Post-quantum cryptography can resist the attack of quantum computers. HCASH integrates two most popular anti-quantum signature schemes, BLISS [DDLL13] and MSS/LMS [BDH11, 1LM95]. BLISS is the most efficient anti-quantum signature scheme at present. It has the smallest public key and the shortest signature size. MSS/LMS is the most efficient scheme based on hash signature.
The security assumption of MSS/LMS is very weak (that is, strong security). Its security only depends on the security of the underlying hash algorithm. Under this security assumption, MSS/LMS is provably secure.