The Merkle-tree construction promises to o er authentication and digital signatures which are resistant to quantum attacks. One of the rst proposals in public key cryptography (1979), this construction relies only on a hash function for its security. While RSA and other number theory based algorithms will succumb to e cient quantum algorithms, a hash function need not have a \number-theoretic ...