LMS vs XMSS: The Quantum-Resistant Signature Showdown for 2027
The post-quantum cryptography landscape in 2026 is dominated by lattice-based algorithms like ML-KEM and ML-DSA, but another category of quantum-resistant signatures is gaining attention due to an impending deadline: stateful hash-based signatures, specifically LMS and XMSS. The NSA's Commercial National Security Algorithm Suite 2.0 mandates that new national security systems must support quantum-resistant cryptography starting January 1, 2027, with LMS and XMSS being the approved tools for firmware and software signing.
LMS (Leighton-Micali Signatures) and XMSS (eXtended Merkle Signature Scheme) are both hash-based signature schemes that have been used to protect Cisco firmware updates for over a decade. Unlike ML-DSA, which is stateless, LMS and XMSS require careful state tracking, making them suitable for controlled signing environments like firmware updates where a single organization manages the signing process.
The key difference between LMS and XMSS lies in their signature sizes and performance. LMS signatures are smaller, at around 1,432 bytes, compared to XMSS's 2,500 bytes. However, both schemes share a critical weakness: the private key has a finite number of uses, and reusing a key can lead to security vulnerabilities. This operational challenge sets them apart from traditional RSA or ECDSA signing keys.
Despite their differences, both LMS and XMSS are approved for specified signing use cases under the CNSA 2.0 framework. They are not intended to replace ML-DSA for general-purpose use but are specifically designed for firmware and software signing where state management is feasible.