IP Library › Granted Patent US 12,676,753
Granted Patent B1
US 12,676,753 · App. 18/137,966 · Granted Jul 7, 2026

Methods and systems for generating and updating Merkle trees for an evolving data series and applications thereof

Inventors: Burton S. Kaliski, Jr. (McLean, VA); Andrew Fregly (Reston, VA); Joseph Harvey (Clifton, VA); Swapneel Sheth (Fairfax, VA)
Assignee: VeriSign, Inc.
H04L9/3247H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,676,753
App. No.
18/137,966
Filed
Apr 21, 2023
Granted
Jul 7, 2026
Kind
B1
Art Unit
2432
USPC
713/168
Abstract

A computer-implemented method for authenticating messages relative to a hash-based data authentication structure includes producing a first signed data structure that includes one or more node hash values from the hash-based data authentication structure. The node hash values are selected according to a selected strategy and configured to authenticate messages relative to the hash-based data structure. The method further includes producing a second signed data structure that is a modified version of the first signed data structure. The method further includes enabling a signed data structure provider to provide to a verifier the first signed data structure and the second signed data structure. The method further includes enabling an authentication path provider to provide to the verifier an authentication path formed relative to the first signed data structure or the second signed data structure. The verifier determines whether to use the first signed data structure and performs a verification procedure.

Claims (40)

1 . A computer-implemented method for authenticating messages relative to a hash-based data authentication structure, the computer-implemented method comprising:

producing a first signed data structure, wherein the first signed data structure comprises a first subset of a plurality of node hash values from the hash-based data authentication structure, wherein the first subset is selected according to a selected strategy and configured to authenticate messages relative to the hash-based data authentication structure;

producing a second signed data structure, wherein the second signed data structure comprises a second subset of the plurality of node hash values from the hash-based data authentication structure, wherein the second subset comprises the first subset with one or more of at least one added node hash value or at least one removed node hash value;

enabling a signed data structure provider to provide to a verifier the first signed data structure and the second signed data structure; and

enabling an authentication path provider to provide to the verifier an authentication path formed relative to the first signed data structure or the second signed data structure,

wherein the verifier determines whether to use the first signed data structure based on the authentication path, and performs a verification procedure, wherein the verifier determines whether to use the first signed data structure by:

obtaining the authentication path formed relative to the first signed data structure or the second signed data structure; and

determining, based on information associated with the authentication path, whether the authentication path can be verified relative to the first signed data structure.

2 . The computer-implemented method of claim 1 , wherein the verification procedure further comprises the verifier:

obtaining a third signed data structure from the signed data structure provider responsive to determining that the authentication path cannot be verified relative to the first signed data structure; and

verifying the authentication path relative to the first signed data structure or the third signed data structure.

3 . The computer-implemented method of claim 1 , wherein the verification procedure further comprises the verifier:

verifying the authentication path relative to the first signed data structure responsive to determining that the authentication path can be verified relative to the first signed data structure.

4 . The computer-implemented method of claim 1 , wherein the selected strategy comprises at least one or more of a full strategy, a single strategy, a basic binary strategy, an extended binary strategy, a spaced strategy, a variable spaced strategy, a bounded strategy, a spaced and bounded strategy, a spaced extended binary strategy, and a bounded extended binary strategy.

5 . The computer-implemented method of claim 1 , wherein producing the first signed data structure comprises grouping elements that are to be added to a data series into data series batches that have identifiers that start at one greater than a highest element identifier in a current data series authenticated by the verifier.

6 . The computer-implemented method of claim 1 , further comprising creating a long-lived data structure for a data series based on a subseries of the data series that is anticipated not to change during a period of time.

7 . The computer-implemented method of claim 1 , further comprising constructing multiple data structures that can be used as authenticators for subsets of an expanding data series.

8 . The computer-implemented method of claim 1 , further comprising producing and using multiple reference values from multiple data structures, wherein the multiple data structures comprise an unbalanced data structure having subtrees from which the multiple reference values are obtained.

9 . The computer-implemented method of claim 1 , further comprising performing a batch updating process using a merge method, wherein an initial authenticator is created with a number of leaves that is a largest power of two that is less than or equal to a number of resource record sets in a data series.

10 . The computer-implemented method of claim 1 , wherein the selected strategy authenticates long-lived data elements that are anticipated not to change during a period of time, and wherein another strategy authenticates changing data elements.

11 . The computer-implemented method of claim 1 , further comprising publishing the plurality of node hash values in the first signed data structure as synthesized public keys.

12 . The computer-implemented method of claim 11 , wherein at least one of the synthesized public keys is used as at least one of: a domain name system security extension (DNSSEC) key signing key or a DNSSEC zone signing key.

13 . The computer-implemented method of claim 1 , further comprising publishing, in an internet public key infrastructure (PKI) as a synthesized public key, information sufficient to validate the plurality of node hash values in at least one of the first signed data structure or the second signed data structures.

14 . A computer-implemented method for authenticating messages relative to a hash-based data authentication structure, the computer-implemented method comprising:

obtaining, from a signed data structure provider, a first signed data structure, wherein the first signed data structure comprises a first subset of a plurality of node hash values from the hash-based data authentication structure, wherein the first subset is selected according to a selected strategy and configured to authenticate messages relative to the hash-based data authentication structure;

obtaining, from an authentication path provider, an authentication path formed relative to a second signed data structure, wherein the second signed data structure comprises a second subset of the plurality of node hash values from the hash-based data authentication structure, wherein the second subset comprises the first subset with one or more of at least one added node hash value or at least one removed node hash value;

determining, based on information associated with the authentication path, whether the authentication path can be verified relative to the first signed data structure;

responsive to determining that the authentication path cannot be verified relative to the first signed data structure, obtaining, from the signed data structure provider, a third signed data structure, wherein the third signed data structure is a modified version of the first signed data structure; and

verifying the authentication path relative to the first signed data structure or the third signed data structure, and wherein verifying the authentication path comprises:

obtaining the authentication path formed relative to the first signed data structure or the second signed data structure; and

determining, based on information associated with the authentication path, whether the authentication path can be verified relative to the first signed data structure.

15 . The computer-implemented method of claim 14 , wherein the selected strategy comprises at least one or more of a full strategy, a single strategy, a basic binary strategy, an extended binary strategy, a spaced strategy, a variable spaced strategy, a bounded strategy, a spaced and bounded strategy, a spaced extended binary strategy, and a bounded extended binary strategy.

