SLH-DSA (Stateless Hash-Based Digital Signature Algorithm), standardised as NIST FIPS 205 in August 2024, is the post-quantum signature standard based on hash functions rather than lattice problems. Where ML-DSA and ML-KEM both rest their security on the hardness of Module Learning With Errors — a relatively young mathematical assumption first formulated in 2005 — SLH-DSA’s security rests exclusively on the collision resistance and preimage resistance of an underlying hash function (SHA-256, SHA-512, or SHAKE, depending on parameter set). Hash function security against quantum computers is well-understood: Grover’s algorithm provides at most a quadratic speedup, which is fully mitigated by doubling output size (SHA-256 remains adequate against classical attacks; SHA-512 provides AES-256-equivalent quantum resistance). The decades-long cryptanalytic confidence in SHA-2 and SHA-3 makes SLH-DSA’s security argument the most conservative available: it requires no new mathematical assumption beyond the hash functions already trusted throughout the entire cryptographic stack.
SLH-DSA is derived from SPHINCS+, the hash-based signature scheme that NIST selected as its conservative, non-lattice alternative during the PQC standardisation process. Its construction chains together several cryptographic primitives: WOTS+ (Winternitz One-Time Signatures Plus) for signing individual messages with disposable key pairs, FORS (Forest of Random Subsets) for signing indices into a hypertree structure, and a hypertree of Merkle trees whose root commits to all possible signing key pairs. The “stateless” in the name is the critical property that distinguishes SLH-DSA from older hash-based schemes like XMSS: the signer does not need to maintain state about which one-time keys have been used, eliminating the catastrophic key-reuse vulnerability of stateful hash-based schemes. Instead, the one-time key used for each signature is derived deterministically from the private key and a random (or message-derived) index, making SLH-DSA safe to use with standard key management infrastructure and in multi-signer or distributed signing scenarios. NIST defines twelve parameter sets across two security/speed trade-off axes — small (smaller signatures, slower signing) and fast (larger signatures, faster signing) — at security levels 1, 3, and 5. Representative sizes for the recommended level-3 fast variant (SLH-DSA-SHAKE-192f): 48-byte public key, 35,664-byte signature. The tiny public key is SLH-DSA’s standout property; the large signature is its primary operational disadvantage.
SLH-DSA’s role in the PQC deployment strategy is as a diversity anchor, not a primary workhorse. ML-DSA is faster to sign, faster to verify, and produces signatures 10–15× smaller; it is the recommended default replacement for ECDSA and RSA signatures. SLH-DSA is the answer to “what do we use if a structural weakness in lattice-based cryptography is discovered?” — maintaining a parallel SLH-DSA signature on critical, long-lived artifacts (firmware images, root CA certificates, code signing certificates with multi-year validity) ensures that those artifacts remain secure even if the ML-DSA lattice assumption is broken. The deployment pattern for high-assurance signing infrastructure is therefore: sign with ML-DSA-65 as the primary algorithm and SLH-DSA-SHAKE-192s (small, conservative) as the secondary algorithm, and publish both signatures as separate OCI referrers or alongside the ML-DSA signature in the signing envelope. Verifiers can accept either, giving the signed artifact a defence-in-depth property across two independent mathematical foundations. For certificate authorities with decade-long root CA lifetimes, the small SLH-DSA public key (48 bytes) is attractive for root CA self-signatures: the root certificate itself can carry an SLH-DSA self-signature that is quantum-safe and requires no new mathematical trust, at the cost of a larger certificate file (dominated by the SLH-DSA signature, not the key).
