Skip to content
ContentLora

    Tip: press / anywhere to search.

    technology

    SLH-DSA (FIPS 205)

    Also known as FIPS 205, SPHINCS+, Stateless Hash-Based Digital Signature Algorithm

    SLH-DSA is the stateless hash-based digital signature algorithm NIST standardized as FIPS 205 in August 2024, derived from SPHINCS+, as a backup in case lattice-based ML-DSA proves vulnerable.[1][2][3] It relies only on hash functions but produces signatures of 7,856 to 49,856 bytes, several times larger than ML-DSA's.[4][5]

    Editor reviewedUpdated Post-quantum cryptography and securityComputing
    Key facts

    What it is

    SLH-DSA (Stateless Hash-Based Digital Signature Algorithm) is one of the three post-quantum standards NIST published on 13 August 2024, as FIPS 205.[1] It is based on SPHINCS+, an entry in NIST’s competition.[2] Like ml-dsa, it signs data so recipients can detect tampering and confirm who signed it. Its role is different, though. NIST describes it as a backup in case ML-DSA proves vulnerable.[3]

    Why hash-based matters

    Most post-quantum standards rely on structured lattices. SLH-DSA relies only on the security of hash functions.[6][2] Quantum computers only weaken hash functions modestly, through Grover’s algorithm, and larger outputs compensate.[7] That independence from lattices is why NIST keeps it as a backup.[3] Attacks on candidates do happen. The isogeny-based SIKE scheme was broken in 2022 after reaching NIST’s fourth round.[8]

    The trade-off

    Security comes at a price in size. FIPS 205 approves 12 parameter sets, each tuned for relatively small signatures (“s”) or relatively fast signing (“f”).[4] Public keys are tiny, 32 to 64 bytes. Signatures range from 7,856 to 49,856 bytes, several times larger than ML-DSA’s 2,420 to 4,627 bytes.[4][5] Each key pair can sign up to 2^64 messages.[9]

    In April 2026 NIST released a draft, SP 800-230, adding SLH-DSA parameter sets for cases where only a limited number of signatures is needed.[10]

    Where it fits

    SLH-DSA is supported in mainstream libraries; OpenSSL 3.5 added it alongside ML-KEM and ML-DSA in April 2025.[11] Signature size matters most where many signatures travel with each connection, as in the Web PKI, which the UK NCSC expects to be one of the hardest systems to migrate.[12] For the wider picture of how signatures are being migrated, see how post-quantum cryptography works and the migration timeline debate.

    How it is built

    FIPS 205 says SLH-DSA’s security relies on the presumed difficulty of finding preimages for hash functions, along with related properties of the same hash functions.[13] The scheme is assembled from hash-based building blocks: the WOTS+ one-time signature, the XMSS Merkle-tree scheme and the FORS few-time scheme, arranged in a “hypertree”. Each key pair contains billions of FORS keys, all generated pseudorandomly from a single seed.[14] Because so many keys are available, the signer does not have to keep track of which ones have been used. That is what “stateless” means.[14][9]

    Stateless versus stateful

    NIST already approves older, stateful hash-based signatures in SP 800-208. With those, the signer must keep a record of how often each key has been used.[15] NSA chose the SP 800-208 schemes for signing software and firmware under CNSA 2.0, a setting where keeping track of key use is practical.[15][16] SLH-DSA removes the need to track state, at the cost of the larger signatures described above.[4] For comparison, NSA expects software and firmware signing in US national security systems to use CNSA 2.0 algorithms, which for that purpose means the stateful SP 800-208 schemes, exclusively by 2030.[17][15]

    Questions readers ask

    Why have a second signature standard?

    NIST intends SLH-DSA as a backup in case ML-DSA proves vulnerable. It is based on hash functions rather than lattices.[3][2]

    What does "stateless" mean here?

    FIPS 205 defines SLH-DSA as a stateless hash-based scheme, and its parameter sets are designed so that one key pair can sign up to 2^64 messages.[2][9]

    What is SP 800-230?

    A draft NIST publication, released in April 2026, that adds SLH-DSA parameter sets for limited-signature use cases.[10]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      On 13 August 2024 NIST published its first three finalized post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). confirmedas of 2024-08-13

    2. [2]

      SLH-DSA is a stateless hash-based digital signature algorithm based on SPHINCS+. confirmedas of 2024-08-13

    3. [3]

      NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13

    4. [4]

      FIPS 205 approves 12 SLH-DSA parameter sets, tuned for either small signatures ("s") or fast signing ("f"), with public keys of 32 to 64 bytes and signatures from 7,856 to 49,856 bytes. confirmedas of 2024-08-13

    5. [5]

      ML-DSA's three parameter sets, ML-DSA-44, ML-DSA-65 and ML-DSA-87, have public keys of 1,312, 1,952 and 2,592 bytes and signatures of 2,420, 3,309 and 4,627 bytes. confirmedas of 2024-08-13

    6. [6]

      Of the four algorithms NIST first selected, three are based on structured lattices and one on hash functions, math problems experts believe are hard for both classical and quantum computers. confirmedas of 2026-10-10

    7. [7]

      Grover's algorithm gives only a quadratic speed-up against symmetric-key systems, and NIST judged that doubling the key size would be enough to preserve their security. confirmedas of 2026-10-10

    8. [8]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    9. [9]

      The SLH-DSA parameter sets in FIPS 205 were designed for key pairs that sign up to 2^64 messages. confirmedas of 2024-08-13

    10. [10]

      On 13 April 2026 NIST released the initial public draft of SP 800-230, adding SLH-DSA parameter sets for limited signature use cases. confirmedas of 2026-04-13

    11. [11]

      OpenSSL 3.5, released on 8 April 2025, added support for ML-KEM, ML-DSA and SLH-DSA. confirmedas of 2025-04-08

    12. [12]

      The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20

    13. [13]

      FIPS 205 says SLH-DSA's security relies on the presumed difficulty of finding preimages for hash functions and related properties of those hash functions. confirmedas of 2024-08-13

    14. [14]

      SLH-DSA is built from hash-based components - the WOTS+ one-time signature, the XMSS Merkle-tree scheme and the FORS few-time scheme - arranged in a hypertree, and each key pair holds billions of FORS keys generated pseudorandomly from a single seed. confirmedas of 2024-08-13

    15. [15]

      Separately from FIPS 205, NIST SP 800-208 approves stateful hash-based signature schemes, which require the signer to track key use; NSA's CNSA 2.0 picked the SP 800-208 schemes for software and firmware signing. confirmedas of 2024-08-13

    16. [16]

      CNSA 2.0 lists CRYSTALS-Kyber (standardised as ML-KEM) for key establishment and CRYSTALS-Dilithium (ML-DSA) for signatures, at their highest (Level V) parameters for all classification levels, and NIST SP 800-208 hash-based signatures for software and firmware signing. confirmedas of 2022-09-07

    17. [17]

      NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07

    Revision history (2)
    1. Page created.
    2. Added how SLH-DSA is built, its security assumption and its relation to stateful hash-based signatures.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "SLH-DSA (FIPS 205)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/slh-dsa

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.