16 . The computer-implemented method of claim 14 , further comprising publishing the first subset as synthesized public keys.

17 . The computer-implemented method of claim 1 , wherein the first subset is selected from a plurality of levels of the hash-based data authentication structure.

18 . The computer-implemented method of claim 1 , wherein:

the first subset is associated with a first range of node hash value identifiers,

the second subset is associated with a second range of node hash value identifiers, and

determining whether to use the first signed data structure comprises:

determining a third range represented by the authentication path, and

determining whether the third range corresponds to the first range.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2023
From: KALISKI, BURTON S., JR.; FREGLY, ANDREW; HARVEY, JOSEPH; SHETH, SWAPNEEL
To: VERISIGN, INC.
Reel/Frame 063855/0144 →
Continuity (4)
Provisional Application 63429093 · Nov 30, 2022
Provisional Application 63416909 · Oct 17, 2022
Provisional Application 63406699 · Sep 14, 2022
Provisional Application 63356973 · Jun 29, 2022
References Cited (196)
US 10009181B2 · Kaliski, Jr. et al. · 2018 [cited by applicant]
US 10116450B1 · Brown · 2018 [cited by examiner]
US 10153905B2 · Kaliski, Jr. · 2018 [cited by applicant]
US 11025407B2 · Kaliski, Jr. · 2021 [cited by examiner]
US 20130055369A1 · Kumar et al. · 2013 [cited by applicant]
US 20140181984A1 · Kundu et al. · 2014 [cited by applicant]
US 20170272250A1 · Kaliski, Jr. · 2017 [cited by applicant]
US 20180159689A1 · Keuffer et al. · 2018 [cited by applicant]
US 20200364911A1 · Benzakour et al. · 2020 [cited by applicant]
US 20210184864A1 · Wentz et al. · 2021 [cited by applicant]
US 20240380856A1 · Dmitrii et al. · 2024 [cited by applicant]
CN 110602239A · 2019 [cited by examiner]
WO WO2019093574A1 · 2019 [cited by examiner]
Verisign IDF 2021-3508 <https://verisign.lecorpio.com/Runtime/EntityObject.aspx?TypeId=fce3012f-6660-489d-b174-53a05e5bb4d2&ObjectId=40cef332-7da4-41c6-8706-79250ace544a&AddToNavigationHistory=true&DashboardID=9bbc9031-… [cited by applicant]
B. Kaliski, Securing the DNS in a Post-Quantum World: Hash-Based Signatures and Synthesized Zone Signing Keys, Jan. 2021, https://blog.verisign.com/security/securing-the-dns-in-a-post-quantum-world-hash-based-signatures… [cited by applicant]
R. C. Merkle, “A Digital Signature Based on a Conventional Encryption Function”, Advances in Cryptology—CRYPTO '87. Lecture Notes in Computer Science. vol. 293, doi:10.1007/3-540-48184-2_32, ISBN 978-3-540-18796-7. [cited by applicant]
M. Müller et al., Retrofitting Post-Quantum Cryptography in Internet Protocols: A Case Study of DNSSEC <https://dl.acm.org/doi/10.1145/3431832.3431838>, ACM SIGCOMM CCR, 2020. [cited by applicant]
M. Müller, Making DNSSEC Future Proof <https://research.utwente.nl/en/publications/making-dnssec-future-proof>, Ph.D. Thesis, U. Twente, 2021. [cited by applicant]
P. Hoffman, Quantum Computing and the DNS <https://www.icann.org/en/system/files/files/octo-031-11feb22-en.pdf>, ICANN OCTO-031, 2022. [cited by applicant]
G.J. Beernink, Taking the Quantum Leap: Preparing DNSSEC for Post Quantum Cryptography <http://essay.utwente.nl/89509/1/Beernink_MA_EEMCS.pdf>, M.Sc. Thesis, U. Twente, 2022. [cited by applicant]
S. Jafarli, Providing DNS Security in Post-Quantum Era with Hash-Based Signatures <http://essay.utwente.nl/89552/>, M.Sc. Thesis, U. Twente, 2022. [cited by applicant]
A. Fregly and R. van Rijswijk-Deij, Stateful Hash-Based Signatures for DNSSEC <https://datatracker.ietf.org/doc/draft-afrvrd-dnsop-stateful-hbs-for-dnssec/>, Internet-Draft, 2022. [cited by applicant]
J. Jansen, Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC <https://www.rfc-editor.org/info/rfc5702>, RFC 5702, Oct. 2009. [cited by applicant]
P. Hoffman and W.C.A. Wijngaards, Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC <https://www.rfc-editor.org/info/rfc6605>, RFC 6605, Apr. 2012. [cited by applicant]
O. Sury and R. Edmonds, Edwards-Curve Digital Security Algorithm ( <https://www.rfc-editor.org/info/rfc8080>EdDSA <https://www.rfc-editor.org/info/rfc8080>) for DNSSEC <https://www.rfc-editor.org/info/rfc8080>, RFC 8080… [cited by applicant]
A. Huelsing et al., XMSS: <https://www.rfc-editor.org/info/rfc8391>eXtended <https://www.rfc-editor.org/info/rfc8391> Merkle Signature Scherne <https://www.rfc-editor.org/info/rfc8391>, RFC 8391, May 2018. [cited by applicant]
D. McGrew, M. Curcio and S. Fluhrer. Leighton—<https://www.rfc-editor.org/info/rfc8554>Micali <https://www.rfc-editor.org/info/rfc8554> Hash-Based Signatures <https://www.rfc-editor.org/info/rfc8554>. RFC 8554, Apr. 201… [cited by applicant]
P. Wouters and O. Sury, Algorithm Implementation Requirements and Usage Guidance for DNSSEC <https://www.rfc-editor.org/info/rfc8624>, RFC 8624, Jun. 2019. [cited by applicant]
F. Li et al,. Proof-Infused Streams: Enabling Authentication of Sliding Window Queries on Streams <http://hadjieleftheriou.com/papers/vldb07.pdf>, VLDB 2007, Sep. 2007. [cited by applicant]
C. Papamanthou et al., Streaming Authenticated Data Structures <https://link.springer.com/content/pdf/10.1007/978-3-642-38348-9_22.pdf>, Eurocrypt 2013, May 2013. [cited by applicant]
