August 27, 01:26
SHRINCS BIP published to make Bitcoin quantum-secure, with risks
SHRINCS BIP Published: Quantum-Secure Bitcoin Comes With A Catch
Cointelegraph

Blockstream published a Bitcoin Improvement Proposal for its SHRINCS post-quantum signature scheme. Blockstream Research's Jonas Nick called it the first concrete post-quantum signature proposal designed specifically for Bitcoin. SHRINCS has already signed real transactions on Blockstream's Liquid sidechain. Researchers tested the scheme in production on Liquid in March this year. SHRINCS signatures have a minimum size of 548 bytes plus a 48-byte public key. SHRINCS signatures can grow to 4,619 bytes. Bitcoin's existing Schnorr signatures are 64 bytes. Bitcoin's ECDSA signatures are 70 bytes. NIST-approved post-quantum signature schemes are between 38 and 123 times larger than Bitcoin's existing signatures. Blockstream estimates that Bitcoin could process about 3 transactions per second with SHRINCS. The estimate compares with 0.5 transactions per second for the NIST-approved lattice-based ML-DSA scheme. The estimate compares with 0.36 transactions per second for the NIST-approved hash-based SPHINCS+ scheme. Segregated Witness makes signature data occupy one quarter as much space as other transaction data. The BIP warns that its security proof is incomplete. Marin Ivezic said the scheme has not been audited and has not undergone the public cryptanalysis received by NIST signatures. SHRINCS stores used one-time keys on a device instead of using a stateless multi-layer hash tree. Each signature becomes 16 bytes larger with each use. A lost device would require a stateless fallback transaction of about 5,777 bytes for recovery. Yoon Auh said the design adds statefulness, compact signing paths, fallbacks, seed-initialization assumptions, and rules for switching to larger stateless signatures. The BIP warns that keys generated with hypertree pruning are incompatible with implementations that do not support hypertree pruning. Importing a key between incompatible implementations may result in lost funds. Blockstream incorporated its companion SHRIMPS scheme into SHRINCS as a built-in stateless path under the same 48-byte public key. The incorporated path is about 26% smaller than an otherwise equivalent version because it uses a nonstandard parameter set. Blockstream is also studying lattice-based signatures and zero-knowledge proof aggregation. Blockstream estimates that Bitcoin could process 6.7 transactions per second if zero-knowledge proofs were used with SHRINCS. The article says Bitcoin's quantum migration will require governance decisions because activation would need sufficient support.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.