IP Library Granted Patent US 12,608,490
Granted Patent B2
US 12,608,490 · App. 18/676,636 · Granted Apr 21, 2026

Tracking hash-based signatures in LMS and XMSS using a distributed ledger

Inventor: Avesta Hojjati (Austin, TX)
Assignee: DigiCert, Inc.
G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,608,490
App. No.
18/676,636
Granted
Apr 21, 2026
Kind
B2
Abstract

Tracking hash-based signatures using a distributed ledger includes, subsequent to generating a plurality of one-time signatures (OTSs) organized in a Merkle tree for use in a stateful hash-based digital signature scheme, receiving a request for a digital signature based therein; obtaining an OTS from the plurality of OTSs based on checking the distributed ledger; and creating a transaction on the distributed ledger based on the request to mark the OTS as used. The stateful hash-based digital signature scheme can be Leighton-Micali Signature (LMS) or extended Merkle Signature Scheme (XMSS).

Claims (36)

1 . A method for tracking hash-based signatures using a distributed ledger, the method comprising steps of:

subsequent to generating a plurality of one-time signatures (OTSs) organized in a Merkle tree for use in a stateful hash-based digital signature scheme, receiving a request for a digital signature based therein;

obtaining an OTS from the plurality of OTSs based on checking the distributed ledger; and

creating a transaction on the distributed ledger based on the request to mark the OTS as used, wherein the creating the transaction causes a lock on the OTS to prevent a race condition where there are other attempts to use the OTS prior to the transaction being added to the distributed ledger.

2 . The method of claim 1 , wherein the checking the distributed ledger includes:

determining there are no transactions with the OTS.

3 . The method of claim 1 , wherein the checking the distributed ledger includes:

determining there is a transaction with a second OTS of the plurality of OTSs and selecting the OTS based on there being no transactions associated therewith.

4 . The method of claim 1 , wherein the transaction includes an identifier associated with the request.

5 . The method of claim 4 , wherein the identifier notes a specific Hardware Security Module (HSM) of a plurality of HSMs and the Merkle tree of a plurality of Merkle trees.

6 . The method of claim 1 , wherein the stateful hash-based digital signature scheme is Leighton-Micali Signature (LMS).

7 . The method of claim 1 , wherein the stateful hash-based digital signature scheme is extended Merkle Signature Scheme (XMSS).

8 . The method of claim 1 , wherein the checking the distributed ledger includes:

determining there are no transactions with the OTS.

9 . The method of claim 1 , wherein the checking the distributed ledger includes:

determining there is a transaction with a second OTS of the plurality of OTSs and selecting the OTS based on there being no transactions associated therewith.

10 . The method of claim 1 , wherein the creating the transaction causes a lock on the OTS to prevent a race condition where another attempts to use the OTS prior to the transaction being added to the distributed ledger.

11 . The method of claim 1 , wherein the stateful hash-based digital signature scheme is Leighton-Micali Signature (LMS).

12 . The method of claim 1 , wherein the stateful hash-based digital signature scheme is eXtended Merkle Signature Scheme (XMSS).

13 . A system for tracking hash-based signatures using a distributed ledger, the system comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to

subsequent to generation of a plurality of one-time signatures (OTSs) organized in a Merkle tree for use in a stateful hash-based digital signature scheme, receive a request for a digital signature based therein;

obtain an OTS from the plurality of OTSs based on checking the distributed ledger; and

create a transaction on the distributed ledger based on the request to mark the OTS as used, wherein, once the transaction is created, there is a lock on the OTS to prevent a race condition there are other attempts to use the OTS prior to the transaction being added to the distributed ledger.

14 . The system of claim 13 , wherein the checking the distributed ledger includes:

a determination that there are no transactions with the OTS.

15 . The system of claim 13 , wherein the checking the distributed ledger includes:

a determination there is a transaction with a second OTS of the plurality of OTSs and the OTS is selected based on there being no transactions associated therewith.

16 . The system of claim 13 , wherein the transaction includes an identifier associated with the request.

17 . The system of claim 16 , wherein the identifier notes a specific Hardware Security Module (HSM) of a plurality of HSMs and the Merkle tree of a plurality of Merkle trees.

18 . The system of claim 13 , wherein the stateful hash-based digital signature scheme is Leighton-Micali Signature (LMS).

19 . The system of claim 13 , wherein the stateful hash-based digital signature scheme is extended Merkle Signature Scheme (XMSS).

20 . A method for tracking hash-based signatures using a distributed ledger, the method comprising steps of:

subsequent to generating a plurality of one-time signatures (OTSs) organized in a Merkle tree for use in a stateful hash-based digital signature scheme, receiving a request for a digital signature based therein;

obtaining an OTS from the plurality of OTSs based on checking the distributed ledger; and

creating a transaction on the distributed ledger based on the request to mark the OTS as used, wherein the transaction includes an identifier associated with the request, and wherein the identifier notes a specific Hardware Security Module (HSM) of a plurality of HSMs and the Merkle tree of a plurality of Merkle trees.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: HOJJATI, AVESTA
To: DIGICERT, INC.
Reel/Frame 067547/0554 →
Continuity (1)
Related Publication 20250371170A1 · Dec 4, 2025
References Cited (10)
US 12231580B1 · McMahon · 2025 [cited by examiner]
US 20230300129A1 · Hojjati et al. · 2023 [cited by applicant]
US 20230344639A1 · Hojjati · 2023 [cited by applicant]
US 20230344650A1 · Hojjati · 2023 [cited by applicant]
US 20230385811A1 · Naidoo et al. · 2023 [cited by applicant]
US 20240048369A1 · Kam · 2024 [cited by examiner]
US 20240096051A1 · Gopalakrishna et al. · 2024 [cited by applicant]
“QRL Whitepaper”, [retrieved on Aug. 28, 2025], from the Internet: <URL: https://docs.theqrl.org/build/fundamentals/whitepaper> (Year: 2016). [cited by examiner]
Peter Waterland, “Statefulness and security”, [retrieved on Aug. 28, 2025], from the Internet: <URL: https://www.theqrl.org/blog/statefulness-and-security/> (Year: 2017). [cited by examiner]
Will Song, “Announcing two new LMS libraries”, [retrieved on Aug. 28, 2025], from the Internet: <URL: https://blog.trailofbits.com/2024/04/26/announcing-two-new-lms-libraries/> (Year: 2024). [cited by examiner]