L. Reyzin and S. Yakoubov, Efficient Asynchronous Accumulators for Distributed PKI <https://link.springer.com/chapter/10.1007/978-3-319-44618-9_16>, SCN 2016, Aug. 2016. ('authors version <https://eprint.iacr.org/2015/7… [cited by applicant]
U.S. Appl. No. 17/827,576, filed May 27, 2022. [cited by applicant]
Arends, R., Austein, R., Larson, M., Massey, D., Rose, S.: DNS Security Introduction and Requirements. IETF (2005). https://doi.org/10.17487/RFC4033. [cited by applicant]
Attrapadung, N., Libert, B., Peters, T.: Computing on authenticated data: New privacy definitions and constructions. In: Wang, X., Sako, K. (eds) Advances in Cryptology—ASIACRYPT 2012, LNCS, vol. 7658, pp. 367-385. Spri… [cited by applicant]
Baldimtsi, F., Chalkias, K., Chatzigiannis, P., Kelkar, M.: Truncator: Time-space Tradeoff of Cryptographic Primitives, In: Cryptology ePrint Archive, Paper 2022/1581, https://eprint.iacr.org/2022/1581, last accessed No… [cited by applicant]
Barker, W., Polk, W., Souppaya, M.: Getting Ready for Post-Quantum Cryptography: Exploring Challenges Associated with Adopting and Using Post-Quantum Cryptographic Algorithms, NIST Cybersecurity White Paper, Apr. 28, 20… [cited by applicant]
Boneh, D., Gentry, C., Lynn, B., Shacham, H.: Aggregate and verifiably encrypted signatures from bilinear maps. In: Biham, E. (ed.) Advances in Cryptology—EUROCRYPT 2003, LNCS, vol. 2656, pp. 416-432. Springer, Berlin, … [cited by applicant]
Bünz, B., Kiffer, L., Luu, L., Zamani, M.: FlyClient: Super-light clients for cryptocurrencies. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 928-946. IEEE (2020), https://doi.org/10.1109/SP40000.2020.00049. [cited by applicant]
Champine, L.: Streaming Merkle Proofs within Binary Numeral Trees. In: Cryptology ePrint Archive, Paper 2021/038. https://eprint.iacr.org/2021/038, last accessed Oct. 18, 2022. [cited by applicant]
Chase, M., Kohlweiss, M., Lysyanskaya, A., Meiklejohn, S.: Malleable signatures: New definitions and delegatable anonymous credentials. In 2014 IEEE 27th Computer Security Foundations Symposium, pp. 199-213. IEEE (2014)… [cited by applicant]
Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., Polk, W.: RFC 5280, Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. IETF (2008). https://doi.org/10.17… [cited by applicant]
Crosby, S., Wallach, D.: Efficient data structures for tamper-evident logging. In Proceedings of the 18th USENIX Security Symposium, pp. 317-334. USENIX Association (2009). https://dl.acm.org/doi/abs/10.5555/1855768.185… [cited by applicant]
Decker, C., Wattenhofer, R.: Bitcoin transaction malleability and MtGox. In: Kuty?owski, M., Vaidya, J. (eds.) Computer Security—ESORICS 2014, LNCS, vol. 8173, pp. 313-326. Springer, Cham (2014). https://doi.org/10.1007… [cited by applicant]
Draft Call for Additional Digital Signature Schemes for the Post-Quantum Cryptography Standardization Process, NIST, https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/call-for-proposals-dig-sig-sept-2022.p… [cited by applicant]
Driscoll, F.: Terminology for Post-Quantum Traditional Hybrid Schemes,. https://datatracker.ietf.org/doc/draft-driscoll-pqt-hybrid-terminology, last accessed Oct. 18, 2022. Work in progress. [cited by applicant]
Goyal, R., Vaikuntanathan, V.: Locally Verifiable Signature and Key Aggregation, In: Cryptology ePrint Archive, Paper 2022/179, https://eprint.iacr.org/2022/179, last accessed Oct. 18, 2022. To appear, Advances in Crypt… [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) using OpenID Connect”, Work in Progress, Internet-Draft, draft-ietf-regext-rdap-openid-12, Mar. 2022, https://datatracker.ietf.o… [cited by applicant]
Huelsing, A., D. Butin, S. Gazdag et al. XMSS: extended Merkle Signature Scheme. IETF RFC 8391, DOI 10.17487/RFC8391 , May 2018. https://www.rfc-editor.org/info/rfc8391. [cited by applicant]
Hülsing, A., Rijneveld, J., Song, F.: Mitigating multi-target attacks in hash-based signatures. In: Cheng, CM., Chung, KM., Persiano, G., Yang, BY. (eds) Public-Key Cryptography—PKC 2016, LNCS, vol. 9614, pp. 387-416. S… [cited by applicant]
Khaburzaniya, I., Konstantinos, C., Lewi, K., Malval, H.: Aggregating and thresholdizing hash-based signatures using STARKs. In: Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, pp… [cited by applicant]
Kudinov, M., Ronen, Hülsing, A., E. Yogev, E., SPHINCS+C: Compressing SPHINCS+ With (Almost) No Cost, In: Cryptology ePrint Archive, Paper 2022/778, https://eprint.iacr.org/2022/778, last accessed Nov. 18, 2022. [cited by applicant]
Migration to Post-Quantum Cryptography. NIST National Cybersecurity Center of Excellence. https://www.nccoe.nist.gov/crypto-agility-considerations-migrating-post-quantum-cryptographic-algorithms. Accessed Oct. 11, 2022. [cited by applicant]
National Security Agency. Announcing the Commercial National Security Algorithm Suite 2.0. Sep. 2022. https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF. Accessed Oct. 11, 2022. [cited by applicant]
Papamanthou, C., Shi, E., Tamassia, R., Yi, K.: Streaming authenticated data structures. In: Johansson, T., Nguyen, P.Q. (eds.) Advances in Cryptology—EUROCRYPT 2013, LNCS, vol. 7881, pp. 353-370. Springer, Berlin, Heid… [cited by applicant]
Post-Quantum Cryptography Standardization. NIST. https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization. Accessed Oct. 11, 2022. [cited by applicant]
