freenode
Security & Cryptography

Conformance vectors offered for stateful HBS key state checks

An open test suite targets ACID guarantees for hash-based signature state as NIST revises SP 800-208 to allow private key export.

Angel has published an open conformance bench for stateful hash-based signature (HBS) private-key state management and offered it as input to NIST's planned revision of SP 800-208.

In late 2024 NIST said it intends to revise the publication so private keys can leave a module while still mitigating the core risk: once the key is exported, nothing enforces correct handling of its one-time-use state. Stateful schemes such as XMSS burn signature indices permanently; a counter that falls behind the actual key, or a restore that reuses an index, can silently exhaust security.

RFC 10033 already requires four ACID properties over that state and notes that rollback-resistant counters are hard in pure software, yet it supplies no test that an implementation actually meets them. Angel's suite fills the gap. It defines the four reachable outcomes when a stored counter is compared with the key's true index, isolates the single lethal case (key ahead of counter), and supplies 18 executable vectors plus a small command-line protocol. A runner scores subjects at four conformance levels; level 0 simply forces the implementer to declare whether the private key is persisted or seed-derived, because the two behave differently after restart.

The judgement logic is a zero-dependency Rust extraction of the guard Angel used while running XMSSMT-SHA2_40/8_256 in a research settlement ledger. The work is presented as concrete material for the SP 800-208 revision rather than a finished standard.