PQCWC: Post-Quantum Cryptography Winternitz-Chen Anonymous Scheme
Abel C. H. Chen
Information & Communications Security Laboratory, Chunghwa Telecom Laboratories, Taoyuan, Taiwan
E-mail: chchen.scholar@gmail.com
Received 19 March 2026; Accepted 11 June 2026
As quantum computing technology matures, it poses a threat to the security of mainstream asymmetric cryptographic methods. In response, the National Institute of Standards and Technology released the final version of post-quantum cryptographic (PQC) algorithm standards in August 2024. These post-quantum cryptographic algorithms are primarily based on lattice-based and hash-based cryptography. Therefore, this study proposes the Post-Quantum Cryptography Winternitz-Chen (PQCWC) anonymous scheme, aimed at exploring the design of anonymous schemes based on PQC for future applications in privacy protection. The anonymous scheme designed in this study is mainly built on the Winternitz signature scheme, which can prevent the original public key from being exposed in the certificate. Furthermore, the PQCWC anonymous scheme integrates the butterfly key expansion mechanism, introducing the world’s first hash-based butterfly key expansion mechanism, achieving anonymity for both the registration authority and the certificate authority, thereby fully protecting privacy. In the experimental environment, this study compares various hash algorithms, including Secure Hash Algorithm-1 (SHA-1), the SHA-2 series, the SHA-3 series, and the BLAKE series. The results demonstrate that the proposed anonymous scheme can achieve anonymity without increasing key length, signature length, key generation time, signature generation time, or signature verification time.
Keywords: Post-quantum cryptography, anonymous scheme, hash-based cryptography, Winternitz signature scheme.
Quantum computing technology has been rapidly advancing, and with the suitable quantum algorithms, computational efficiency has the potential to achieve exponential acceleration [1]. For instance, Shor quantum algorithm [2] can quickly find hidden subgroups and their periods through quantum Fourier transform [3], enabling the rapid solution of factorization and discrete logarithm problems [4]. However, current mainstream asymmetric cryptography methods (e.g. RSA and elliptic curve cryptography (ECC)) rely on the security of these problems. With quantum computing, this security could be quickly compromised [5]. Therefore, asymmetric cryptography based on factorization and discrete logarithm problems is no longer considered secure [6]. In light of this, the National Institute of Standards and Technology (NIST) has, in recent years, been working towards establishing standards for post-quantum cryptography (PQC) [7]. NIST has solicited submissions for various algorithms based on lattice-based cryptography [8], hash-based cryptography [9], code-based cryptography [10], and multivariate-based cryptography [11] from around the world. In August 2024, NIST finalized the standards for PQC algorithms, including the Stateless Hash-based Digital Signature Algorithm (SLH-DSA) [12], the Module-Lattice-based Digital Signature Algorithm (ML-DSA) [13], and the Module-Lattice-based Key Encapsulation Mechanism (ML-KEM) [14]. Furthermore, several PQC applications have been developed, including in vehicular-to-everything (V2X) communications [15], the Internet of Things (IoT) [16], and blockchain [17]. Among these standard algorithms, the SLH-DSA is a type of hash-based cryptographic algorithm. Due to the irreversible nature of hashing, hash-based cryptography is mainly applied in digital signatures, making it unsuitable for key encapsulation.
The current certificate formats, such as X.509 certificates [18] and Security Credential Management System (SCMS) certificates [19] in V2X communications, have established standards and specifications. When updating to post-quantum cryptographic algorithms, the primary modification involves changing the Object Identifier (OID) of the algorithm in the certificate format. The corresponding public key of the end entity to be signed is placed in the public key field, and the issuer generates the signature for the to-be-signed data and places it in the signature field. However, since the public key is included in the certificate, it could potentially allow an attacker to track the user associated with the same public key in the user’s certificate in subsequent applications. The attacker could then analyze all messages signed with the corresponding private key, raising concerns about user privacy exposure. To address this, the IEEE 1609.2.1 standard [20] introduced the butterfly key expansion (BKE) mechanism [21]. This mechanism protects the user’s original public key (referred to as the “caterpillar public key” in this context) by expanding it into “cocoon public keys” and “butterfly public keys.” It ensures that the butterfly public key cannot be traced back to the caterpillar public key, thus safeguarding user privacy. However, the BKE mechanism defined in the IEEE 1609.2.1 standard is primarily built on ECC, which relies on the properties of elliptic curves for key expansion. This method is vulnerable to quantum computing attacks and, therefore, cannot provide quantum-safe security levels.
In light of the need for privacy protection and quantum-safe security, this study proposes a PQC anonymous scheme based on hash-based cryptography, named Post-Quantum Cryptography Winternitz-Chen (PQCWC). The proposed method primarily leverages the Winternitz one-time signature scheme [22] to design an anonymous certificate solution, incorporating the BKE mechanism to provide privacy protection, while ensuring quantum-safe security through the properties of hash-based cryptography. The contributions of this study are outlined as follows:
• This study proposes the PQCWC scheme, which provides an anonymous scheme based on hash-based cryptography that ensures quantum-safe security.
• This study proposes the world’s first hash-based butterfly key expansion (HBKE) mechanism, which achieves anonymity for every end entity in the system, including the registration authority (RA) and certificate authority (CA), thus fully protecting privacy.
• This study compares various hash algorithms, including Secure Hash Algorithm-1 (SHA-1), the SHA-2 series, the SHA-3 series, and the BLAKE series, demonstrating that the proposed anonymous scheme achieves anonymity without increasing key length, signature length, key generation time, signature generation time, or signature verification time.
This paper is divided into six sections. Section 2 reviews the existing methods, including a literature review, and introduces the Winternitz one-time signature method, the known certificate request and response process, and the IEEE 1609.2.1 BKE mechanism. Section 3 presents the PQC anonymous scheme (i.e. PQCWC scheme) designed in this study and explains how key expansion is achieved based on the characteristics of hash-based cryptography. Section 4 proposes the HBKE mechanism proposed in this study, detailing how to achieve BKE within the PQCWC scheme by expanding the hash-based caterpillar key into a hash-based cocoon public key, and further into a hash-based butterfly public key. Section 5 provides a performance comparison, constructing the proposed PQCWC and the HBKE mechanism with different hash algorithms and comparing computational efficiency. Finally, Section 6 summarizes the findings of this study and discusses possible future research directions.