Reyzin, L., Yakoubov, S.: Efficient asynchronous accumulators for distributed PKI. In: Zikas, V., De Prisco, R. (eds) Security and Cryptography for Networks, SCN 2016, LNCS, vol. 9841, pp. 292-309. Springer, Cham, 2016.… [cited by applicant]
Sloane, N.J.A., Wilks, A.: a(n)=a(floor(n/2))+n; also denominators in expansion of 1/sqrt(1-x) are 2^a(n); also 2n—number of 1's in binary expansion of 2n. In: The On-Line Encyclopedia of Integer Sequences, Entry A00518… [cited by applicant]
Sloane, N.J.A.: The ruler function: 2^a(n) divides 2n. Or, a(n)=2-adic valuation of 2n. in: The On-Line Encyclopedia of Integer Sequences, Entry A001511, https://oeis.org/A001511, last accessed Oct. 18, 2022. [cited by applicant]
Todd, P.: Merkle Mountain Ranges, https://github.com/opentimestamps/opentimestamps-server/blob/master/doc/merkle-mountain-range.md, last accessed Oct. 18, 2022. [cited by applicant]
Wouters, P. and O. Sury. Algorithm Implementation Requirements and Usage Guidance for DNSSEC. IETF RFC 8624, DOI 10.17487/RFC8624, Jun. 2019. https://www.rfc-editor.org/info/rfc8624. [cited by applicant]
U.S. Appl. No. 18/137,992, filed Apr. 21, 2023. [cited by applicant]
U.S. Appl. No. 18/219,522, filed Jul. 7, 2023. [cited by applicant]
Bradner, S., et al., Intellectual Propery Rights in IETF Technology:, BCP 79, RFC 8179, DOI 10.17487/RFC8179, May 2017, https://www.rfc-editor.org/info/rfc8179. [cited by applicant]
Eastlake, D., et al., “Randonmess Requirements for Security,” BCP 106, RFC 4086, DOI 10.17487/RFC4086, https://www.rfc-editor.org/info/rfc4086. [cited by applicant]
Leiba, B., “Ambuigity of Uppercase vs Lowercase in RFC 2119 Key Words,” BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, https://www.rfc-editor/og/info/rfc 8174. [cited by applicant]
“L. Reyzin and S. Yakoubov, Efficient Asynchronous Accumulators for Distributed PK<https://link.springer.com/chapter/10.1007/978-3-319-44618-9_16>, SCN 2016, Aug. 2016. ('authors version <https://eprint.iacr.org/2015/71… [cited by applicant]
Li, F., Yi, K., Hadjieleftheriou, M., Kollios, G.: Proof-infused streams: Enabling authentication of sliding window queries on streams. In: Proceedings of the 33rd International Conference on Very Large Data Bases, pp. … [cited by applicant]
McGrew, D., M. Curcio and S. Fluhrer. Leighton-Micali Hash-Based Signatures. IETF RFC 8554, DOI 10.17487/RFC8554, Apr. 2019. https://www.rfc-editor.org/info/rfc8554. [cited by applicant]
Merkle, R. Secrecy, Authentication, and Public Key Systems. Ph.D. thesis, Stanford University, 1979. [cited by applicant]
Hülsing, A., J. Rijneveld and F. Song. Mitigating multi-target attacks in hash-based signatures. In Public-Key Cryptography—PKC 2016, LNCS, vol. 9614, pp. 387-416. Springer, 2016. https://doi.org/10.1007/978-3-662-49384… [cited by applicant]
Huque, S., Shulman, H., Kerr, S., “Algorithm Negotiation in DNSSEC”, Jul. 2018, pp. 1-17 https://datatracker.ietf.org/doc/draft-huque-dnssec-algnego/03/. [cited by applicant]
ICANN, “Registrar Data Escrow Specifications”, Nov. 2007, pp. 1-8 https://www.icann.org/en/system/files/files/rde-specs-09nov07-en.pdf. [cited by applicant]
IETF, Charter “Post-Quantum Use in Protocols (pquip)”, IETF, Jan. 2023, https://datatracker.ietf.org/doc/charter-ietf-pquip/. [cited by applicant]
IETF, Charter “Post-Quantum Use in Protocols (pquip)”, IETF, Jan. 2023, https://datatracker.ietf.org/wg/pquip/about/. [cited by applicant]
Kaliski, B., “Preparing for Post-Quantum: Securing Internet Infrastructure for the Long Term”, Cloudfest Mar. 22, 2023, pp. 1-13. [cited by applicant]
Kaliski, B., “Preparing for Post-Quantum: The DNSSEC Case”, 6th International Symposium on Cyber Security, Cryptology and Machine Learning (CSCML 2022), Jun. 30-Jul. 1, 2022, pp. 1-43. [cited by applicant]
Kaliski, B., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, NIST Fourth PQC Standardization Conference, Dec. 2022, pp. 1-32 https://csrc.nist.gov/Presentations/2022/mer… [cited by applicant]
Kaliski, B., Fregly, A., Harvey, J., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, Video courtesy of RSA Conference, Apr. 2023, pp. 1-38. [cited by applicant]
Katz, J.: Analysis of a Proposed Hash-Based Signature Standard. In: Chen, L., McGrew, D., Mitchell, C. (eds) Security Standardisation Research. SSR 2016. LNCS, vol. 10074. Springer, Cham (2016). https://doi.org/10.1007/… [cited by applicant]
Khaburzaniya, I., Chalkias, K., Lewi, K., Malvai, H.: Aggregating and thresholdizing hash-based signatures using STARKs. In: Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, pp. 39… [cited by applicant]
Kolbl, S., Lauridsen, L., Mendel, F., Rechberger, C., Efficient Short-Input Hashing for Post-Quantum Applications, in IACR Transactions on Symmetric Cryptology vol. 2016, No. 2, pp. 1-29, DOI 10.13154/tosc.v2016.i2.1-29… [cited by applicant]
Kuszmaul, J.: Verkle Trees, https://math.mit.edu/research/highschool/primes/materials/2018/Kuszmaul.pdf, last accessed Oct. 18, 2022. [cited by applicant]
Laurie, B., E. Messeri and R. Stradling. Certificate Transparency Version 2.0. IETF RFC 9162, DOI 10.17487/RFC9162, Dec. 2021. https://www.rfc-editor.org/info/rfc9162. [cited by applicant]
Lozano, G., ICANN, “Registry Data Escrow Specification”, Nov. 2020, https://datatracker/ietf.org/doc/html/rfc8909. [cited by applicant]
Merkle, R.: Secrecy, Authentication, and Public Key Systems. Ph.D. thesis, Stanford University (1979). http://www.ralphmerkle.com/papers/Thesis1979.pdf, last accessed Feb. 13, 2023. [cited by applicant]
