May 22 - Jul 5, 2026
This new scheme addresses the limitations of conventional methods which achieve unforgeability by simply concatenating signatures but fail to ensure non-malleability. Specifically, BoP-2 enhances security by employing a nonce and hash that involve elements of both signature types, thus necessitating the recovery of certain parameters for verification. This approach not only secures the system against individual scheme failures but also adds robustness against quantum computing threats, albeit at the cost of increased signature size and compromised batch verifiability. The informational-theoretical commitment properties of the PQC component are pivotal in this hybrid, enhancing its overall security framework.
In another vein, the discussion on cryptographic techniques in Bitcoin highlights the distinction between existential and strong unforgeability (EUF and SUF, respectively). Traditional hybrid approaches often used in industry do not inherently endow the resultant scheme with SUF, critical for applications like Bitcoin. The analysis indicates that nesting one scheme within another, without strategic modification, does not transfer SUF properties reliably. Thus, the paper discusses BoP-2 as a nuanced solution that manipulates the Schnorr scheme's challenge component to inherit SUF from any nested PQ scheme, thereby addressing core security concerns in blockchain technologies.
Furthermore, the conversation extends to the practical implications of integrating various cryptographic systems under the PQC regime. Issues such as the performance inefficiencies of isogenies and the inherent problems in hash-based systems and lattices raise significant concerns about their viability in PQC environments. Also discussed is the importance of batch verifiability in PQC schemes compared to Schnorr signatures, highlighting the need for efficient and cost-effective cryptographic solutions that align with operational demands and security standards.
Moreover, the discourse around Signature Upgrade Functionality (SUF) post-Segwit Bitcoin transactions elucidates the reduced significance of signatures in influencing transaction IDs. It presents deterministic signing as a potential solution to malleability issues, while also exploring the space efficiency benefits of hybrid schemes proposed by Boris Nagaev. His suggestion to integrate BIP340 within a hash-based scheme might add minimal overhead, thereby optimizing space, a crucial factor in blockchain applications. However, discussions with Jonas Nick brought up concerns about expanding the hybrid public key root to prevent related-key collision attacks, slightly diminishing the byte savings initially anticipated.
Lastly, the broader implications of adopting hybrid cryptographic schemes, particularly those mixing elliptic curve and PQC, are debated. While pure PQC schemes may lack widespread trust currently, hybrid models could provide a safer transitional strategy by combining established EC signatures with novel PQC methods. This could potentially enhance security without compromising user confidence in blockchain technologies, even as discussions continue on the optimal blend of these cryptographic technologies to address future threats and operational demands effectively.
Thread Summary (9 replies)
May 22 - Jul 5, 2026
10 messages
TLDR
We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project.
Give Feedback