This section first introduces the Winternitz one-time signature method, followed by an explanation of the well-known certificate request and response process, and a discussion of its anonymity and privacy issues. Lastly, the BKE mechanism designed in IEEE 1609.2.1 and its approach to privacy protection will be presented.
The Winternitz one-time signature method is a classic hash-based cryptographic approach. It begins by assuming that the length of the data to be signed, denoted as D, is limited to bits. The data is then divided into elements by splitting every bits into a single data element. This divides the data D into a sequence of m data elements, represented as , where . Subsequently, a signature value element is generated for each data element individually [22, 23]. The length of each signature value element, denoted as , varies depending on the hash algorithm used, resulting in a total signature length of . The detailed steps are described as follows.
During the key generation phase, a sequence of m random integer elements, denoted as , is generated as the private key. For each integer element in the private key, hash computations are performed to obtain a sequence of m hash value elements, denoted as , where is the hash function. The value of is the result of performing hash computations on .
Therefore, as the value of increases, the number of hash computations required to generate the public key increases exponentially. Conversely, if the value of is smaller, although fewer hash computations are needed and the public key generation is faster, the number of elements in the sequence m will increase, leading to a growth in both private key length and public key length. Furthermore, while a smaller value speeds up computations, it may also increase the risk of the key being compromised more quickly. Therefore, selecting an appropriate value for is an important consideration.
During the signature generation phase, the data to be signed, D, is obtained and divided into a sequence of data elements. Since the data elements are segmented according to the bits length, each data element falls within the range . The private key element undergoes hash computations to produce the signature value element . Similarly, hash computations are performed on each private key element to obtain the signature value sequence .
The computation time for this process is similar to that of key generation and depends on the value of . As increases, the number of hash computations required for generating the signature increases exponentially. Conversely, if is smaller, the value of m increases, resulting in a larger number of signature value elements and a longer signature sequence.
During the signature verification phase, the data to be signed, D, the signature values, S, and the public key, B, are obtained. For each signature value element hash computations are performed to produce the verification value element . This process is repeated for each signature value element to obtain the verification value sequence . If each verification value element matches its corresponding public key element, then the verification is successful, i.e., .
In the basic public key infrastructure (PKI), a CA issues certificates to end entities. The end entity generates a certificate signing request (CSR) for the CA, which includes information about the end entity, the end entity’s public key, and a list of requested permissions. After reviewing the end entity’s credentials, the CA issues the end entity’s certificate, which contains the end entity’s information, public key, and permission list [24].
Furthermore, to manage the PKI, a RA is established to review the end entity’s credentials and generate the corresponding CSR for the CA. This setup clarifies the division of roles among the entities. The RA handles communication with end entities and verifies their credentials, playing a crucial auditing role in various applications. The CA is responsible for producing end entity certificates based on the CSR [25].
However, in the current PKI system, the issued certificates for end entities include the end entity’s original public key. Consequently, if an attacker collects all messages verified with the same public key, it could lead to privacy exposure issues for the user.
Since privacy is especially important for end entities in the V2X communications, effective privacy protection measures are required. The IEEE 1609.2.1 standard proposes the BKE mechanism [20, 21], which uses key expansion to avoid storing the original public key (i.e. the caterpillar key) in the certificate, thereby achieving the goal of privacy protection. This study focuses on explicit certificates, and implicit certificates are not within the scope of this study. Further details are provided below.
The end entity generates two sets of original key pairs: the caterpillar key pair for signing and the caterpillar key pair for encryption. The signing caterpillar key pair consists of the signing caterpillar private key and the signing caterpillar public key ; the encryption caterpillar key pair consists of the encryption caterpillar private key and the encryption caterpillar public key . In the IEEE 1609.2.1 standard, ECC is primarily used for asymmetric cryptography. Assuming the elliptic curve base point is , and the order of the elliptic curve is , the signing caterpillar public key is , and the encryption caterpillar public key is . Futhermore, to establish the same key expansion function and parameter values with the RA, two Advanced Encryption Standard (AES) keys, and , are generated. The end entity can then encapsulate the signing caterpillar public key , the encryption caterpillar public key , the AES keys and , along with the end entity information and the requested permission list into an EeRaCertRequest packet to be sent to the RA [20].
When the RA receives the EeRaCertRequest packet, it can use the AES key and key expansion function to generate a pseudorandom number , and use the AES key and key expansion function to generate a pseudorandom number . The value represents a time period known to both the RA and the end entity, with the detailed calculation defined in the IEEE 1609.2.1 standard [20]. The RA can then expand the signing caterpillar public key based on the pseudorandom number into the signing cocoon public key , and expand the encryption caterpillar public key based on the pseudorandom number into the encryption cocoon public key . Finally, the RA sends the signing cocoon public key , the encryption cocoon public key , and the requested permission list to the CA.
When the CA receives the request packet, it generates a random number , and uses this random number to expand the signing cocoon public key into the signing butterfly public key . The CA then issues the end entity certificate, placing the butterfly public key in the public key field and the corresponding permission list in the permission field. The CA encrypts the end entity certificate and the random number using the encryption cocoon public key , resulting in the ciphertext , which is then returned to the RA.
When the RA receives the message, it forwards the message to the end entity. The end entity uses the shared known time period and the expansion functions to generate the pseudorandom numbers and , and based on these pseudorandom numbers, produces the signing cocoon private key and the encryption cocoon private key . The encryption cocoon private key is then used to decrypt the ciphertext , revealing the plaintext contents, which include the end entity certificate and the random number . Finally, the signing cocoon private key is expanded using the random number to generate the butterfly private key , which pairs with the butterfly public key in the end entity. In practical applications, the end entity can use the butterfly private key to sign a secure protocol data unit (SPDU), and other end entities can verify the signature using the butterfly public key .
In light of the privacy concerns caused by traditional certificate schemes [24, 25] storing the original public keys of end entities, this study proposes the PQCWC anonymous schemes. These schemes achieve privacy protection by storing the expanded public key in the certificate instead of the original public key through a key expansion mechanism.