Migration to Post-Quantum Cryptography. NIST National Cybersecurity Center of Excellence. https://www.nccoe.nist.gov/crypto-agility-considerations-migrating-post-quantum-cryptographic-algorithms, last accessed Feb. 16, … [cited by applicant]
Mockapetris, P.: RFC 1034, Domain Names—Concepts and Facilities. IETF (1987). https://doi.org/10.17487/RFC1034. [cited by applicant]
Moody, D., “NIST Status Update on the 3rd Round”, “NIST 3rd PQC Standardization Conference”, Jun. 2021, https://csrc.nist.gov/CSRC/media/Presentations/status-update-on-the-3rd-round/images-media/session-1-moody-nist-rou… [cited by applicant]
Moody, D., “The Beginning to the End: The First NIST PQC Standards”, PKC 2022, Mar. 8-11, 2022, Mar. 8, 2022, https://csrc.nist.gov/csrc/media/Presentations/2022/the-beginning-of-the-end-the-first-nist-pqc-standa/images… [cited by applicant]
Moriarty, K., B. Kaliski, J. Jonsson et al. PKCS #1: RSA Cryptography Specifications Version 2.2. IETF RFC 8017, DOI 10.17487/RFC8017, Nov. 2016. https://www.rfc-editor.org/info/rfc8017. [cited by applicant]
Mosca, M., Piani, M., “Quantum Threat Timeline Report 2020,” https://globalriskinstitute.org/download/quantum-threat-timeline-report-2020/. [cited by applicant]
Mosca, M., Piani, M., “Quantum Threat Timeline Report 2022”, Global Risk Institute, Dec. 2022, https://globalriskinstitute.org/mp-files/2022-quantum-threat-timeline-report-dec.pdf/.https://globalriskinstitute.org/mp-fil… [cited by applicant]
National Institute of Standards and Technology (NIST), “SP 800-131A Transitioning the Use of Cryptographic Algorithms and Key Lengths”, Mar. 2019, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2… [cited by applicant]
National Security Agency. Announcing the Commercial National Security Algorithm Suite 2.0. Sep. 2022, pp. 1-10. https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF, last accessed Feb. 1… [cited by applicant]
NIST (National Institute of Standards and Technology), “SP 800-57 Recommendation for Key Management: Part 1—General”, Oct. 2020, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf. [cited by applicant]
NIST CSRC, “PQC Standardization Process: Announcing Four Candidates to be Standardized, Plus Fourth Round Candidates”, NIST, Jul. 5, 2022, https://csrc.nist.gov/news/2022/pqc-candidates-to-be-standardized-and-round-4. [cited by applicant]
Orman, H., Internet Security and Quantum Computing, Dec. 2021, https://eprint/iacr.org/2021/1637.pdf. [cited by applicant]
Peikert, C., Pepin, Z., Sharp, C.: Vector and functional commitments from lattices. In: Nissim, K., Waters, B. (eds.) Theory of Cryptography, TCC 2021, LNCS, vol. 13044, pp. 480-511. Springer, Cham (2021). https://doi.o… [cited by applicant]
Post-Quantum Cryptography Standardization. NIST. https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization. Accessed Sep. 12, 2022. [cited by applicant]
Rescorla, D., “The Transport Layer Security Protocol Version 1.3”, RFC 8446, DOI 10.17487/RFC8446, Aug. 2018, https://www.rfc-editor.org/info/rfc8446. [cited by applicant]
RFC 4523—The Secure Shell (SSH) Transport Layer Protocol. [cited by applicant]
RFC 5734—Extensible Provisioning Protocol (EPP) Transport over TCP. [cited by applicant]
RFC 6698—The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol. [cited by applicant]
RFC 6781—DNSSEC Operational Practices, Version 2. IETF. [cited by applicant]
RFC 7481—Security Services for the Registration Data Access Protocol (RDAP). [cited by applicant]
RFC 7525—Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS). [cited by applicant]
RFC 8162—Using Secure DNS to Associate Certificates with Domain Names for S/MIME. [cited by applicant]
RFC 8247—Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2). [cited by applicant]
RFC 8301—Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM). [cited by applicant]
RFC 8310—Usage Profiles for DNS over TLS and DNS over DTLS. [cited by applicant]
RFC 8332—Use of RSA Keys with SHA-256 and SHA-512 in the Secure Shell (SSH) Protocol. [cited by applicant]
Fregly, Andrew, Projecting Impact of Post Quantum Cryptography on Registry Operations, ROW11—Jun. 21, 2022. [cited by applicant]
Fregly, Andrew, Projecting Impact of Post-Quantum Cryptography on Registry Operations, CENTR Workshop, May 31, 2023. [cited by applicant]
Schwabe, P., D. Stebila and T. Wiggers. Post-quantum TLS without handshake signatures. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pp. 1461-1480. ACM, 2020. https://dl.acm.o… [cited by applicant]
Shor, P.W., “Polynomial time algorithms for prime factorization and discrete logarithms on a quantum computer,” SIAM Review 41.2 (1999): 303-332. [cited by applicant]
Sikeridis, D., Huntley, S., Ott, D., Devetsikiotis, M.: Intermediate certificate suppression in post-quantum TLS: An approximate membership querying approach, In: CoNEXT '22: Proceedings of the 18th International Confer… [cited by applicant]
Sikeridis, D., Kampanakis, P., Devetsikiotis, M.: Post-quantum authentication in TLS 1.3: a performance study. In: Network and Distributed Systems Security (NDSS) Symposium 2020, The Internet Society (2020). https://dx.… [cited by applicant]
Sloane, N.J.A. The ruler function: 2^a(n) divides 2n. Or, a(n)=2-adic valuation of 2n. Entry A001511 in the On-Line Encyclopedia of Integer Sequences. https://oeis.org/A001511. Accessed Oct. 11, 2022. [cited by applicant]
