HSM / PKCS#11 / SLH-DSA Sign & Verify
What you will do: Pick one of the 12 FIPS 205 parameter sets and a pre-hash mode, then Generate Key Pair, Sign Message and Verify Signature on a real PKCS#11 v3.2 HSM emulator in the browser.
Worked example: With the default SHA2-128s set the 32-byte public key appears, the message signs into a 7.7 KB signature, Verify Signature reports Signature Valid, and the PKCS#11 call log lists every call.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
Browse all Crypto Lab tools · Learn with SLH-DSA: Stateless Hash Signatures
For your role
- Developer / Engineer
- Pick a parameter set from the twelve FIPS 205 variants, keep Pure mode (the recommended default), then run 1. Generate Key Pair, 2. Sign Message and 3. Verify Signature: the PKCS#11 call log shows the exact C_GenerateKeyPair, C_Sign and C_Verify sequence your code would issue.
- Security Architect
- Compare SHA2-128s against the f variants and the 192/256 levels: the same message signs to very different signature sizes, and the Stateful vs Stateless comparison panel says when a stateless scheme is worth that size over LMS or XMSS.
- Researcher / Academic
- Run the Stateful Signatures Known Answer Tests panel to see SLH-DSA sign and verify round-trips (no external expected value) and a SHA-256 NIST reference sample run in-browser, then switch between Pure and pre-hash mode to see what changes on the wire.
- Certification & Validation Engineer
- Pick a parameter set from the twelve FIPS 205 variants, keep Pure mode, then run 1. Generate Key Pair, 2. Sign Message and 3. Verify Signature: the PKCS#11 call log is the exact sequence a test harness drives through the module interface.
Live HSM Mode Active
SoftHSM3 · PKCS#11 v3.2 · Rust · session open
SLH-DSA Live Demo (FIPS 205)
Generate SLH-DSA key pairs, sign messages, and verify signatures using a real PKCS#11 v3.2 HSM emulator in-browser. SLH-DSA (standardized as FIPS 205, August 2024) is the NIST name for SPHINCS+. Compare SLH-DSA (stateless) with the stateful LMS/XMSS schemes from Steps 1–3.
Parameter Set (12 FIPS 205 variants)
Pre-hash mode
Stateful vs Stateless Signature Comparison
| Property | LMS/HSS | SLH-DSA | ML-DSA |
|---|---|---|---|
| Standard | SP 800-208 | FIPS 205 | FIPS 204 |
| Basis | Hash function | Hash function | Lattice |
| Statefulness | Stateful | Stateless | Stateless |
| Max signatures | Bounded (2^h) | Unlimited | Unlimited |
| Pub key (L3) | 60 B | 48 B | 1,952 B |
| Signature (L3) | 2,644 B | 16,224 B | 3,309 B |
| Signing speed | Fast | Slow | Fast |
| CNSA 2.0 | Required | Not listed | Required |
| Best use | Firmware, code signing (CNSA 2.0) | CA roots, stateless contexts, no persistent state | TLS, general-purpose signing |
Why is SLH-DSA stateless? Unlike LMS/XMSS, SLH-DSA does not consume a leaf index on each signing operation. Instead, it derives a fresh, ephemeral WOTS+ key for every signature using a per-signature randomizer drawn from the private key seed — making each signature self-contained. There is no counter to persist, no monotonic register to protect, and no risk of catastrophic key reuse from a crashed or cloned HSM. In practice this means the private key can be safely backed up, distributed across HSM replicas, or stored in software — operational constraints that are impossible with LMS or XMSS.
The cost of statefulness elimination: SLH-DSA (FIPS 205, formerly SPHINCS+) signs with a Merkle hypertree whose path proof must be included in full — producing signatures of 7–49 KB depending on the parameter set, versus 1–9 KB for LMS at comparable security levels. The "s" variants optimize for smaller signatures; the "f" variants optimize for faster signing at the expense of larger output. All operations above execute via SoftHSM3 PKCS#11 v3.2. Generated keys are for educational purposes only.
Stateful Signatures Known Answer Tests
FIPS 205 · FIPS 180-4
Click Run validation tests to run 3 use-case scenarios. Evidence in this set: NIST ACVP-Server reference sample — Expected values copied from the public NIST ACVP-Server repository with immutable source identity.; Functional round-trip — Output produced by an implementation is consumed by the same or paired implementation..
Reference samples from the public NIST ACVP-Server repository · FIPS 205 · FIPS 180-4 · Generated keys are for educational use only.
No PKCS#11 calls yet — run a live operation to see activity.
Try it
Sign the same message with SHA2-128s and then a 128f variant. What changes?
Next step
Keep learning: SOC Implementation for PQCSOC Implementation for PQC follows SLH-DSA: Stateless Hash Signatures, the module this tool practises, in the Software Infrastructure track.
Related content
Next in HSM / PKCS#11