To accommodate different application needs, this study presents two PQCWC anonymous schemes that can be chosen based on the application field. Sections 3.1 and 3.2 describe the processes of PQCWC anonymous schemes 1 and 2, respectively, and Section 3.3 mathematically proves the proposed PQCWC anonymous schemes.
The proposed PQCWC anonymous schemes are based on the following assumptions:
• Communication between the end entity and the CA is established through a secure connection.
• The end entity and the CA share known parameters and a pseudorandom number generator.
• The CA has an encryption key pair (including private key and public key ). The CA’s encryption key pair can be implemented using a ML-KEM [14] to achieve quantum-level security. Furthermore, the end entity knows the CA’s encryption public key .
The process of the proposed PQCWC Anonymous Scheme 1 is illustrated in Figure 1. It includes the generation of the signing key pair by the end entity, the generation of the expanded public key and anonymous certificate by the CA, and the generation of the expanded private key by the end entity.
Figure 1 The proposed PQCWC anonymous scheme 1.
The end entity generates a hash-based signing key pair, consisting of a signing private key and a signing public key , as defined in Section 2.1. The end entity then packages the signing public key , along with the relevant end entity information I to be signed, into a certificate request packet and sends it to the CA.
Upon receiving the certificate request packet and verifying the end entity eligibility, the CA uses the shared parameter , known to both the CA and the end entity, to expand the signing public key . The expanded public key is generated, where is the hash function, and is the result of applying hash computations on each . The CA then produces the anonymous certificate of the end entity based on the expanded public key and the relevant end entity information I, and returns it to the end entity.
After receiving the anonymous certificate, the end entity generates the expanded private key . The end entity can then use the expanded private key to generate signatures, and other end entities can verify the signatures using the expanded public key from the anonymous certificate.
The process of the proposed PQCWC Anonymous Scheme 2, as shown in Figure 2, includes the generation of a signing key pair and AES key by the end entity, the generation of the expanded public key and anonymous certificate by the CA, and the generation of the expanded private key by the end entity.
Figure 2 The proposed PQCWC anonymous scheme 2.
The end entity generates a signing key pair based on a hash function, consisting of the signing private key and the signing public key , as defined in Section 2.1. Furthermore, the end entity generates an AES key , which is encrypted using the CA’s encryption public key , resulting in the ciphertext . The end entity then packages the signing public key , the ciphertext , and the relevant information to be signed, into a certificate request packet and sends it to the CA.
Upon receiving the certificate request packet and confirming the end entity eligibility, the CA decrypts the ciphertext using its private key , obtaining the plaintext AES key . The CA then generates a random number and uses it as the seed for a pseudorandom number generator, producing a sequence of pseudorandom elements , where each element lies within the range . The signing public key is expanded to generate the expanded public key , where is a hash function and is the result of applying hash computations to . The CA then generates the anonymous certificate of the end entity based on the expanded public key and the relevant end entity information , and encrypts the random number with the AES key , returning the ciphertext to the end entity.
Upon receiving the ciphertext containing , the end entity decrypts it using the AES key , sets as the seed for the pseudorandom number generator, and produces a sequence of m pseudorandom elements , with each element lying within the range . The signing private key is expanded to generate the expanded private key . The end entity can then use the expanded private key to generate signatures, and other end entities can verify the signatures using the expanded public key .
This section provides the theoretical proofs for the two proposed PQCWC anonymous schemes.
The relationship between the expanded public key and the expanded private key in the proposed PQCWC Anonymous Scheme 1 can be proven using Equation (3.3.1). It can be observed that each expanded private key element , after hash calculations, becomes the expanded public key element . Each expanded private key element maintains exactly hash calculations with its corresponding expanded public key element.
| (1) |
When generating a signature, the expanded private key can be used to sign the data to be signed , as shown in Equation (2). During signature verification, the expanded public key can be used to verify the signature . As shown in Equation (3), when the signature is correct, each verification value element will match its corresponding public key element.
| (2) | ||
| (3) |
The relationship between the expanded public key and the expanded private key in the proposed PQCWC Anonymous Scheme 2 can be proven using Equation (4). It can be observed that each expanded private key element , after hash calculations, becomes the expanded public key element . Each expanded private key element maintains exactly hash calculations with its corresponding expanded public key element. It is worth mentioning that PQCWC Anonymous Scheme 1 can be considered a special case of PQCWC Anonymous Scheme 2, where any element is equal to .
| (4) |
When generating a signature, the expanded private key can be used to sign the data to be signed , as shown in Equation (5). During signature verification, the expanded public key can be used to verify the signature . As shown in Equation (6), when the signature is correct, each verification value element will match its corresponding public key element.
| (5) | ||
| (6) |
The PQCWC anonymous schemes proposed in Section 3 provides anonymity to other end entities but not to the CA. The CA can still identify the relationship between the expanded public key and the original public key. To achieve anonymity even from the CA, this study proposes a hash-based BKE mechanism (shown in Figure 3) built on the proposed PQCWC anonymous scheme. By performing one key expansion at the RA and another at the CA, this mechanism ensures anonymity from the RA, the CA, and other end entities. Below is a detailed explanation of the hash-based BKE mechanism and its proof of concept.
The hash-based BKE mechanism is primarily built on the proposed PQCWC anonymous scheme. Since PQCWC Anonymous Scheme 1 is a special case of PQCWC Anonymous Scheme 2, the following description uses PQCWC Anonymous Scheme 2 as an example.
Figure 3 The proposed hash-based butterfly key expansion mechanism.
The proposed hash-based BKE mechanism is based on the following assumptions:
• Communication between the end entity, RA, and CA is established over a secure communication channel.
• The end entity and the RA share a commonly known time period .
• The end entity, RA, and CA share a commonly known pseudorandom number generator.
• The RA has an encryption key pair, and the end entity is aware of the RA’s public encryption key.
• The CA has an encryption key pair, and the end entity is aware of the CA’s public encryption key.
The process of the proposed hash-based BKE mechanism is illustrated in Figure 3. It involves the end entity generating the caterpillar key pair and AES keys, the RA generating the cocoon public key, the CA generating the butterfly public key and anonymous certificate, and the end entity generating the butterfly private key.