David Benjamin, “Batch Signing for TLS,” Internet-Draft, Jul. 29, 2019, https://datatracker.ietf.org/doc/draft-davidben-tls-batch-signing/00/. [cited by applicant]
David Benjamin, “Batch Signing for TLS,” Internet-Draft, Sep. 13, 2019, https://datatracker.ietf.org/doc/draft-davidben-tls-batch-signing/01/. [cited by applicant]
David Benjamin, “Batch Signing for TLS,” Internet-Draft, Nov. 1, 2019, https://datatracker.ietf.org/doc/draft-davidben-tls-batch-signing/02/. [cited by applicant]
David Benjamin, “Batch Signing for TLS,” Internet-Draft, Jan. 13, 2020, https://datatracker.ietf.org/doc/draft-ietf-tis-batch-signing/00/. [cited by applicant]
Diana Berbecaru, “MBS-OCSP: An OCSP based certificate revocation system for wireless environments,” IEEE, 2004, pp. 267-272. [cited by applicant]
Abe, M., Chase, M., David B., et al. Constant-size structure-preserving signatures: Generic constructions and simple assumptions. Journal of Cryptology 29(4):833-878. Springer, 2016. https://doi.org/10.1007/s00145-015-9… [cited by applicant]
Ahn, J.H., Boneh, D., Camenisch, J., Hohenberger, S., Shelat, A., and Waters, B., Computing on authenticated data. Journal of Cryptology 28(2), 351-395. Springer, 2015. https://doi.org/10.1007/s00145-014-9182-0. [cited by applicant]
Alagic, G., Apon, D., Cooper D., et al. NIST IR 8413-upd1: Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process. NIST, Jul. 2022; includes updates as of Sep. 26, 2022. https://d… [cited by applicant]
Arends, R., Austein, R., Larson, M., Massey, D., Rose, S., “DNS Security Introduction and Requirements”, RFC 4033, DOI 10.17487/RFC4033, Mar. 2005, pp. 1-21, https://www.rfc-editor.org/info/rfc4033. [cited by applicant]
Attrapadung, N., B. Libert and T. Peters. Computing on authenticated data: New privacy definitions and constructions. In Advances in Cryptology—ASIACRYPT 2012, LNCS, vol. 7658, pp. 367-385. Springer, 2012. https://doi.o… [cited by applicant]
Aumasson, J.-P., D.J. Bernstein, W. Beullens, et al. SPHINCS+ Submission to the NIST post-quantum project, v.3.1. Jun. 10, 2022. https://sphincs.org/data/sphincs+-r3.1-specification.pdf. Accessed Oct. 11, 2022. [cited by applicant]
Bai, S., L. Ducas, E. Kiltz, et al. CRYSTALS-Dilithium Algorithm Specifications and Supporting Documentation (Version 3.1). Feb. 8, 2021. https://pq-crystals.org/dilithium/data/dilithium-specification-round3-20210208.pd… [cited by applicant]
Barker, W., W. Polk and M. Souppaya. Getting Ready for Post-Quantum Cryptography: Exploring Challenges Associated with Adopting and Using Post-Quantum Cryptographic Algorithms. NIST Cybersecurity White Paper, Apr. 28, 2… [cited by applicant]
Benaloh, J. and M. de Mare. One-way accumulators: A decentralized alternative to digital signatures. In Advances in Cryptology—EUROCRYPT '93, LNCS, vol. 765, pp. 274-285. Springer, 1993. https://doi.org/10.1007/3-540-48… [cited by applicant]
Ben-Sasson, E., Bentov, I., Horesh, Y., Riabzev, M.: Scalable, Transparent, and Post-Quantum Secure Computational Integrity. In: Cryptology ePrint Archive, Paper 2018/046, https://eprint.iacr.org/2018/046, last accessed… [cited by applicant]
Black, Paul E., “Quantum Computation,” in Paul E. Black (ed.), Dictionary of Algorithms and Data Structures, Dec. 17, 2007, https://www.nist.gov/dads/HTML/quantumComputation.html, last accessed Feb. 16, 2023. [cited by applicant]
Boneh, D., C. Gentry, B. Lynn and H. Shacham. Aggregate and verifiably encrypted signatures from bilinear maps. In Advances in Cryptology—EUROCRYPT 2003, pp. 416-432. Springer, 2003. https://doi.org/10.1007/3-540-39200-… [cited by applicant]
Bos, J.W., Hülsing, A., Renes, J., van Vredendaal, C.: Rapidly Verifiable XMSS Signatures, Cryptology ePrint Archive, Paper 2020/898, https://eprint.iacr.org/2020/898, last accessed Feb. 13, 2023. [cited by applicant]
Bünz, B., L. Kiffer, L. Luu and M. Zamani. FlyClient: Super-light clients for cryptocurrencies. In 2020 IEEE Symposium on Security and Privacy (SP), pp. 928-946. IEEE, 2020. https://doi.org/10.1109/SP40000.2020.00049. [cited by applicant]
Buterik, V.: Verkle Trees, https://vitalik.ca/general/2021/06/18/verkle.html, last accessed Oct. 18, 2022. [cited by applicant]
Catalano, D., Fiore, D.: Vector commitments and their applications. In: Kurosawa, K., Hanaoka, G. (eds.) Public-Key Cryptography—PKC 2013, LNCS, vol. 7778, pp. 55-72. Springer, Berlin, Heidelberg (2013). https://doi.org… [cited by applicant]
Champine, L. Streaming Merkle Proofs within Binary Numeral Trees. Cryptology ePrint Archive, Paper 2021/038. 2021. https://eprint.iacr.org/2021/038. [cited by applicant]
Chase, M., Kohlweiss, M., Lysyanskaya, A., and Meiklejohn, S., Malleable signatures: New definitions and delegatable anonymous credentials. In 2014 IEEE 27th Computer Security Foundations Symposium, pp. 199-213. IEEE, 2… [cited by applicant]
Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., Polk, W.: RFC 5280, “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile”, RFC 5280, DOI 10.17487/RFC5280, … [cited by applicant]
Cooper, D.A., D. Apon, Q.H. Dang et al. NIST Special Publication 800-208: Recommendation for Stateful Hash-Based Signature Schemes. NIST, Oct. 2020. https://doi.org/10.6028/NIST.SP.800-208. [cited by applicant]
