<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-pquip-hbs-state" target="https://datatracker.ietf.org/doc/html/draft-ietf-pquip-hbs-state-03">
   <front>
      <title>Hash-based Signatures: State and Backup Management</title>
      <author initials="T." surname="Wiggers" fullname="Thom Wiggers">
         <organization>PQShield</organization>
      </author>
      <author initials="K." surname="Bashiri" fullname="Kaveh Bashiri">
         <organization>BSI</organization>
      </author>
      <author initials="S." surname="Kölbl" fullname="Stefan Kölbl">
         <organization>Google</organization>
      </author>
      <author initials="J." surname="Goodman" fullname="Jim Goodman">
         <organization>Crypto4A Technologies</organization>
      </author>
      <author initials="S." surname="Kousidis" fullname="Stavros Kousidis">
         <organization>BSI</organization>
      </author>
      <date month="February" day="7" year="2026" />
      <abstract>
	 <t>   Stateful Hash-Based Signature Schemes (Stateful HBS) such as LMS,
   HSS, XMSS and XMSS^MT combine Merkle trees with One-Time Signatures
   (OTS) to provide signatures that are resistant against attacks using
   large-scale quantum computers.  Unlike conventional stateless digital
   signature schemes, Stateful HBS have a state to keep track of which
   OTS keys have been used, as double-signing with the same OTS key
   allows forgeries.

   This document provides guidance and catalogs security considerations
   for the operational and technical aspects of deploying systems that
   rely on Stateful HBS.  Management of the state of the Stateful HBS,
   including any handling of redundant key material, is a sensitive
   topic.  This document describes some approaches to handle the
   associated challenges.  It also describes the challenges that need to
   be resolved before certain approaches should be considered.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-pquip-hbs-state-03" />
   
</reference>