The end entity generates a hash-based key pair for signing, which includes the caterpillar private key and the caterpillar public key , as defined in Section 2.1. Additionally, two AES keys, and qCA, are generated. The AES key is encrypted using the registration authority’s public encryption key, resulting in the ciphertext , and the AES key is encrypted using the certificate authority’s public encryption key, resulting in the ciphertext ’. The end entity then packages the caterpillar public key , the ciphertexts and , along with the relevant signing information I, into a certificate request packet and sends it to the registration authority.
After receiving the certificate request packet and verifying the end entity’s eligibility, the RA retrieves the relevant information from the signing request data , which includes the permission list for the request. The RA then uses its private encryption key to decrypt the ciphertext , obtaining the plaintext (i.e., the AES key , the RA encrypts the shared known time period , producing the ciphertext , and sets as the seed for a pseudorandom number generator. The RA generates a sequence of pseudorandom elements , where each pseudorandom element falls within the range . The RA then expands the caterpillar public key , producing the cocoon public key , where is a hash function, and the value of is the result of performing hash computations on . The RA then sends the cocoon public key , the permission list , and the ciphertext to the CA.
The CA receives the packet and uses its private encryption key to decrypt the ciphertext , obtaining the plaintext (i.e., the AES key ). The CA generates a random number , which is set as the seed for a pseudorandom number generator. The CA then produces a sequence of pseudorandom elements , with each pseudorandom element falling within the range . The CA expands the cocoon public key , producing the butterfly public key , where is a hash function, and the value of is the result of performing hash computations on . The CA then generates an anonymous certificate Cert for the end entity based on the butterfly public key and the permission list J. Finally, the CA encrypts the anonymous certificate Cert and the random number using the AES key to produce the ciphertext Z, which is sent back to the registration authority.
After the end entity receives the ciphertext , it uses the AES key to decrypt and obtain the anonymous certificate Cert and the random number . The end entity then uses the AES key to encrypt the commonly known time period , producing the ciphertext . This is set as the seed for a pseudorandom number generator, which generates a sequence of pseudorandom elements , with each element restricted to the range . Next, the end entity expands the caterpillar private key , producing the cocoon private key , where is a hash function, and the value of is the result of performing hash computations on . Then, the end entity sets as the seed for a pseudorandom number generator, which produces a sequence of m pseudorandom elements , again within the range . The end entity then expands the cocoon private key to generate the butterfly private key , where is a hash function, and the value of is the result of performing hash computations on . Subsequently, the end entity can use the butterfly private key to produce a signature, and other end entities can verify the signature using the butterfly public key .
The relationship between the butterfly public key and butterfly private key based on the hash butterfly key expansion can be proven using Equation (7). It can be observed that each butterfly private key element , after hash computations, becomes the corresponding butterfly public key element . The relationship between each butterfly private key element and its corresponding butterfly public key element maintains a consistent hash computations. When generating a signature, the butterfly private key can be used to sign the data to be signed , as shown in Equation (8). When verifying the signature, the butterfly public key can be used to verify the signature . As shown in Equation (9), when the signature is correct, each verification element will match its corresponding public key element.
| (7) | ||
| (8) | ||
| (9) |
This section will compare the proposed method in terms of security and computational efficiency to verify its feasibility. First, the experimental environment will be described, followed by a security comparison with state-of-the-art (SOTA) methods and an evaluation of the computational efficiency of the proposed method using various hashing algorithms.
To practically verify the efficiency of the PQC anonymous schemes proposed in this study, a Windows 10 Enterprise Edition computer was used to simulate the end entity, RA, and CA. The key generation time, key expansion time, signature generation time, and signature verification time were evaluated. The detailed specifications of the software and hardware used in the experiment include a CPU Intel(R) Core(TM) i7-10510U, 8 GB of memory, OpenJDK 18.0.2.1, and the Bouncy Castle Release 1.72 library. This study compares various hashing algorithms, including SHA-1, the SHA-2 family, the SHA-3 family, and the BLAKE family, demonstrating that the proposed anonymous schemes can achieve anonymity without increasing key length, signature length, key generation time, signature generation time, or signature verification time.
In terms of security, the BKE mechanism in the IEEE 1609.2.1 standard provides anonymity, including anonymity from other end entities and CA [20, 21]. However, since the BKE mechanism in IEEE 1609.2.1 is primarily based on ECC, it may be vulnerable to quantum computing attacks and cannot achieve quantum-safe security levels. The schemes in [22, 23] are mainly built on hash-based cryptography and can achieve quantum-safe security level. However, these schemes include the original public key in the certificate, which can pose privacy risks, as shown in Table 1.
Table 1 The comparison of security
| Privacy Protection | |||
| Anonymous to Other | Anonymous | ||
| Scheme | Quantum-Safe | End Entities | to CA |
| [20] | x | x | |
| [21] | x | x | |
| [22] | x | ||
| [23] | x | ||
| The Proposed PQCWC Scheme 1 | x | x | |
| The Proposed PQCWC Scheme 2 | x | x | |
| The Proposed Hash-based BKE | x | x | x |
The proposed PQCWC anonymous schemes in this study are primarily based on hash-based cryptography, enabling it to achieve quantum-safe security levels while allowing for key expansion. This means that even without using the BKE mechanism, it can provide anonymity from other end entities. Furthermore, based on the PQCWC anonymous schemes, this study proposes a hash-based BKE mechanism, enabling anonymity from the RA and the CA and providing enhanced privacy protection.
In the experimental environment, this study assumes that the data to be signed, D, is of a fixed length of 256 bits (which could be the digest value after computing the original data using SHA-256). Each private key element is also 256 bits long. A comparison is made between cases where the lengths of are 8 bits or 16 bits, with the signature lengths shown in Tables 2 and 3. The number of elements, , in the private key sequence, public key sequence, and signature sequence primarily depends on the length of the data D and the length of . The hash algorithm used will determine the length of each element in the signature sequence, which, in turn, determines the total length of the signature sequence. For example, when is 8 bits, is 32, and the hash value length for SHA-1 is 160 bits. Therefore, the signature sequence contains 32 hash values, each of 160 bits, resulting in a total length of 5120 bits (i.e., 640 bytes). As observed in Tables 2 and 3, the proposed method does not increase the signature length, achieving anonymity within the same length. Additionally, although increasing the length can reduce the signature length, the computation time will increase exponentially, which will be discussed in detail in subsequent sections.
