{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T18:48:13Z","timestamp":1754160493030,"version":"3.41.2"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031385537"},{"type":"electronic","value":"9783031385544"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-38554-4_14","type":"book-chapter","created":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T19:03:06Z","timestamp":1691521386000},"page":"421-454","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Machine-Checked Security for\u00a0$$\\textrm{XMSS} $$ as\u00a0in RFC\u00a08391 and\u00a0$$\\mathrm {SPHINCS^{+}} $$"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6848-5564","authenticated-orcid":false,"given":"Manuel","family":"Barbosa","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3497-3110","authenticated-orcid":false,"given":"Fran\u00e7ois","family":"Dupressoir","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6650-9924","authenticated-orcid":false,"given":"Benjamin","family":"Gr\u00e9goire","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2215-4134","authenticated-orcid":false,"given":"Andreas","family":"H\u00fclsing","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5351-991X","authenticated-orcid":false,"given":"Matthias","family":"Meijers","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8196-7875","authenticated-orcid":false,"given":"Pierre-Yves","family":"Strub","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2023,8,9]]},"reference":[{"key":"14_CR1","doi-asserted-by":"crossref","unstructured":"Almeida, J.B., Baritel-Ruet, C., Barbosa, M., Barthe, G., Dupressoir, F., Gr\u00e9goire, B., Laporte, V., Oliveira, T., Stoughton, A., Strub, P.-Y.: Machine-checked proofs for cryptographic standards: indifferentiability of sponge and secure high-assurance implementations of SHA-3. In: Cavallaro, L., Kinder, J., Wang, X., Katz, J. (eds.) ACM CCS 2019, pp. 1607\u20131622. ACM Press, Nov. (2019)","DOI":"10.1145\/3319535.3363211"},{"key":"14_CR2","doi-asserted-by":"crossref","unstructured":"Barbosa, M., Barthe, G., Bhargavan, K., Blanchet, B., Cremers, C., Liao, K., Parno B.: SoK: computer-aided cryptography. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 777\u2013795. IEEE Computer Society (2021)","DOI":"10.1109\/SP40001.2021.00008"},{"key":"14_CR3","doi-asserted-by":"crossref","unstructured":"Barbosa, M., Barthe, G., Fan, X., Gr\u00e9goire, B., Hung, S.-H., Katz, J., Strub, P.-Y., Wu, X., Zhou, L.: EasyPQC: verifying post-quantum cryptography. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, CCS 2021, New York, NY, USA, pp. 2564\u20132586. Association for Computing Machinery (2021)","DOI":"10.1145\/3460120.3484567"},{"key":"14_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1007\/978-3-642-32347-8_2","volume-title":"Interactive Theorem Proving","author":"G Barthe","year":"2012","unstructured":"Barthe, G., Crespo, J.M., Gr\u00e9goire, B., Kunz, C., Zanella B\u00e9guelin, S.: Computer-aided cryptographic proofs. In: Beringer, L., Felty, A. (eds.) ITP 2012. LNCS, vol. 7406, pp. 11\u201327. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-32347-8_2"},{"key":"14_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"180","DOI":"10.1007\/978-3-642-19074-2_13","volume-title":"Topics in Cryptology \u2013 CT-RSA 2011","author":"G Barthe","year":"2011","unstructured":"Barthe, G., Gr\u00e9goire, B., Lakhnech, Y., Zanella B\u00e9guelin, S.: Beyond provable security verifiable IND-CCA security of OAEP. In: Kiayias, A. (ed.) CT-RSA 2011. LNCS, vol. 6558, pp. 180\u2013196. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19074-2_13"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., H\u00fclsing, A., K\u00f6lbl, S., Niederhagen, R., Rijneveld, J., Schwabe, P.: The SPHINCS$$^+$$ signature framework. In: Cavallaro, L., Kinder, J., Wang, X., Katz, J. (eds.) ACM CCS 2019, pp. 2129\u20132146. ACM Press (2019)","DOI":"10.1145\/3319535.3363229"},{"key":"14_CR7","doi-asserted-by":"crossref","unstructured":"Bos, J.W., H\u00fclsing, A., Renes, J., van Vredendaal, C.: Rapidly verifiable XMSS signatures. IACR TCHES 2021(1), 137\u2013168 (2021). https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/8730","DOI":"10.46586\/tches.v2021.i1.137-168"},{"key":"14_CR8","doi-asserted-by":"crossref","unstructured":"Cooper, D., Apon, D., Dang, Q., Davidson, M., Dworkin, M., Miller, C.: Recommendation for stateful hash-based signature schemes (2020)","DOI":"10.6028\/NIST.SP.800-208"},{"key":"14_CR9","doi-asserted-by":"crossref","unstructured":"Cremers, C., Horvat, M., Hoyland, J., Scott, S., van der Merwe, T.: A comprehensive symbolic analysis of TLS 1.3. In: Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017, pp. 1773\u20131788. ACM Press (2017)","DOI":"10.1145\/3133956.3134063"},{"key":"14_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"637","DOI":"10.1007\/978-3-030-92062-3_22","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"AB Grilo","year":"2021","unstructured":"Grilo, A.B., H\u00f6velmanns, K., H\u00fclsing, A., Majenz, C.: Tight adaptive reprogramming in\u00a0the\u00a0QROM. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13090, pp. 637\u2013667. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_22"},{"key":"14_CR11","doi-asserted-by":"crossref","unstructured":"Grumbling, E., Horowitz, M.: Quantum Computing: Progress and Prospects. National Academies of Sciences, Engineering, and Medicine. The National Academies Press, 1st edn. (2019)","DOI":"10.17226\/25196"},{"key":"14_CR12","doi-asserted-by":"crossref","unstructured":"Huelsing, A., Butin, D., Gazdag, S.-L., Rijneveld, J., Mohaisen, A.: XMSS: eXtended Merkle Signature Scheme. RFC 8391 (2018)","DOI":"10.17487\/RFC8391"},{"key":"14_CR13","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-22972-5_1","volume-title":"Advances in Cryptology - ASIACRYPT 2022","author":"A H\u00fclsing","year":"2022","unstructured":"H\u00fclsing, A., Kudinov, M.: Recovering the tight security proof of SPHINCS$$^{+}$$. In: Agrawal, S., Lin, D. (eds.) Advances in Cryptology - ASIACRYPT 2022, pp. 3\u201333. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22972-5_1"},{"key":"14_CR14","doi-asserted-by":"publisher","first-page":"622","DOI":"10.1007\/978-3-031-15802-5_22","volume-title":"Advances in Cryptology - CRYPTO 2022","author":"A H\u00fclsing","year":"2022","unstructured":"H\u00fclsing, A., Meijers, M., Strub, P.-Y.: Formal verification of Saber\u2019s public-key encryption scheme in EasyCrypt. In: Dodis, Y., Shrimpton, T. (eds.) Advances in Cryptology - CRYPTO 2022, pp. 622\u2013653. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15802-5_22"},{"key":"14_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1007\/978-3-662-49384-7_15","volume-title":"Public-Key Cryptography \u2013 PKC 2016","author":"A H\u00fclsing","year":"2016","unstructured":"H\u00fclsing, A., Rijneveld, J., Song, F.: Mitigating multi-target attacks in hash-based signatures. In: Cheng, C.-M., Chung, K.-M., Persiano, G., Yang, B.-Y. (eds.) PKC 2016. LNCS, vol. 9614, pp. 387\u2013416. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-49384-7_15"},{"key":"14_CR16","doi-asserted-by":"crossref","unstructured":"Koblitz, N., Menezes, A.J.: Critical perspectives on provable security: fifteen years of \u201canother look\u201d papers. Adv. Math. Commun. 13(4), 517\u2013558 (2019)","DOI":"10.3934\/amc.2019034"},{"key":"14_CR17","unstructured":"Kudinov, M., Kiktenko, E., Fedorov, A.: [pqc-forum] round 3 official comment: Sphincs+ (2020). https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/post-quantum-cryptography\/documents\/round-3\/official-comments\/Sphincs-Plus-round3-official-comment.pdf. Accessed 1 Feb 2022"},{"key":"14_CR18","doi-asserted-by":"crossref","unstructured":"McGrew, D., Curcio, M., Fluhrer, S.: Leighton-Micali Hash-Based Signatures. RFC 8554 (2019)","DOI":"10.17487\/RFC8554"},{"key":"14_CR19","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/MSP.2018.3761723","volume":"16","author":"M Mosca","year":"2018","unstructured":"Mosca, M.: Cybersecurity in an era with quantum computers: will we be ready? IEEE Secur. Priv. 16, 38\u201341 (2018)","journal-title":"IEEE Secur. Priv."},{"key":"14_CR20","unstructured":"NIST. National Institute for Standards and Technology. announcing request for nominations for public-key post-quantum cryptographic algorithms (2016). https:\/\/csrc.nist.gov\/News\/2016\/Public-Key-Post-Quantum-Cryptographic-Algorithms"},{"key":"14_CR21","unstructured":"NIST. National Institute for Standards and Technology. PQC standardization process: Announcing four candidates to be standardized, plus fourth round candidates (2022). https:\/\/csrc.nist.gov\/News\/2022\/pqc-candidates-to-be-standardized-and-round-4"},{"key":"14_CR22","series-title":"pp","doi-asserted-by":"publisher","first-page":"501","DOI":"10.1007\/978-3-031-17234-2_23","volume-title":"Post-Quantum Cryptography","author":"R Perlner","year":"2022","unstructured":"Perlner, R., Kelsey, J., Cooper, D.: Breaking category five SPHINCS$$^{+}$$ with SHA-256. In: Cheon, J.H., Johansson, T. (eds.) Post-Quantum Cryptography. pp, pp. 501\u2013522. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-17234-2_23"},{"key":"14_CR23","series-title":"Part II, volume 11693 of LNCS","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-3-030-26951-7_9","volume-title":"CRYPTO 2019","author":"M Zhandry","year":"2019","unstructured":"Zhandry, M.: How to record quantum queries, and applications to quantum indifferentiability. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. Part II, volume 11693 of LNCS, pp. 239\u2013268. Springer, Heidelberg (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_9"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-38554-4_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,26]],"date-time":"2025-07-26T22:03:28Z","timestamp":1753567408000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-38554-4_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031385537","9783031385544"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-38554-4_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"9 August 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 August 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 August 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"43","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"479","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"124","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}