Crosby, S. and D. Wallach. Efficient data structures for tamper-evident logging. In Proceedings of the 18th USENIX Security Symposium, pp. 317-334. USENIX Association, 2009. https://dl.acm.org/doi/abs/10.5555/1855768.18… [cited by applicant]
CRYSTALS: Cryptographic Suite for Algebraic Lattices, https://pq-crystals.org/. [cited by applicant]
Damas, J., Graff, M., Vixie, P., “Extension Mechanisms for DNS (EDNS(0))”, STD 75, RFC 6891, DOI 10.17487/RFC6891, Apr. 2013, https://www.rfc-editor.org/info/rfc6891. [cited by applicant]
Day in the Life of the Internet Traces, DNS-OARC, https://www.dns-oarc.net/oarc/data/catalog, last accessed Feb. 13, 2023. [cited by applicant]
Decker, C. and R. Wattenhofer. Bitcoin transaction malleability and MtGox. In Computer Security—ESORICS 2014, LNCS, vol. 8713, pp. 313-326. Springer, 2014. https://doi.org/10.1007/978-3-319-11212-1_18. [cited by applicant]
Draft Call for Additional Digital Signature Schemes for the Post-Quantum Cryptography Standardization Process. NIST. https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/call-for-proposals-dig-sig-sept-2022.p… [cited by applicant]
Driscoll, F. Terminology for Post-Quantum Traditional Hybrid Schemes. Internet-Draft draft-driscoll-pqt-hybrid-terminology-00, Jul. 8, 2022. https://datatracker.ietf.org/doc/draft-driscoll-pqt-hybrid-terminology. Work i… [cited by applicant]
Ducas, L., et al., CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme, IACR Transactions on Crytographic Hardware and Embedded Systems vol. 0, No. 0, pp. 1-31, https://eprint.iacr.org/2017/633. [cited by applicant]
FIPS Pub 180-4: Secure Hash Standard. NIST, U.S. Department of Commerce, Aug. 2015. https://doi.org/10.6028/NIST.FIPS.180-4. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf, downloaded Aug. 10, 2023. [cited by applicant]
FIPS Pub 81: DES Modes of Operation. National Bureau of Standards, U.S. Department of Commerce, Dec. 2, 1980. https://doi.org/10.6028/NBS.FIPS.81. [cited by applicant]
Fluhrer, S.: Further Analysis of a Proposed Hash-Based Signature Standard. In: Cryptology ePrint Archive, Paper 2017/553, https://eprint.iacr.org/2017/553, last accessed Feb. 13, 2023. [cited by applicant]
Fouque P.-A., J. Hoffstein, P. Kirchner, et al. Falcon: Fast-Fourier Lattice-based Compact Signatures over NTRU Specification v1.2. Jan. 10, 2020. https://falcon-sign.info/falcon.pdf. Accessed Oct. 11, 2022. [cited by applicant]
Fregly, A., “Research Agenda for a Post-Quantum DNSSEC,” OARC 40, Feb. 16-17, 2023, pp. 1-10, https://indico.dns-oarc.net/event/46/. [cited by applicant]
Fregly, A., et al., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice,” NIST Fourth PQC Standardization Conference, Nov. 29-Dec. 1, 2022, pp. 1-32, https://csrc.nist.gov/Eve… [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, Conference Paper, LNCS vol. 13871, Abstract, pp. 1-2. [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, Dec. 15, 2022, pp. 1-41. [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, in Rosulek, M. (editor), Lecture Notes in Computer Science, vol. 13871, C… [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, License to Publish Proceedings Papers, SpringerNature, Feb. 13, 2023, pp.… [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, May 1, 2023, pp. 1-42. [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice, Feb. 13, 2023, pp. 1-27. [cited by applicant]
Fregly, A., Harvey, J., Kaliski, B., Sheth, S., “Merkle Tree Ladder Mode: Reducing the Size Impact of NIST PQC Signature Algorithms in Practice”, “Topics in Cryptology—CT-RSA” conference paper, Apr. 19, 2023, https://li… [cited by applicant]
Fujiwara,K., Vixie, P., “Fragmentation Avoidance in DNS”, Work in Progress, Internet-Draft, draft-ietf-dnsop-avoid-fragmentation-05, Jun. 2021, https://datatracker.letf.org/doc/draft-ieft-dnsop-avoid-fragmentation. [cited by applicant]
Goertzen, J., Stebila, D., “Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation”, University of Waterloo, Nov. 2022, pp. 1-18 https://s3.amazonaws.com/files.douglas.stebila.ca/files/research/papers/EPRINT-… [cited by applicant]
Goyal, R. and V. Vaikuntanathan. Locally Verifiable Signature and Key Aggregation. Cryptology ePrint Archive, Paper 2022/179. To appear, Advances in Cryptology—CRYPTO 2002, pp. 1-50, https://eprint.iacr.org/2022/179. [cited by applicant]
Goyal, R., Vaikuntanathan, V.: Locally Verifiable Signature and Key Aggregation, In: , Dodis, Y., Shrimpton, T. (eds), Advances in Cryptology—CRYPTO 2022, LNCS, vol. 13508, pp. 761-791. Springer, Cham (2022). https://do… [cited by applicant]
Grilo, A.B., Hövelmanns, K., Hülsing, A., Majenz, C.: Tight adaptive reprogramming in the QROM. In: Tibouchi, M., Wang, H. (eds) Advances in Cryptology—ASIACRYPT 2021, LNCS, vol. 13090, pp. 637-667. Springer, Cham (2021… [cited by applicant]
Harvey, J., draft-harvey-cfrg-mtl-mode, Merkle Tree Ladder Mode (MTL) Signatures, IETF-117, slides 1-6, Jul. 25, 2023. [cited by applicant]
Harvey, J., Kaliski, B., Fregly, A., Sheth, S., Merkle Tree Ladder Mode (MTL) Signatures, Internet-Draft: draft-harvey-cfrg-htl-mode-00, Published Jul. 10, 2023, pp. 1-68. [cited by applicant]
Sloane, N.J.A. and A. Wilks. a(n)=a(floor(n/2))+n; also denominators in expansion of 1/sqrt(1-x) are 2^a(n); also 2n—number of 1's in binary expansion of 2n. Entry A005187 in the On-Line Encyclopedia of Integer Sequence… [cited by applicant]
SPHINCS+: Stateless Hash-Based Signatures. https://sphincs.org/. Accessed Sep. 12, 2022. [cited by applicant]