Table 2 The comparison of signature lengths () (unit: bits)
| Hash Algorithm | Hash Value Length | [22, 23] | The Proposed Method | ||
| SHA-1 | 160 | 8 | 32 | 5120 | 5120 |
| SHA-224 | 224 | 8 | 32 | 7168 | 7168 |
| SHA-256 | 256 | 8 | 32 | 8192 | 8192 |
| SHA-384 | 384 | 8 | 32 | 12288 | 12288 |
| SHA-512 | 512 | 8 | 32 | 16384 | 16384 |
| SHA3-224 | 224 | 8 | 32 | 7168 | 7168 |
| SHA3-256 | 256 | 8 | 32 | 8192 | 8192 |
| SHA3-384 | 384 | 8 | 32 | 12288 | 12288 |
| SHA3-512 | 512 | 8 | 32 | 16384 | 16384 |
| BLAKE2-256 | 256 | 8 | 32 | 8192 | 8192 |
| BLAKE2-384 | 384 | 8 | 32 | 12288 | 12288 |
| BLAKE2-512 | 512 | 8 | 32 | 16384 | 16384 |
Table 3 The comparison of signature lengths () (unit: bits)
| Hash Algorithm | Hash Value Length | [22, 23] | The Proposed Method | ||
| SHA-1 | 160 | 16 | 16 | 2560 | 2560 |
| SHA-224 | 224 | 16 | 16 | 3584 | 3584 |
| SHA-256 | 256 | 16 | 16 | 4096 | 4096 |
| SHA-384 | 384 | 16 | 16 | 6144 | 6144 |
| SHA-512 | 512 | 16 | 16 | 8192 | 8192 |
| SHA3-224 | 224 | 16 | 16 | 3584 | 3584 |
| SHA3-256 | 256 | 16 | 16 | 4096 | 4096 |
| SHA3-384 | 384 | 16 | 16 | 6144 | 6144 |
| SHA3-512 | 512 | 16 | 16 | 8192 | 8192 |
| BLAKE2-256 | 256 | 16 | 16 | 4096 | 4096 |
| BLAKE2-384 | 384 | 16 | 16 | 6144 | 6144 |
| BLAKE2-512 | 512 | 16 | 16 | 8192 | 8192 |
It is worth mentioning that although the private key sequence consists of elements, it is possible to store only a 256-bit random number as the seed for the pseudorandom number generator, which can then generate the elements of the private key. Similarly, while the public key sequence also consists of elements, the entire public key sequence can be hashed using SHA-256, reducing the public key length to 256 bits. Therefore, since both the private and public keys in hash-based cryptography can be relatively short, this study does not delve deeply into the length of private and public keys.
In this section, to compare the computation time for key generation and the computation time for the proposed PQCWC anonymous schemes (i.e., key expansion), different hash algorithms (i.e., the hash function mentioned in previous sections) are used to generate 1000 keys and 1000 expanded keys, respectively. For a fair comparison, the same values of and are used, and the results for individual elements are shown in Tables 4 and 5. From the experimental results, it can be observed that the key generation time mainly depends on hash computations, while the key expansion time mainly depends on hash computations. Therefore, when the values of and are the same, there is little difference between the key generation time and the key expansion time for the PQCWC Anonymous Scheme 1. Additionally, since the PQCWC Anonymous Scheme 2 uses random numbers in the range [0, ] for expansion, the computation time is lower than that of key generation. To better visualize the differences between the various schemes, Figures 4 and 5 present box plots of the experimental results.
Table 4 The comparison of key generation and key expansion () (unit: milliseconds)
| Key Expansion Based | Key Expansion Based | ||
| Hash Algorithm | Key Generation | on PQCWC Scheme 1 | on PQCWC Scheme 2 |
| SHA-1 | 0.085 | 0.079 | 0.041 |
| SHA-224 | 0.110 | 0.104 | 0.053 |
| SHA-256 | 0.129 | 0.120 | 0.059 |
| SHA-384 | 0.166 | 0.155 | 0.077 |
| SHA-512 | 0.146 | 0.142 | 0.072 |
| SHA3-224 | 0.250 | 0.241 | 0.122 |
| SHA3-256 | 0.302 | 0.286 | 0.141 |
| SHA3-384 | 0.220 | 0.212 | 0.111 |
| SHA3-512 | 0.324 | 0.313 | 0.160 |
| BLAKE2-256 | 0.130 | 0.121 | 0.060 |
| BLAKE2-384 | 0.139 | 0.132 | 0.067 |
| BLAKE2-512 | 0.161 | 0.154 | 0.073 |
Table 5 The comparison of key generation and key expansion () (unit: milliseconds)
| Key Expansion Based | Key Expansion Based | ||
| Hash Algorithm | Key Generation | on PQCWC Scheme 1 | on PQCWC Scheme 2 |
| SHA-1 | 15.049 | 14.902 | 7.365 |
| SHA-224 | 15.764 | 15.608 | 7.727 |
| SHA-256 | 15.540 | 15.379 | 7.756 |
| SHA-384 | 18.579 | 18.470 | 8.902 |
| SHA-512 | 19.138 | 19.368 | 9.600 |
| SHA3-224 | 55.740 | 55.634 | 28.029 |
| SHA3-256 | 51.622 | 51.787 | 26.001 |
| SHA3-384 | 51.501 | 51.803 | 26.327 |
| SHA3-512 | 51.961 | 52.158 | 26.054 |
| BLAKE2-256 | 28.725 | 28.741 | 14.370 |
| BLAKE2-384 | 28.464 | 28.368 | 14.290 |
| BLAKE2-512 | 28.536 | 28.328 | 14.289 |
Figure 4 The comparison of key generation and key expansion () (Unit: milliseconds).
Figure 5 The comparison of key generation and key expansion () (Unit: milliseconds).
