Key idea: the signer builds only part of the XMSS tree (pruning), so lifetime scales with keygen time.
One signer
LightLedger Nano S+i
Standardweak CPUi
Fullpowerful CPUi
Lifetimei
210K249K signatures (subtree of 213)
22M26M signatures (subtree of 220)
1.15B1.4B signatures (full tree of 226)
Key generation
1.98M compressions60 s
254M compressions2.0 s
16.2B compressions16 s
Signing
74K compressions, 16 KiB cache2.2 s
70K compressions, 1 MiB cache0.5 ms
93K compressions, 16 MiB cache0.1 ms
Threshold, t-of-n
Adapted from PRAWNS: a one-time ceremony at keygen precomputes every hash of a secret, run either as an honest-majority MPC among the operators (DKG) or by a trusted dealer; signing then needs no MPC (432≈ 820 bytes per signer, 3 rounds), and is secure against t − 1 malicious signers (with abort).
With DKG
Bottleneck: keygen traffic per operator
Lifetimei (signatures)
7.5K8.9K signatures (subtree of 28)
28.5K33.5K signatures (subtree of 210)
108K128K signatures (subtree of 212)
2-of-3
1121 GB
4385 GB
172342 GB
3-of-5
1326 GB
52103 GB
207410 GB
4-of-7
1428 GB
55110 GB
222440 GB
With a trusted dealer
Bottleneck: public data to store (also applies to the DKG version)