Stern, J., D. Pointcheval, J. Malone-Lee and N.P. Smart. Flaws in applying proof methodologies to signature schemes. In Advances in Cryptology—CRYPTO 2002, pp. 93-110. Springer, 2002. https://doi.org/10.1007/3-540-45708… [cited by applicant]
Submission Requirements and Evaluation Criteria for the Post-Quantum Cryptography Standardization Process, NIST, https://csrc.nist.gov/CSRC/media/Projects/Post-Quantum-Cryptography/documents/call-for-proposals-final-dec… [cited by applicant]
Sury, O., “DNS Flag Day 2020”, Sep. 2020, https://www.isc.org/blogs/dns-flag-day-2020-2.Work in Progress, Internet-Draft, draft-ietf-dnsop-avoid-fragmentation-05, Jun. 2021, https://datatracker/ietf.org/doc/draft-ietf-d… [cited by applicant]
Todd, P. Merkle Mountain Ranges. 2012. https://github.com/opentimestamps/opentimestamps-server/blob/master/doc/merkle-mountain-range.md. Accessed Oct. 11, 2022. [cited by applicant]
Yuan, Q., M. Tibouchi and M. Abe. Security notions for stateful signature schemes. IET Information Security 16 (1):1-17. Wiley Online Library, 2022. https://doi.org/10.1049/ise2.12040. [cited by applicant]
Andy Fregly to [email protected] , “Re: Request for feedback on possible SPHINCS+ variant”, Jan. 5, 2023, https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/LUczQNCw7HA/m/l65HGBZ5AgAJ—comments on the ability … [cited by applicant]
Burt Kaliski to [email protected], “Re: Request for feedback on possible SPHINCS+ variant”, Jan. 13, 2023, https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/LUczQNCw7HA/m/9GovatAOBQAJ—confirms Verisign's int… [cited by applicant]
Burt Kaliski to [email protected], “Re: [CFRG] Fw: New Version Notification for draft-harvey-cfrg-mtl-mode-00.txt”, Jul. 25, 2023, https://mailarchive.ietf.org/arch/msg/cfrg/OX6cbbAgbaVE8wFI8QjGt1_bwWQ/—responds to a questi… [cited by applicant]
Joe Harvey to [email protected], “[CFRG] Fw: New Version Notification for draft-harvey-cfrg-mtl-mode-00.txt”, Jul. 21, 2023, https://mailarchive.ietf.org/arch/msg/cfrg/9BILaWo1CS_64Fs29JQX4GdUVRc/—forwards an announcement o… [cited by applicant]
Joe Harvey to [email protected], “Re: [CFRG] Fw: New Version Notification for draft-harvey-cfrg-mtl-mode-00.txt”, Jul. 28, 2023, https://mailarchive.ietf.org/arch/msg/cfrg/Hnkw99CUj7nk__1tQ5J3it9ft_8/—responds to a question… [cited by applicant]
Burt Kaliski, “Next Steps in Preparing for Post-Quantum DNSSEC”, Verisign blog, Jul. 20, 2023, https://blog.verisign.com/security/post-quantum-dnssec-preparation/—provides an overview of MTL mode and announces the MTL m… [cited by applicant]
David Benjamin, Devon O'Brien , Bas Westerbaan, “Merkle Tree Certificates for TLS”, Internet-Draft, https://datatracker.ietf.org/doc/draft-davidben-tls-merkle-tree-certs/00/, Mar. 10, 2023; updated version, https://data… [cited by applicant]
Orie Steele, Henk Birkholz, Maik Riechert, et al., “Concise Encoding of Signed Merkle Tree Proofs”, Internet-Draft, Mar. 13, 2023, https://datatracker.ietf.org/doc/draft-steele-cose-merkle-tree-proofs/00/—describes “a f… [cited by applicant]
Dennis Jackson, “Abridged Compression for WebPKI Certificates”, Internet-Draft, Jul. 6, 2023 https://datatracker.ietf.org/doc/draft-jackson-tis-cert-abridge/00/—defines a method that “smooths the transition to post-quan… [cited by applicant]
Foteini Baldimtsi, Konstantinos Chalkias, Panagiotis Chatzigiannis, Mahimna Kelka, “Truncator: Time-space Tradeoff of Cryptographic Primitives”, IACR ePrint, Nov. 14, 2022, https://eprint.iacr.org/2022/1581—presents “mi… [cited by applicant]
Panos Kampanakis, Tancrède Lepoint, “Do we need to change some things? Open questions posed by the upcoming post-quantum migration to existing standards and deployments”, IACR ePrint, Feb. 2, 2023, https://eprint.iacr.o… [cited by applicant]
Carlos Aguilar-Melchor, Martin R. Albrecht, Thomas Bailleux, et al., “Batch Signatures, Revisited”, IACR ePrint, Apr. 4, 2023, https://eprint.iacr.org/2023/492—revisits “batch signatures (previously considered in a draf… [cited by applicant]
Kaliski Jr. et al., “Methods and Systems for Generating and Updating Merkle Trees for an Evolving Data Series and Applications Thereof,” U.S. Appl. No. 18/137,966, filed Apr. 21, 2023, 139 Specification and 24 Figures. [cited by applicant]
Kaliski Jr. et al., “Methods and Systems for Generating and Updating Merkle Trees for an Evolving Data Series and Applications Thereof,” U.S. Appl. No. 63/356,973, filed Jun. 29, 2022. [cited by applicant]
Kaliski Jr. et al., “Methods and Systems for Generating Condensed Signatures for an Evolving Data Series and Applications Thereof,” U.S. Appl. No. 63/406,699, filed Sep. 14, 2022, 48 pages Specification and 5 Figures. [cited by applicant]
Fregly et al., “Methods and Systems for Generating Condensed Signatures for an Evolving Data Series and Applications Thereof,” U.S. Appl. No. 63/416,909, filed Oct. 17, 2022, 70 pages Specification and 6 Figures. [cited by applicant]
Kaliski Jr. et al., “Methods and Systems for Generating Condensed Signatures for an Evolving Data Series and Applications Thereof,” U.S. Appl. No. 63/429,093, filed Nov. 30, 2022, 91 pages Specification and 6 Figures. [cited by applicant]
Kaliski Jr. et al., “Systems and Methods for Integrating a Signature Algorithm Into an Application,” U.S. Appl. No. 63/667,601, filed Jul. 3, 2024; 13 pages Specification. [cited by applicant]