From Figures 4 and 5, it can be observed that the data distribution of key generation time and key expansion time for PQCWC Anonymous Scheme 1 is similar. However, for PQCWC Anonymous Scheme 2, both the average and median key expansion times are lower than the key generation time, though the range between the maximum and minimum values is wider. This is due to the random number being in the range of [0, ], which causes a greater variation in computation time.
Furthermore, to objectively verify the significance of these differences, this study employs a statistical -test to calculate pairwise comparisons between different schemes. Since there are 12 different algorithms tested, the degree of freedom is 22, and when the -value exceeds 2.074, it indicates a significant difference [26]. The results of the -tests are shown in Tables 6 and 7. From the experimental results, it can be observed that there is no significant difference between the key generation time and the key expansion time for PQCWC Anonymous Scheme 1. However, there is a significant difference between the key expansion time for PQCWC Anonymous Scheme 2 and both the key generation time and the key expansion time for PQCWC Anonymous Scheme 1. Furthermore, as indicated by Tables 4 and 5, the key expansion time for PQCWC Anonymous Scheme 2 is significantly lower. Therefore, the proposed PQCWC anonymous credential scheme offers higher computational efficiency.
Table 6 The t-test results for the comparison of key generation and key expansion ()
| Key | Key Expansion Based | |
| -value | Generation | on PQCWC Scheme 1 |
| Key Expansion Based on PQCWC Scheme 1 | 0.279 | |
| Key Expansion Based on PQCWC Scheme 2 | 3.807 | 3.545 |
Table 7 The -test results for the comparison of key generation and key expansion ()
| Key | Key Expansion Based | |
| -value | Generation | on PQCWC Scheme 1 |
| Key Expansion Based on PQCWC Scheme 1 | 0.001 | |
| Key Expansion Based on PQCWC Scheme 2 | 2.992 | 2.977 |
In this section, to compare the computation time of generating signatures using the original private key with that of generating signatures using the proposed PQCWC anonymous schemes (i.e., expanded private key), different hash algorithms were used to generate 1,000 signatures. The experimental results are shown in Tables 8 and 9. The results indicate that regardless of whether the original private key or the expanded private key is used, the number of hash computations for each private key element depends on the value of the element in the data D to be signed. Therefore, the computation times for generating signatures using the original private key, the expanded private key in PQCWC Anonymous Scheme 1, and the expanded private key in PQCWC Anonymous Scheme 2 are all similar. The t-test results, shown in Tables 10 and 11, indicate no significant differences across the computation times.
Table 8 The comparison of signature generation () (unit: milliseconds)
| Signature Generation Based | Signature Generation Based | ||
| Hash Algorithm | [22, 23] | on PQCWC Scheme 1 | on PQCWC Scheme 2 |
| SHA-1 | 0.041 | 0.038 | 0.041 |
| SHA-224 | 0.051 | 0.051 | 0.047 |
| SHA-256 | 0.061 | 0.062 | 0.059 |
| SHA-384 | 0.074 | 0.073 | 0.075 |
| SHA-512 | 0.070 | 0.067 | 0.065 |
| SHA3-224 | 0.128 | 0.119 | 0.119 |
| SHA3-256 | 0.149 | 0.142 | 0.140 |
| SHA3-384 | 0.108 | 0.112 | 0.109 |
| SHA3-512 | 0.155 | 0.155 | 0.156 |
| BLAKE2-256 | 0.060 | 0.058 | 0.058 |
| BLAKE2-384 | 0.068 | 0.068 | 0.067 |
| BLAKE2-512 | 0.077 | 0.075 | 0.074 |
Table 9 The comparison of signature generation () (unit: milliseconds)
| Hash Algorithm | [22, 23] | Based on PQCWC Scheme 1 | Based on PQCWC Scheme 2 |
| SHA-1 | 7.580 | 7.576 | 7.520 |
| SHA-224 | 7.832 | 7.872 | 7.851 |
| SHA-256 | 7.499 | 7.502 | 7.484 |
| SHA-384 | 9.234 | 9.217 | 9.182 |
| SHA-512 | 9.504 | 9.459 | 9.482 |
| SHA3-224 | 29.137 | 29.099 | 29.138 |
| SHA3-256 | 25.430 | 25.474 | 25.420 |
| SHA3-384 | 25.828 | 25.787 | 25.721 |
| SHA3-512 | 26.247 | 26.149 | 26.110 |
| BLAKE2-256 | 14.407 | 14.451 | 14.393 |
| BLAKE2-384 | 14.393 | 14.408 | 14.381 |
| BLAKE2-512 | 14.622 | 14.633 | 14.600 |
Table 10 The -test results for the comparison of signature generation ()
| t-value | [22, 23] | Based on PQCWC Scheme 1 |
| Based on PQCWC Scheme 1 | 0.119 | |
| Based on PQCWC Scheme 2 | 0.182 | 0.064 |
Table 11 The -test results for the comparison of signature generation ()
| t-value | [22, 23] | Based on PQCWC Scheme 1 |
| Based on PQCWC Scheme 1 | 0.002 | |
| Based on PQCWC Scheme 2 | 0.011 | 0.008 |
Table 12 The comparison of signature verification () (unit: milliseconds)
| Signature Generation Based | Signature Generation Based | ||
| Hash Algorithm | [22, 23] | on PQCWC Scheme 1 | on PQCWC Scheme 2 |
| SHA-1 | 0.040 | 0.042 | 0.039 |
| SHA-224 | 0.051 | 0.051 | 0.050 |
| SHA-256 | 0.060 | 0.057 | 0.057 |
| SHA-384 | 0.077 | 0.076 | 0.073 |
| SHA-512 | 0.070 | 0.069 | 0.068 |
| SHA3-224 | 0.118 | 0.120 | 0.118 |
| SHA3-256 | 0.145 | 0.137 | 0.141 |
| SHA3-384 | 0.105 | 0.108 | 0.104 |
| SHA3-512 | 0.160 | 0.157 | 0.155 |
| BLAKE2-256 | 0.061 | 0.060 | 0.060 |
| BLAKE2-384 | 0.067 | 0.068 | 0.066 |
| BLAKE2-512 | 0.080 | 0.077 | 0.077 |
Table 13 The comparison of signature verification () (unit: milliseconds)
| Hash Algorithm | [22, 23] | Based on PQCWC Scheme 1 | Based on PQCWC Scheme 2 |
| SHA-1 | 7.489 | 7.469 | 7.443 |
| SHA-224 | 7.910 | 7.940 | 7.939 |
| SHA-256 | 8.007 | 8.053 | 7.998 |
| SHA-384 | 9.419 | 9.408 | 9.453 |
| SHA-512 | 9.650 | 9.623 | 9.643 |
| SHA3-224 | 26.767 | 26.578 | 26.517 |
| SHA3-256 | 26.364 | 26.362 | 26.215 |
| SHA3-384 | 25.914 | 25.881 | 25.771 |
| SHA3-512 | 26.093 | 25.942 | 25.995 |
| BLAKE2-256 | 14.563 | 14.593 | 14.453 |
| BLAKE2-384 | 14.230 | 14.254 | 14.102 |
| BLAKE2-512 | 14.120 | 13.954 | 13.913 |
In this section, to compare the computation time for signature verification using the original public key with that using the expanded public key in the proposed PQCWC anonymous credential scheme, different hash algorithms were used to verify the 1,000 signatures generated in the previous section. The experimental results are shown in Tables 12 and 13. The results indicate that, whether using the original public key or the expanded public key, the number of hash computations for each signature element is determined by , where is the value of the element in the data D to be signed. Therefore, the computation times for verifying signatures using the original public key, the expanded public key in PQCWC Anonymous Scheme 1, and the expanded public key in PQCWC Anonymous Scheme 2 are similar. The -test results, shown in Tables 14 and 15, indicate no significant differences in computation time.
Table 14 The t-test results for the comparison of signature verification ()
| -value | [22, 23] | Based on PQCWC Scheme 1 |
| Based on PQCWC Scheme 1 | 0.067 | |
| Based on PQCWC Scheme 2 | 0.146 | 0.081 |
Table 15 The t-test results for the comparison of signature verification ()
| -value | [22, 23] | Based on PQCWC Scheme 1 |
| Based on PQCWC Scheme 1 | 0.012 | |
| Based on PQCWC Scheme 2 | 0.027 | 0.016 |
This study proposes the PQCWC anonymous schemes, which achieves quantum-safe security level while also providing anonymity to protect privacy. Furthermore, based on the PQCWC scheme, the study further proposes a hash-based butterfly key expansion mechanism to enable anonymity from the CA, fully safeguarding the privacy of end entities. In the experimental section, the study demonstrates that the proposed method shows no significant differences from the state-of-the-art in terms of signature length, key generation time, key expansion time, signature generation time, and signature verification time. It provides anonymity with no additional computational overhead.
Future research could explore extending the PQCWC anonymous schemes by integrating Merkle trees and combining it with the SLH-DSA algorithm [12] to enhance practicality.
Some contributions of the manuscript have been published as a preprint on the web pages of arXiv (i.e. https://arxiv.org/abs/2410.03678). This work acknowledges and appreciates that IEEE 1609.2, IEEE 1609.2.1, ETSI TS 103 097, ETSI TS 102 941, ETSI TR 104 239-1, and ETSI TR 104 171 have incorporated the author’s relevant contributions and recommendations.
[1] R. Ibarrondo, G. Gatti and M. Sanz, “Quantum Genetic Algorithm With Individuals in Multiple Registers,” in IEEE Transactions on Evolutionary Computation, vol. 28, no. 3, pp. 788–797, 2024, doi:10.1109/TEVC.2023.3296780.
[2] P. W. Shor, “Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer,” in SIAM Journal on Computing, vol. 26, no. 5, pp. 1484–1509, 1997. DOI:10.1137/S0097539795293172.
[3] K. Oonishi and N. Kunihiro, “Shor’s Algorithm Using Efficient Approximate Quantum Fourier Transform,” in IEEE Transactions on Quantum Engineering, vol. 4, pp. 1–16, 2023, Art no. 3102016, doi:10.1109/TQE.2023.3319044.
[4] Y. Aono et al., “The Present and Future of Discrete Logarithm Problems on Noisy Quantum Computers,” in IEEE Transactions on Quantum Engineering, vol. 3, pp. 1–21, 2022, Art no. 3102021, doi:10.1109/TQE.2022.3183385.
[5] Y. Wang, H. Zhang and H. Wang, “Quantum polynomial-time fixed-point attack for RSA,” in China Communications, vol. 15, no. 2, pp. 25–32, 2018, doi:10.1109/CC.2018.8300269.
[6] S. P. Jordan and Y.-K. Liu, “Quantum Cryptanalysis: Shor, Grover, and Beyond,” in IEEE Security & Privacy, vol. 16, no. 5, pp. 14–21, 2018, doi:10.1109/MSP.2018.3761719.
[7] G. Alagic et al., “Status Report on the Third Round of the NIST Post-quantum Cryptography Standardization Process,” NIST Special Publication, NISTIR 8413, 2022. DOI:10.6028/NIST.IR.8413.
[8] T. Tosun and E. Savas, “Zero-Value Filtering for Accelerating Non-Profiled Side-Channel Attack on Incomplete NTT-Based Implementations of Lattice-Based Cryptography,” in IEEE Transactions on Information Forensics and Security, vol. 19, pp. 3353–3365, 2024, doi:10.1109/TIFS.2024.3359890.
[9] S. Suhail, R. Hussain, A. Khan and C. S. Hong, “On the Role of Hash-Based Signatures in Quantum-Safe Internet of Things: Current Solutions and Future Directions,” in IEEE Internet of Things Journal, vol. 8, no. 1, pp. 1–17, 2021, doi:10.1109/JIOT.2020.3013019.
[10] Cohen, R. G. L. D’Oliveira, S. Salamatian and M. Médard, “Network Coding-Based Post-Quantum Cryptography,” in IEEE Journal on Selected Areas in Information Theory, vol. 2, no. 1, pp. 49–64, 2021, doi:10.1109/JSAIT.2021.3054598.
[11] J. Dey and R. Dutta, “Progress in Multivariate Cryptography: Systematic Review, Challenges, and Research Directions,” in ACM Computing Surveys, vol. 55, no. 12, Article No.: 246, 2023, doi:10.1145/3571071.
[12] National Institute of Standards and Technology, “Stateless Hash-Based Digital Signature Standard,” Federal Information Processing Standards Publication, FIPS 205, 2024. DOI:10.6028/NIST.FIPS.205.
[13] National Institute of Standards and Technology, “Module-Lattice-Based Digital Signature Standard,” Federal Information Processing Standards Publication, FIPS 204, 2024. DOI:10.6028/NIST.FIPS.204.
[14] National Institute of Standards and Technology, “Module-Lattice-Based Key-Encapsulation Mechanism Standard,” Federal Information Processing Standards Publication, FIPS 203, 2024. DOI:10.6028/NIST.FIPS.203.
[15] K.-A. Shim, “A Survey on Post-Quantum Public-Key Signature Schemes for Secure Vehicular Communications,” in IEEE Transactions on Intelligent Transportation Systems, vol. 23, no. 9, pp. 14025–14042, 2022, doi:10.1109/TITS.2021.3131668.
[16] H. Gharavi, J. Granjal and E. Monteiro, “Post-Quantum Blockchain Security for the Internet of Things: Survey and Research Directions,” in IEEE Communications Surveys & Tutorials, vol. 26, no. 3, pp. 1748–1774, 2024, doi:10.1109/COMST.2024.3355222.
[17] Z. Yang, H. Alfauri, B. Farkiani, R. Jain, R. D. Pietro and A. Erbad, “A Survey and Comparison of Post-Quantum and Quantum Blockchains,” in IEEE Communications Surveys & Tutorials, vol. 26, no. 2, pp. 967–1002, 2024, doi:10.1109/COMST.2023.3325761.
[18] C. H. Chen, “Post-Quantum Cryptography X.509 Certificate,” 2024 International Conference on Smart Systems for applications in Electrical Sciences (ICSSES), Tumakuru, India, 2024, pp. 1–6, doi:10.1109/ICSSES62373.2024.10561274.
[19] C. H. Chen, “Comments on “Exploring Secure V2X Communication Networks for Human-Centric Security and Privacy in Smart Cities” – Privacy-Preserving Certificate in V2X Communications,” in IEEE Access, vol. 13, pp. 76923–76933, 2025, doi:10.1109/ACCESS.2025.3563461.
[20] “IEEE Draft Standard for Wireless Access in Vehicular Environments (WAVE) – Certificate Management Interfaces for End Entities,” in IEEE P1609.2.1/D2, September 2025, pp. 1–259, 9 Oct. 2025. URL: https://ieeexplore.ieee.org/servlet/opac?punumber=11201012.
[21] Hammi, J. P. Monteuuis, H. Labiod, R. Khatoun and A. Serhrouchni, “Using Butterfly Keys: A Performance Study of Pseudonym Certificates Requests in C-ITS,” 2017 1st Cyber Security in Networking Conference (CSNet), Rio de Janeiro, Brazil, 2017, pp. 1–6, doi:10.1109/CSNET.2017.8242002.
[22] M. Honda and Y. Kaji, “Optimum Fingerprinting Function for Winternitz One-Time Signature,” 2024 IEEE International Symposium on Information Theory (ISIT), Athens, Greece, 2024, pp. 2898–2902, doi:10.1109/ISIT57864.2024.10619351.
[23] M. Honda and Y. Kaji, “Extended Version—to Be, or Not to Be Stateful: Post-Quantum Secure Boot Using Hash-based Signatures,” Journal of Cryptographic Engineering, vol. 14, pp. 631–648, 2024, doi:10.1007/s13389-024-00362-4.
[24] S. Khan et al., “A Survey on X.509 Public-Key Infrastructure, Certificate Revocation, and Their Modern Implementation on Blockchain and Ledger Technologies,” in IEEE Communications Surveys & Tutorials, vol. 25, no. 4, pp. 2529–2568, 2023, doi:10.1109/COMST.2023.3323640.
[25] P. Kurariya, A. Bhargava, S. Sailada, N. Subramanian, J. Bodhankar and A. Kumar, “Experimentation on Usage of PQC Algorithms for eSign,” 2022 IEEE International Conference on Public Key Infrastructure and its Applications (PKIA), Bangalore, India, 2022, pp. 1–6, doi:10.1109/PKIA56009.2022.9952354.
[26] C. H. Chen, G. Liu, Y. C. Wei, Z. Li and B. Y. Lin, “A Pre-signed Response Method Based on Online Certificate Status Protocol Request Prediction,” in Enterprise Information Systems, vol. 16, no. 8–9, 2022, doi:10.1080/17517575.2021.1986861.
Abel C. H. Chen (Senior Member, IEEE) has published over 400 journal articles, conference papers, and patents. His contributions were published in IEEE Transactions on Intelligent Transportation Systems, IEEE Transactions on Emerging Topics in Computational Intelligence, IEEE Internet of Things Journal, ACM Transactions on Sensor Networks, Information Science, IEEE Communications Letters, and Physica A: Statistical Mechanics and its Applications. He has also submitted numerous contributions to more than 100 standards, including IEEE 1609.2, IEEE 1609.2.1, ETSI TS 102 941, ETSI TR 104 171, and ETSI GR QKD 007. He served as the Chair for several conferences, such as AAAI-22 Workshop, WWW 2021 Workshop, IEEE BIBM 2021 Workshop, IEEE TrustCom 2021 Workshop, IEEE APNOMS 2020, and IEEE ICC 2020. He serves as an Editor for several journals, such as Scientific Data, IEEE Open Journal of Intelligent Transportation Systems, and Network: Computation in Neural Systems. He served as an Associate Editor or the Guest Editor for several journals, such as IEEE Access, IEICE Transactions on Information and Systems, Journal of Applied Statistics, and ISPRS International Journal of Geo-Information. He was listed among the Top 2% Scientists Worldwide, in 2022, 2023, 2024, and 2025 by Stanford University. Some of his publications have been recognized as highly cited papers on Web of Science using data from Essential Science Indicators (ESI).
Quantum Information Technologies Journal, Vol. 2_1, 9–40
doi: 10.13052/qitj2795-0492.212
© 2026 River Publishers