XMSS Merkle trees

Walk an XMSS Merkle tree of real WOTS-TW leaves: build the root, spend one leaf, publish the auth path, and verify the climb.

Text → SHA-256 truncated to 16 bytes. Leaf index is the stateful counter (0…7).

Loading interactive XMSS Merkle-tree demo…

Keys: Space play/pause · ←/→ step · P/N phase

Key material

Fixed demo seeds (same as the WOTS posts). Leaves are real SHRINCS WOTS-TW public keys compressed with T_sl; parents use tweakable H.

WOTS gives you a one-time signature which breaks if used to sign more than one message. XMSS (eXtended Merkle Signature Scheme) is how you turn many WOTS keys into a single many-time verifying key. The demo above builds a small tree (h=3, eight WOTS leaves) so every node fits on screen. Step through key generation, a signature with its authentication path, and verification with Next / Prev (or Play).