2025-02-20
Post-Quantum Cardano
- Lays out how to make Cardano post-quantum as quantum computing heats up, noting NIST just finalized the FIPS 203 to 206 standards.
- Explains that adopting one post-quantum signature does not make you quantum secure, since security is always relative to a defined adversary and its capabilities.
- Proposes a three-step plan: model a quantum adversary end to end, split Cardano into a main chain and a post-quantum proof chain via Mithril, then eventually merge them.
- Weighs hash-based versus lattice-based schemes, favoring lattices for programmability, and flags that post-quantum signatures are 5 to 10 times larger and slower without hardware support.
- Reassures that Cardano is well positioned with world-class cryptographers, framing crypto as an eternal cat and mouse where quantum computers are just the next Enigma-breaking Bombe.
38 entries
On February 20 2025 the quantum computing world is heating up, and in 5 to 10 years the industry will have to modernize cryptography, citing Microsoft's Majorana as a huge step.
The US government agrees, as NIST proactively worked with cryptographers to release finalized post-quantum standards in August 2024, FIPS 203, 204, 205, and 206.
The standards: general encryption, CRYSTALS-Dilithium renamed ML-DSA, and SPHINCS+ from Zooko's lineage, plus Algorand's lattice-based Falcon, a post-quantum leader.
Algorand has post-quantum state proofs and compact certificates, and IO worked with them on ALBA, a Mithril extension, and updating the VRF to be post-quantum.
Praises the hot-off-the-press LatticeFold+ from Dan Boneh and Binyi Chen as one of the best folding papers ever, a compact proof-carrying-data scheme with a 64 bit field.
Cardano bases security on elliptic curve signatures, which Shor's algorithm breaks on a quantum computer, so hardening only evades it, not solves it.
Merely adopting a post-quantum signature does not make you quantum secure, because in cryptography security is always defined against an adversary, Mr A, with a chosen set of capabilities.
The security model must decide the adversary's compute power, computer access, online or offline status, and special capabilities like a quantum computer.
Cites Kerckhoffs's principle that security must rest on the secret keys not obscurity, and warns of side-channel attacks where hardware betrays the algorithm, like an Israeli paper that broke PGP acoustically to recover the RSA key.
You can defeat crypto classically, via electrical engineering, with a 5 dollar wrench, or with special capabilities, and praises Aggelos and IO's 240 papers as world-class at this.
Step one is a quantum secure model for Cardano end to end, auditing every algorithm against a canonical quantum adversary the cryptographic community must still define.
Step two splits Cardano into the elliptic-curve main chain you know and a Cardano proof blockchain, which is why LatticeFold+ matters.
The proof chain uses Mithril, like Algorand's compact certificates, upgraded to a post-quantum signature system, running as a companion audit log of Cardano's history.
The proof chain becomes a programmable proof chain and eventually a data availability layer, and post-quantum is kept off the main chain because its signatures are 5 to 10 times larger and slower.
Chips have ASIC circuitry accelerating standardized crypto like AES and hashes 50 to 100 times, which non-standard post-quantum crypto cannot use, compounding the slowdown.
Slowdown cuts TPS 5 to 10 fold and balloons block sync time, which is why Cardano did not launch with an unstandardized scheme, so NIST's FIPS standards now let hardware makers accelerate them.
Step two could use LatticeFold+ for a powerful programmable folding scheme, or a lighter touch of Mithril certificates with finality signed post-quantum.
Step three is eventual integration once schemes mature and a post-quantum VRF exists, merging the meta chain and main chain, and Laos proofs of equivocation via Mithril let the movement begin faster.
Frames the choice as hash land versus lattice land: XMSS, SPHINCS, and STARKs versus CRYSTALS and LatticeFold, favoring lattices for their mathematical complexity and programmability.
The budget request will be augmented to bring world experts in during 2025 and 2026 to work out the quantum adversary science, while an interim NIST scheme runs with Mithril.
The audit-log checkpoint is quantum resistant and doable in a 2 to 3 year horizon, useful in its own right as a data availability and proof layer, before revisiting the ledger model.
Asks whether UTXO is still the best accounting model versus intents, algebraic ledgers like Gabby's, or Bruno's chimeric ledgers that combine architectures.
Changing the cryptography is a chance to revisit authenticated data structures like Merkle trees, DAGs, and graphs, which matter more with intents and identity.
The standards are preliminary and the whole US government must move, noting the NSA already switched its protocols to post-quantum because of the archive data attack.
Security is always temporal, secure only for a bounded time, illustrated by a security guard who eventually dies or retires while compute power always grows.
Recounts Bletchley Park, where Alan Turing's Bombe broke the Nazi Enigma the Germans thought unhackable, since they never anticipated the computer, popularizing computing.
Quantum computers are just another Bombe against today's Enigma-like classical crypto, and you can always build a new Enigma with a post-quantum signature scheme.
Cryptography is an eternal cat and mouse where the algorithm and the computer forever chase each other.
Microsoft's Majorana is a new cat needing a new mouse, but Cardano is well placed with top cryptographers at IO, Stanford, CMU, and Edinburgh, so it is a prioritization not a brilliance problem.
Announcements like Google's Willow and Microsoft's topological qubits shorten the horizon from 20 to 30 years to 5 to 10, so first-principles adversarial and universal composition modeling must happen, with group domain expert Alexander.
A small supplemental budget is needed, every protocol like Ouroboros must be checked, and the proof ledger can start on Mithril-adjacent projects like Midgard as a historical stopgap.
The merger is a chance to go beyond extended UTXO with a different accounting structure and new authenticated data structures, noting Vitalik's Verkle trees and Poseidon hashes.
It is an endless cat and mouse where an MIT quantum information theorist will always find a new algorithm, but public crypto has been durable since 1976 and elliptic curves since the 1980s.
Elliptic-curve algorithms outlived the Blackberry and Nokia handsets now in landfills, so retooling to post-quantum loses many familiar optimizations.
Credits his friend Neil Koblitz for elliptic curve cryptography and his serpentine path paper, noting supersingular isogenies as a hard, uncertain quantum-resistant alternative from Waterloo.
Cardano is not caught with its pants down after NIST did its job, and the TSC, product committee, and IO research will pick algorithms and work with crypto firms like Galois, auditing any foreign crypto.
Every cryptographic implementation gets a formal security audit because Cardano is known for formal methods, like hiring a master plumber before changing the plumbing.
The video is a kickoff for the post-quantum conversation at Intersect, the TSC, and the research group, with a planned cryptographer workshop at the University of Edinburgh.