Skip to content

Feature/winternitz ots - #7621

Merged
alxkm merged 3 commits into
TheAlgorithms:masterfrom
dilaraacetin:feature/winternitz-ots
Sep 27, 2026
Merged

alxkm merged 3 commits into
TheAlgorithms:masterfrom
dilaraacetin:feature/winternitz-ots

Conversation

@dilaraacetin

Copy link
Copy Markdown
Contributor

Fixes #7620

What does this PR add?

This PR adds a Winternitz One-Time Signature (WOTS) implementation, the
size-optimized evolution of the recently added Lamport signature and the actual
building block of modern post-quantum signature standards such as XMSS (RFC 8391)
and SPHINCS+ (FIPS 205).

Implementation details

  • WinternitzSignature.java — self-contained, no external dependencies
    (java.security.MessageDigest + SecureRandom only)
  • Supports Winternitz parameter w ∈ {4, 16, 256} (default 16); chain counts
    len1, len2, len are derived from w rather than hard-coded
    (e.g. w=16 → len1=64, len2=3, len=67)
  • Base-w digit extraction and checksum computation shared between sign and
    verify via a single helper to guarantee symmetry
  • One-time property enforced: signing a second message with the same key pair
    throws IllegalStateException
  • Defensive copies of all key and signature material; input validation for
    null/malformed inputs and unsupported w values

Tests

WinternitzSignatureTest.java covers: valid signature verification for each
supported w (parameterized), chain-count derivation, tampered message and
tampered signature rejection, wrong key pair and mismatched w rejection,
one-time enforcement, null/invalid inputs, empty and multi-KB messages, and
immutability of returned key material.

Javadocs explain the algorithm, the role of the Winternitz parameter and the
checksum, why the scheme is quantum-resistant, the one-time limitation, and
include a @see reference to LamportSignature plus a Wikipedia link. The
implementation is for educational purposes only.


  • I have read CONTRIBUTING.md.
  • This pull request is all my own work -- I have not plagiarized it.
  • All filenames are in PascalCase.
  • All functions and variable names follow Java naming conventions.
  • All new algorithms have a URL in their comments that points to Wikipedia or other similar explanations.
  • All new algorithms include a corresponding test class that validates their functionality.
  • All new code is formatted with clang-format -i --style=file path/to/your/file.java

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 97.46835% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.49%. Comparing base (d291e7d) to head (a0597b3).

Files with missing lines Patch % Lines
...com/thealgorithms/ciphers/WinternitzSignature.java 97.46% 2 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##             master    #7621      +/-   ##
============================================
+ Coverage     81.46%   81.49%   +0.03%     
- Complexity     8053     8079      +26     
============================================
  Files           835      836       +1     
  Lines         25387    25466      +79     
  Branches       4950     4966      +16     
============================================
+ Hits          20681    20754      +73     
- Misses         3921     3924       +3     
- Partials        785      788       +3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@alxkm alxkm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Thank you for the contribution.

@alxkm
alxkm merged commit 550a7ed into TheAlgorithms:master Sep 27, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FEATURE REQUEST] Add Winternitz One-Time Signature (WOTS) — Hash-Based Post-Quantum Signature

3 participants