Christine Kim Maps Bitcoin’s Quantum Security Roadmap

Share This Post


Bitcoin developers are exploring a potential roadmap to address the long-term threat that sufficiently powerful quantum computers could pose to the network’s existing cryptography. According to an X post by Christine D. Kim, founder of Protocol Watch Research & Advisory, two proposals, BIP-360 and SHRINCS, have emerged as key parts of this discussion.

In the post, the founder described that BIP-360 proposes a new Pay-to-Merkle-Root (P2MR) output type that is intended to reduce public-key exposure, while SHRINCS is a proposed hash-based signature scheme that is designed designed for post-quantum security.

The proposals are intended to give Bitcoin users a way to protect their coins before a cryptographically relevant quantum computer becomes practical. However, neither represents a completed upgrade. BIP-360 remains in draft status, while SHRINCS still requires further security analysis, testing and independent review.

BIP-360 And SHRINCS Address Different Parts Of The Problem

The concern behind the proposals is that a sufficiently capable quantum computer could eventually threaten the cryptographic systems that Bitcoin uses to make sure that the transactions are secure. This does not mean current quantum computers can break Bitcoin. Instead, developers are considering how the network could respond if a cryptographically relevant quantum computer, or CRQC, becomes practical.

Christine D. Kim outlined the developing roadmap describing BIP-360, SHRINCS, Lifeboat and DropKick as pieces of a broader effort to address the issue. BIP-360 proposes Pay-to-Merkle-Root, or P2MR, through a Bitcoin soft fork. The proposal is designed to reduce exposure to attacks in which a quantum computer could potentially derive a private key from an exposed public key.

According to the BIP-360 proposal, P2MR would provide a new output type that can support multiple spending paths while allowing future cryptographic upgrades. The proposal is not itself a quantum-resistant signature scheme. Instead, it is intended to provide a framework that could accommodate post-quantum signature methods later. BIP-360 is currently listed as a draft, so its existence does not mean the change has been adopted by Bitcoin.

On the other hand, SHRINCS addresses the signature side of the problem. Developed by Blockstream researchers, it is a hash-based signature scheme intended to withstand attacks from quantum computers. The design uses SHA-256, the same hash function already used extensively within Bitcoin.

However, SHRINCS also remains under development. Kim notes that its draft still requires a formal security proof, comprehensive test vectors and independent review before it can be seriously considered for implementation.

The size of post-quantum signatures presents another issue. SHRINCS signatures are considerably larger than the Schnorr signatures currently used by Bitcoin. If post-quantum signatures become widely used, the additional data could put pressure on block space.

Researchers are hence also examining ways to combine or compress signatures so that the additional cryptographic data does not create the same burden on the network.

Emergency Options Are Being Considered For Users Who Do Not Migrate

Protecting coins before a quantum computer becomes practical is not the only problem that exists. Developers also have to consider what happens if a CRQC (cryptographically relevant quantum computers) appears while some Bitcoin remains in addresses that are vulnerable to the new technology.

This is where proposals such as Lifeboat and DropKick come into the discussion. Both of these proposals are seen as possible rescue mechanisms for users who have not moved their coins to post-quantum-secure arrangements before a CRQC emerges.

Dryja’s Lifeboat proposal uses an on-chain commitment mechanism to establish that a user knew certain information before a quantum attacker could obtain it. The proposal also describes a mechanism through which the presence of a CRQC could trigger the soft fork needed for the rescue process.

Conduition’s DropKick takes a similar approach but differs in areas including commitment ordering, fee requirements and activation. Bitcoin Optech’s September 4 newsletter provides additional detail on the differences between the two proposals.

The problem they are attempting to address is the possibility of an attacker using a CRQC to derive a private key and then race the legitimate owner when the owner tries to move the coins. A commitment made before the quantum threat becomes practical could provide a way to establish the user’s prior knowledge and potentially give them a path to recovery.

The proposals still leave several questions open. SHRINCS needs further cryptographic review, while its larger signatures raise questions about how much additional block space post-quantum transactions would require. Developers also have not reached a clear answer on how Bitcoin should treat coins whose owners have permanently lost access to their private keys once quantum computers become capable of attacking older cryptography.

For now, the proposals represent an ongoing area of Bitcoin protocol research rather than a finalized quantum-security upgrade. BIP-360 offers one possible framework for reducing public-key exposure, SHRINCS proposes one potential post-quantum signature system, and Lifeboat and DropKick explore what could happen if users fail to migrate before a CRQC becomes practical. How these proposals develop, and whether they are ultimately adopted, remains an open question.



Source link

Related Posts