard at once.
Why hash-based security is conservative
A hash function turns any input into a short fixed size fingerprint and is hard to reverse. Quantum computers are known to give only a limited speedup against hashing, through Grover's algorithm, which designers handle by choosing adequate output sizes. Details are in Hash Functions and Quantum Computers. Because SLH-DSA assumes little beyond good hash functions, many cryptographers regard it as the most cautious option.
How the idea works
The building block is a one time signature. A signer reveals parts of a secret that match the bits of a message digest, and each key can safely be used only once. To sign many messages, the scheme organizes many one time keys under a tree of hashes, in the style of a Merkle tree, so the public key is just the root of the tree. A signature shows the one time signature plus the path of hashes proving it belongs under that root. SLH-DSA stacks several layers of such trees, so one small public key covers an enormous number of possible signatures.
What stateless means
Older hash-based schemes are stateful. The signer must remember which one time keys were already used, and reusing one can reveal the secret. A backup restore or a crash can cause this mistake. SLH-DSA is stateless: it picks a leaf pseudorandomly from the message, so the signer does not have to track a counter. That removes a serious operational risk, at the cost of larger signatures.
Trade-offs
- Public keys are small, but signatures are large, often many kilobytes depending on the parameter set.
- Signing is slower than lattice schemes, while verification is comparatively quick.
- The standard offers parameter sets that trade size against speed.
- Security assumptions are minimal and well understood.
Where it might be used
It suits cases where signatures are made rarely and trust must last a long time, such as firmware or root keys. For transaction heavy blockchains the size is a challenge. For a broader comparison see Quantum-Resistant Signatures Explained and Post-Quantum Cryptography and Crypto.
Because hash-based signatures rest on such plain assumptions, they are also easier to reason about. A reviewer can ask a simple question: is the hash function secure? If yes, the signature scheme inherits that security. Lattice schemes involve more intricate arguments, which is why having both families available is considered a sensible hedge.
For readers comparing options, a useful summary is that SLH-DSA buys confidence with bytes. You accept bigger signatures and slower signing in return for a security argument that is simple to state and has been studied for a long time, since hash-based signatures date back several decades.
Frequently asked questions
What does SLH-DSA stand for?
Stateless Hash-Based Digital Signature Algorithm. It is defined in NIST FIPS 205 and is based on the SPHINCS+ design.
Why is it called stateless?
The signer does not need to remember which one time keys have been used. That avoids the risk of accidentally reusing a key, which could expose the secret.
Why are SLH-DSA signatures so large?
Each signature carries a one time signature plus authentication paths through several layers of hash trees. Proving membership under a tiny public key takes a lot of data.
Is SLH-DSA safer than ML-DSA?
It rests on fewer assumptions, so many consider it more conservative. That does not make it better for every use, since size and speed are real costs.
Does Grover's algorithm break it?
Grover gives a limited speedup against hash functions. Parameter sets are chosen with that in mind, so it is not considered a practical break.
Could a blockchain use it?
Technically yes, but large signatures raise transaction size and cost. Any real adoption would be a network design decision.
Keep reading
- ML-DSA Explained: The Post-Quantum Signature Standard
ML-DSA (FIPS 204) is NIST's main post-quantum digital signature standard. Learn how lattice signatures work, how they compare to ECDSA, and the trade-offs. - Hash Functions and Quantum Computers: Are They Safe?
Are hash functions like SHA-256 safe from quantum computers? Learn how Grover's algorithm affects hashing, mining and blockchains in plain English. - Quantum-Resistant Signatures Explained
What are quantum-resistant digital signatures? Learn the main families, the NIST standards and the trade-offs blockchains face when upgrading. - Crypto Agility Explained: Preparing for Algorithm Change
Crypto agility is the ability to swap cryptographic algorithms without rebuilding a system. Learn why it matters for the post-quantum shift and for blockchains.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary