أبحاث

Bitcoin ECDSA تحت التهديد الكمي: ما هي توقيعات ما بعد الكم التي يمكن للمطوّر محاكاتها؟

Bitcoin ECDSA under Quantum Threat: Which Post-Quantum Signatures Can a Developer Simulate?

نُشر
دقائق قراءة
20 min · 3,333 كلمة
الادعاءات والمراجعة
32/32 ادعاءات موثقة · 20 مصادر

الطبعات: English · Español · Français

الجواب المباشر

لا يورد أي ادعاء في مجموعة الأدلة هذه وجود حاسوب كمي ذي صلة تشفيرية (cryptographically-relevant quantum computer) يعمل فعليًا، لذا فإن التهديد العملي الحالي لخوارزمية ECDSA في Bitcoin يساوي صفرًا، لكن التقدير الزمني لحدوث الاختراق يتفاوت بشكل واسع ولم يُحسم بعد، مع تقدير متفائل واحد يشير إلى عام 2027 [2] [7] (انظر القسم 1 للاطلاع على العرض الأكمل الوحيد لهذا التقدير). تُعتبر آلية إثبات العمل (proof-of-work) في Bitcoin مقاومة للتسريع الكمي على المدى القريب، بخلاف مخطط توقيعها [7] [2]. أما على الجانب الدفاعي، فيمكن للمطوّر اليوم محاكاة واختبار أداء ECDSA مقارنة بـ Falcon وCRYSTALS-Dilithium وSPHINCS+ في بيئات اختبار مبنية على Python، وتورد عدة أوراق بحثية نتائج ملموسة حول العبء الحسابي والأمان والتكامل لهذه المخططات [1] [4] [6] [13]. لا يقدم أي ادعاء مقارنة مباشرة بين تكلفة اختراق ECDSA وتكلفة اختراق إثبات العمل تحت افتراضات موحدة، لذا فإن أي ترتيب لأيهما ينكسر أولًا لا تدعمه الأدلة مباشرة، وينبغي التصريح بذلك.

لماذا يهم توقيت الاختراق الكمي بالنسبة لـ Bitcoin

يعتمد أمان Bitcoin فيما يخص إنفاق الأموال على ECDSA فوق المنحنى secp256k1، ومن المفهوم أن هذا المخطط قابل للكسر بواسطة خوارزمية Shor إذا تم تشغيلها على حاسوب كمي كبير بما فيه الكفاية [2]. لا يوجد اليوم أي حاسوب كمي ذي صلة تشفيرية (CRQC)، والفجوة بين الأجهزة الحالية وهذا النوع من الآلات توصف بأنها كبيرة [2]. هذا يعني أن التهديد ليس وشيكًا، لكن المطورين ومصممي البروتوكولات الذين يخططون لدورات حياة برمجيات أو محافظ تمتد لسنوات عديدة بحاجة إلى تقدير صادق للمهلة المتاحة قبل أن يصبح الانتقال إلى توقيعات ما بعد الكم أمرًا ملحًا.

تقديرات هذه المهلة متباينة. تذكر إحدى الأوراق أن مخطط التوقيع بالمنحنى الإهليلجي في Bitcoin يمكن أن ينكسر كليًا بواسطة حاسوب كمي في وقت مبكر يصل إلى عام 2027 وفق التقدير الأكثر تفاؤلًا [7]؛ وتتم الإشارة إلى هذا الرقم مجددًا في القسمين 3 و8 من هذه المذكرة بدلًا من إعادة سرده كاملًا. بينما تشدد ورقة أخرى في هذه المجموعة على عدم وجود CRQC اليوم وأن المسافة إلى وجوده كبيرة، دون الالتزام بسنة محددة [2]. هذه أطر مختلفة من ورقتين مختلفتين، إحداهما تعطي تاريخًا للحالة المتفائلة والأخرى تشدد على استحالة التحقق حاليًا، وينبغي للمطوّر أن يتعامل مع عام 2027 كحد أدنى في ظل افتراضات مواتية وليس كتوقع إجماعي.

شقّا أمان Bitcoin، أي التوقيعات وإثبات العمل، ليسا معرّضين بالدرجة نفسها. تهدد خوارزمية Shor مخططي التوقيع ECDSA فوق secp256k1 وBLS فوق BLS12-381 [2]، لكن هذه الفئة من الهجمات لا تنطبق على التعدين. توصف آلية إثبات العمل بأنها مقاومة نسبيًا لتسريع كمي كبير على مدى السنوات العشر القادمة [7]، ولا تهدد خوارزمية Grover، وهي الطريقة الكمية التي تنطبق من حيث المبدأ على مسائل شبيهة بالبحث مثل إثبات العمل، هذه الآلية بشكل ملموس، لأن التسريع الذي توفره هو تربيعي فقط، ولأنها تصطدم بتكلفة كل عملية في الحوسبة المتسامحة مع الأخطاء (fault-tolerant) وبجدار تفرّع K√K، ولأن تعديل الصعوبة في Bitcoin يلغي هذا التسريع [2].

ولأن التوقيعات والتعدين يواجهان ملفات مخاطر مختلفة تمامًا، فإن الأولوية الهندسية العملية واضحة: العمل على استبدال التوقيع بمخطط ما بعد الكم، لا على تعدين ما بعد الكم. هذا يشكل بقية هذه المذكرة، التي تركز على ما يمكن للمطوّر بناؤه وقياسه اليوم باستخدام مخططات توقيع ما بعد الكم في بيئة Bitcoin محاكاة.

ما الذي يتكوّن منه التهديد الكمي لـ Bitcoin فعليًا

تناقش الأدبيات المُستعرضة هنا تهديدين خوارزميين متمايزين، وينبغي عدم الخلط بينهما. خوارزمية Shor هي التي تهم فيما يخص توقيعات Bitcoin: فهي قادرة على كسر ECDSA فوق secp256k1 وBLS فوق BLS12-381 [2]. الحواسيب الكمية بشكل أعم قادرة نظريًا على كسر افتراضات الصعوبة الحسابية الكامنة وراء العديد من المخططات التشفيرية القائمة [13]. استخدام Bitcoin تحديدًا لـ ECDSA يُشار إليه صراحة على أنه غير آمن في مواجهة ما بعد الكم بسبب خوارزمية Shor [12].

خوارزمية Grover هي الخوارزمية الكمية الأخرى الشائعة الذكر، لكنها تستهدف جزءًا مختلفًا من النظام: التعدين، لا التوقيع. لا تهدد بشكل ملموس آلية إثبات العمل في Bitcoin، لأن التسريع الذي توفره تربيعي فقط، ولأنها تُسحق أمام تكلفة كل عملية في الحوسبة المتسامحة مع الأخطاء وجدار تفرّع K√K، ولأن تعديل الصعوبة يلغي هذا التسريع [2]. يدرج الادعاء المُتحقَّق منه تكلفة كل عملية في الحوسبة المتسامحة مع الأخطاء كأحد العوامل الساحقة دون توضيح إضافي للآلية، لذا لا يُطرح هنا أي تفصيل إضافي حول سبب كون هذه التكلفة أبطأ من رقاقة كلاسيكية. ولأن خوارزمية Grover تتعلق بالبحث القائم على التجزئة (hashing) بدلًا من بنية اللوغاريتم المتقطع التي تستهدفها خوارزمية Shor، فإن التهديدين يتطلبان دفاعات منفصلة تمامًا: توقيعات ما بعد الكم لأحدهما، ولا تغيير يُذكر تقريبًا للآخر ضمن الأفق الزمني المدروس.

ليست كل العملات على الشبكة معرّضة بالقدر نفسه حتى في ظل أسوأ سيناريو لكسر ECDSA. من أصل نحو ستة ملايين عملة معرّضة كميًا في Bitcoin، يُقدَّر أن حوالي 2.3 مليون فقط معرّضة بشكل غير قابل للتخفيف [2]. هذا مهم من ناحية الفرز: خطة الانتقال لا تحتاج لمعاملة كامل المعروض بالإلحاحية نفسها، إذ يمكن على الأرجح حماية غالبية العملات المعرّضة عبر آليات أخرى غير الترحيل الإجباري الفوري.

ملف تعرّض Ethereum مختلف مجددًا. ما بين 50 و65% من الإيثر يقع في حسابات كُشفت مفاتيحها ويمكنها اعتماد حماية ما بعد الكم [2]. هذا استنتاج منفصل يخص سلسلة مختلفة، وينبغي عدم إسقاطه على رقم الـ 2.3 مليون عملة الخاص بـ Bitcoin، لأن الورقتين تصفان فئتي أصول مختلفتين وآليات تعرض مختلفة رغم أنهما من المصدر نفسه [2].

ما التكلفة، من حيث الأجهزة، لتنفيذ الهجوم فعليًا

تعطي إحدى الأوراق تقديرات ملموسة للأجهزة والطاقة اللازمة لتنفيذ هجمات على غرار Grover ضد تعدين Bitcoin، وهذا مفيد لتحديد مدى بُعد التقنية الحالية عن هجوم عملي على هذا الجانب من النظام. يواجه Bitcoin بالفعل تهديدًا كميًا عبر هجمات Shor على التوقيعات ذات المنحنى الإهليلجي، وفقًا لهذه الورقة [14]، وهذا إعادة صياغة لنفس النتيجة المذكورة سابقًا [2] وليس تأكيدًا مستقلًا. في أكثر إعداد جزئي مؤاتٍ (b = 32، 2^224 حالة معلَّمة) تنظر فيه الورقة، سيتطلب أسطول من رموز التصحيح السطحي فائق التوصيل (superconducting surface-code) نحو 10^8 كيوبت فيزيائي ونحو 10^4 ميغاواط [14].

وعندما يُضبط الإعداد ليطابق صعوبة سلسلة Bitcoin الرئيسية الفعلية في يناير 2025 (b تقريبًا 79)، تتفجر فاتورة الموارد لتصل إلى نحو 10^23 كيوبت ونحو 10^25 واط [14]. هذا يفوق بمراتب كثيرة أفضل الحالات المؤاتية، ويوضح بشكل ملموس لماذا تُعتبر آلية إثبات العمل مقاومة للتسريع الكمي على المدى القريب: الميزة التربيعية النظرية لخوارزمية Grover تُغرقها متطلبات الموارد الفيزيائية عند الصعوبة الواقعية.

هذان الرقمان، 10^8 كيوبت و10^4 ميغاواط في الإعداد المؤاتي مقابل 10^23 كيوبت و10^25 واط عند صعوبة السلسلة الرئيسية، مستمدان من افتراضات نمذجة ورقة واحدة، وينبغي التعامل معهما كتوضيح لحجم الفجوة وليس كتنبؤ بموعد وجود مثل هذا الأسطول. لا يذكر أي ادعاء في هذه المجموعة جدولًا زمنيًا لبناء مثل هذه الأجهزة. ينبغي للمطوّر أن يتعامل مع هذه الأرقام كفحص للحجم، لا كمدخل لخطة مشروع.

لا شيء في مجموعة الأدلة هذه يعطي تقديرًا مماثلًا لتكلفة الأجهزة اللازمة لهجوم بخوارزمية Shor على توقيعات ECDSA تحديدًا، لذا لا يمكن إجراء مقارنة تكلفة مباشرة بين مهاجمة التوقيعات ومهاجمة التعدين استنادًا لهذه الادعاءات. التقدير المتفائل لعام 2027 لكسر ECDSA (القسم 1) [7] وتكاليف أجهزة التعدين أعلاه [14] مستمدان من ورقتين مختلفتين تستخدمان طرقًا مختلفة، وينبغي عدم دمجهما في جدول زمني واحد.

مخططات توقيع ما بعد الكم المتاحة، وما يشكّلها

بدأت عملية NIST لتوحيد مقاييس التشفير ما بعد الكم في ديسمبر 2016 [12]. ومن هذه العملية، اختارت NIST ثلاثة مخططات توقيع رقمي للتوحيد القياسي: Falcon وSPHINCS+ وCRYSTALS-Dilithium [13]، وتُبرز مراجعة للمجال نفس الخوارزميات الثلاث، CRYSTALS-Dilithium وFalcon وSPHINCS+، باعتبارها الأهم للمتابعة في عملية NIST PQC [20]. برز Dilithium تحديدًا كأحد الفائزين في مسابقة NIST وهو الآن موحّد قياسيًا باسم ML-DSA (FIPS 204) [12]، وقد جرى تحديده كالخيار الأساسي لتوقيع ما بعد الكم الرقمي [13].

يعتمد أمان Dilithium على ثلاثة افتراضات صعوبة: Module Learning with Errors (MLWE)، وModule Short Integer Solution (MSIS)، وSelfTargetMSIS [13]. من بين هذه، يُعتبر SelfTargetMSIS جديدًا، وبينما هو صعب كلاسيكيًا بقدر MSIS، فإن صعوبته الكمية كانت غير واضحة سابقًا [13]. هذه الفجوة مهمة لكل من يعتمد على مستوى الأمان المُعلَن لـ Dilithium، لأن إثبات الصعوبة الكلاسيكية لمخطط ما لا يمتد تلقائيًا إلى السياق الكمي.

تسدّ إحدى الأوراق في هذه المجموعة هذه الفجوة مباشرة: فهي تقدم أول إثبات لصعوبة SelfTargetMSIS، عبر اختزال من MLWE في نموذج Quantum Random Oracle Model (QROM) [13]. ينطبق هذا الإثبات الأمني الجديد بشرط q = 1 mod 2n [13]، لذا فهو لا يغطي كل اختيار ممكن للمعاملات، بل فقط تلك التي تستوفي هذا الشرط النمطي (modular). ينبغي على المطوّر الذي يختار معاملات Dilithium لمحاكاة ما التحقق من هذا الشرط صراحة إذا كان يُقصد أن ينطبق الإثبات الأمني.

يأتي الإثبات بتكلفة حجمية. عند مستوى الأمان نفسه، يكون حجم المفتاح العام وحجم التوقيع أكبر بنحو 2.9 مرة و1.3 مرة على التوالي مقارنة بما اقترحه Kiltz et al. [13]. هذه مفاضلة مباشرة يجب على المطوّر أخذها بعين الاعتبار: الضمان الأمني الأقوى والأكثر اكتمالًا في الإثبات ينتج مفاتيح وتوقيعات أكبر مقارنة بمقترح سابق أقل اكتمالًا في الإثبات.

مقارنة نهج الشبكات (lattice) والمخططات القائمة على الأكواد والتوقيعات المجمّعة

بعيدًا عن المخططات الثلاثة التي اختارتها NIST، تطرح الأدبيات أيضًا مفاضلة أوسع بين عائلات مخططات ما بعد الكم. توفر المخططات القائمة على الشبكات (lattice-based) كفاءة حسابية أفضل، بينما توفر المخططات القائمة على الأكواد (code-based) ضمانات أمنية أقوى على حساب زيادة العبء في الاتصالات [3]. هذا إطار عام من ورقة واحدة تتناول مصادقة MANET، وليس معيار قياس خاص بـ Bitcoin، لكنه يضع توقعات مفيدة لمن يختار عائلة مخطط لبناء نموذج أولي: المخططات الأسرع القائمة على الشبكات تُقابلها مخططات أثقل لكنها أكثر تحفظًا قائمة على الأكواد.

ضمن عائلة الشبكات، جرى اختبار CRYSTALS-Dilithium مباشرة داخل سياق معاملة Bitcoin، مع عيب ملحوظ. تذكر إحدى الأوراق أن CRYSTALS-Dilithium له القصور السلبي المتمثل في تسبّبه في انخفاض كفاءة معاملات Bitcoin بمقدار 17 مرة [4]. هذا ضرر كبير في الكفاءة، ويحفّز العمل على بنى أكثر تراصًا مبنية فوق Dilithium بدلًا من استخدامه دون تعديل.

أحد هذه البنى هو مخطط LAS المقترح في الورقة نفسها. يُنتج مخطط LAS المقترح، القائم على CRYSTALS-Dilithium وبروتوكول Scalable Transparent Arguments of Knowledge (STARK) لإثبات المعرفة الصفرية، توقيعات ذات أمان ما بعد الكم وأحجام توقيع صغيرة [4]. الادعاء المُتحقَّق منه لا يصف LAS كتصميم توقيع مجمّع (aggregate-signature)، لذا لا تصفه هذه المذكرة على هذا النحو؛ إنه يجمع CRYSTALS-Dilithium مع طبقة إثبات STARK تحديدًا لمواجهة فقدان الكفاءة بمقدار 17 مرة الملاحظ مع Dilithium غير المعدّل في سياق Bitcoin في الورقة نفسها.

تتبع ورقة أخرى نهجًا مختلفًا موجهًا نحو التخزين في مقارنة المخططات ضمن إعداد صرافة قائمة على البلوكشين. فهي تقارن توقيعات ما بعد الكم الموصى بها من NIST مع ECDSA في مخطط صرافة Bitcoin، حيث تُسجَّل قيم تجزئة (hash) التوقيعات والمفاتيح العامة داخل البلوكشين وتُخزَّن محتوياتها الفعلية باستخدام IPFS [6]. هذا التصميم، تجزئات على السلسلة ومحتوى كامل على IPFS، هو خيار تصميمي متمايز عن نهج LAS، ويهدف للتحكم في تكلفة التخزين على السلسلة بدلًا من حجم التوقيع مباشرة.

ما الذي قاسته فعليًا محاكاة Python لـ ECDSA وFalcon وDilithium وSPHINCS+

أكثر نقطة مرجعية قابلة للبناء المباشر في مجموعة الأدلة هذه هي دراسة محاكاة قائمة على Python. في هذه البيئة، جرى تحليل ECDSA وFalcon وCRYSTALS-Dilithium وSPHINCS+ بالاقتران مع بروتوكولات الاتصال الكمي BB84 وE91 وSARG04 [1]. هذا الاقتران بين مخططات توقيع ما بعد الكم وبروتوكولات توزيع المفاتيح الكمية سمة مميزة لهذه الدراسة، وتمنح المطوّر نموذجًا لما يجب محاكاته وكيفية هيكلة المقارنة.

من حيث السرعة الخام، لا يزال المخطط الكلاسيكي الأساسي هو الفائز، مع تحفظ حول قابليته للاستمرار. يبقى ECDSA أسرع مخطط أساسي لكنه يفتقر إلى المقاومة الكمية [1]. هذه هي المفاضلة المتوقعة: التوقيع الكلاسيكي بالمنحنى الإهليلجي رخيص حسابيًا لكنه لا يوفر أي حماية بمجرد وجود CRQC.

من بين المرشحين لما بعد الكم، يبرز SPHINCS+ من حيث الأمان بتكلفة مقاسة. يوفر SPHINCS+ أعلى مستوى أمان بعبء متوقع قدره 93.5% [1]. لا تذكر الورقة الوحدة أو خط الأساس الدقيق الذي تُقاس عليه هذه النسبة (على سبيل المثال، ما إذا كان حجم التوقيع أم زمن الحوسبة أم مقياسًا آخر)، لذا ينبغي على المطوّر التعامل مع نسبة 93.5% كرقم مُبلَّغ عنه يجب إعادة إنتاجه وتحديده تجريبيًا، لا كرقم يفسّر نفسه بنفسه.

على صعيد الاتصال الكمي، تبيّن أن بروتوكولًا واحدًا يعمم أداءه بشكل أفضل عبر أحجام المعاملات المختلفة. حقق BB84 من بين البروتوكولات الكمية أفضل كفاءة إجمالية عبر أحجام المعاملات [1]. وبناءً على ذلك، تحدد الدراسة زوجَي تكامل موصى بهما: BB84 وCRYSTALS-Dilithium لتحقيق توازن السرعة/الأمان، وSPHINCS+ وE91 لأقصى قدر من المرونة الكمية [1]. يمنح هذان الزوجان المطوّرَ إعدادين ملموسين للبدء بإعادة إنتاجهما، أحدهما مضبوط للإنتاجية والآخر مضبوط للأمان المحافظ.

آليات الانتقال لسلسلة منشورة بالفعل

لا يمكن لـ Bitcoin تبديل مخطط توقيعه بين عشية وضحاها، إذ إن العملات القديمة مقفلة بموجب المخطط الحالي وأي تغيير في قواعد الإجماع يتطلب تنسيقًا. تعالج إحدى الآليات المقترحة هذا الأمر مباشرة. تقترح الورقة بروتوكول commit-delay-reveal الذي يسمح للمستخدمين بنقل الأموال إلى مخطط توقيع مقاوم للكم، ويعمل حتى في حال تعرّض ECDSA للاختراق، وقابل للتنفيذ كتفريعة لينة (soft fork) [15]. هذا مهم لأنه يعني أن آلية الحماية لا تتطلب تفريعة صلبة (hard fork)، وهي مصممة صراحة لتعمل حتى بعد كسر ECDSA بالفعل، وليس فقط كإجراء وقائي مسبق.

هذا التصميم القائم على commit-delay-reveal يمثل مساهمة من نوع مختلف عن معايير قياس مخططات التوقيع المناقشة في مواضع أخرى من هذه المذكرة. إنه بروتوكول انتقال، يتعلق بكيفية انتقال العملات من مخطط قديم إلى جديد في ظل ظروف عدائية، وليس مقارنة لسرعة أو حجم خوارزميات التوقيع. ينبغي للمطوّر المهتم بمحاكاة انتقال كامل، لا مجرد تبديل مكتبات التوقيع، أن يتعامل مع هذه الآلية باعتبارها الأنسب لبناء نموذج أولي لها.

لا يذكر أي ادعاء في هذه المجموعة رقم أداء (زمن استجابة، إنتاجية، أو تكلفة تخزين) للبروتوكول commit-delay-reveal نفسه. هذا يعني أن المطوّر الراغب بمعرفة عبئه سيحتاج لتنفيذه وقياسه مباشرة، إذ لا تثبت الأدلة الحالية سوى وجود الآلية، والمشكلة التي تحلها، وإمكانية نشرها كتفريعة لينة [15].

بدمج هذا مع أرقام التعرض المذكورة سابقًا، تظهر صورة معقولة (غير مثبتة كمترابطة) للفرز: غالبية عملات Bitcoin المعرّضة ليست معرّضة بشكل غير قابل للتخفيف [2]، ويوجد مسار انتقال متوافق مع التفريعة اللينة لنقل الأموال إلى توقيعات مقاومة للكم [15]. هاتان النتيجتان مستمدتان من ورقتين مختلفتين ولا يربط بينهما أي ادعاء في هذه المجموعة، لذا تعرضهما هذه المذكرة جنبًا إلى جنب دون الادعاء بأن إحداهما تمكّن أو صُممت لتكمّل الأخرى.

الحدود والأسئلة المفتوحة

أكبر ثغرة في مجموعة الأدلة هذه هي غياب أي ادعاء يذكر اختبارًا مباشرًا وجهًا لوجه لمخطط توقيع ما بعد الكم مدمَج في عقدة Bitcoin فعلية عاملة أو عميل كامل، تحت قواعد إجماع Bitcoin الحقيقية. أقرب دليل متاح هو بيئة محاكاة Python [1] ومخطط صرافة Bitcoin يسجّل التجزئات على السلسلة والمحتوى على IPFS [6]، وكلاهما بيئتا اختبار أو تكامل جزئي وليست نشرًا كاملًا للعقدة.

تختلف تقديرات موعد حدوث اختراق ECDSA في الإطار المطروح. تعطي إحدى الأوراق عام 2027 كتقدير للحالة المتفائلة [7] (انظر القسم 1)، بينما تشدد ورقة أخرى على أنه لا يوجد CRQC اليوم وأن الفجوة إلى وجوده كبيرة دون إعطاء سنة [2]. لا ينبغي للمطوّر أن يحسب متوسط هذين التقديرين أو أن يعامل 2027 كتاريخ متوقع؛ فهو صراحة أكثر الحالات تفاؤلًا في ورقته المصدرية [7].

تفتقر عدة أرقام في هذه المجموعة إلى تفصيل منهجي كامل كما وردت. رقم عبء 93.5% لـ SPHINCS+ [1] لا يحدد وحدته أو خط أساسه في الادعاء كما ورد. الانخفاض بمقدار 17 مرة في الكفاءة لـ CRYSTALS-Dilithium في سياق معاملة Bitcoin [4] وزيادتا الحجم بمقدار 2.9 و1.3 مرة لإثبات الأمان الجديد لـ Dilithium مقارنة بـ Kiltz et al. [13] مستمدتان من ورقتين مختلفتين بخطي أساس مختلفين (سياق كفاءة معاملة Bitcoin مقابل مقارنة حجم تشفيري ضد اقتراح سابق محدد) ويجب عدم مقارنتهما ببعضهما.

أخيرًا، لا يقارن أي ادعاء في هذه المجموعة مباشرة تكلفة مهاجمة توقيعات Bitcoin عبر خوارزمية Shor بتكلفة مهاجمة تعدينها عبر خوارزمية Grover باستخدام الوحدات أو الافتراضات نفسها. تقديرات أجهزة التعدين [14] وجدول كسر التوقيع الزمني [7] مستمدان من ورقتين منفصلتين بمنهجيتين منفصلتين. أي تصريح يرتّب أي هجوم أكثر وشوكًا أو أكثر استهلاكًا للموارد من الآخر سيكون استنتاجًا لا تدعمه هذه الأدلة، وقد تجنبت هذه المذكرة عمدًا إجراء هذه المقارنة.

كيفية بناء ذلك، أو كيفية استخدامه

  1. حدد النطاق. قرّر ما إذا كان المشروع معيار قياس لمخطط توقيع (باتباع نموذج محاكاة Python [1])، أو اختبار تكامل مع معاملة Bitcoin (باتباع نهج CRYSTALS-Dilithium وLAS [4])، أو اختبار بنية تخزين (باتباع تصميم التجزئة على السلسلة والمحتوى على IPFS [6]). هذه ثلاثة أشكال مشاريع متمايزة مستمدة من ثلاث أوراق مختلفة؛ اختر واحدًا لتجنب الخلط بين طرقها.
  2. اختر مخططات التوقيع المراد تنفيذها. نفّذ على الأقل ECDSA كخط أساس، بالإضافة إلى المخططات الثلاثة التي اختارتها NIST لما بعد الكم: Falcon وSPHINCS+ وCRYSTALS-Dilithium [13] [1]. استخدم تنفيذات مرجعية لكل منها؛ لا تكتب بدائل تشفيرية جديدة من الصفر.
  3. تحقق من شروط المعاملات قبل الوثوق بإثبات أمني. إذا كنت تستخدم Dilithium وتستشهد بإثباته الأمني في QROM، تأكد من أن اختيار المعاملات يستوفي q = 1 mod 2n [13]، إذ أن الإثبات في هذه الورقة مذكور على أنه ينطبق فقط في ظل هذا الشرط.
  4. ابنِ هيكل المحاكاة في Python. اتبع هيكل الدراسة المرجعية التي حللت ECDSA وFalcon وCRYSTALS-Dilithium وSPHINCS+ بالاقتران مع بروتوكولات الاتصال الكمي BB84 وE91 وSARG04 [1]. غيّر حجم المعاملة كمعامل تجريبي، إذ قاست الدراسة المرجعية الكفاءة عبر أحجام المعاملات [1].
  5. قِس السرعة مقارنة بخط الأساس ECDSA. سجّل زمن التوقيع والتحقق لكل مخطط ما بعد الكم مقارنة بـ ECDSA. توقّع أن يظل ECDSA الأسرع [1]؛ الهدف هو تحديد مقدار بطء كل مرشح ما بعد الكم تحديدًا وفق الأجهزة والتنفيذ الخاصين بك، إذ إن الورقة المرجعية تذكر الترتيب لكن المطوّر يحتاج أرقامه القابلة لإعادة الإنتاج الخاصة به.
  6. قِس العبء وأبلغ عنه بدقة. عند قياس SPHINCS+، أبلغ عن العبء بوحدة صريحة، مثل بايتات حجم التوقيع، أو ميلي ثوان زمن الحوسبة، أو النطاق الترددي. رقم العبء المرجعي البالغ 93.5% [1] لا يحدد وحدته في الادعاء كما ورد، لذا حدد وحدتك بوضوح لجعل النتيجة قابلة لإعادة الإنتاج والمقارنة.
  7. اختبر الزوجين الموصى بهما. أعد إنتاج إعدادَي التكامل من الدراسة المرجعية: BB84 مع CRYSTALS-Dilithium لتحقيق توازن السرعة/الأمان، وSPHINCS+ مع E91 لأقصى قدر من المرونة الكمية [1]. قارن كليهما بخط الأساس القائم على ECDSA وحده على عبء العمل نفسه للمعاملات.
  8. إذا كنت تختبر داخل سياق معاملة Bitcoin، قِس كفاءة المعاملة مباشرة. وجد عمل سابق أن CRYSTALS-Dilithium تسبّب في انخفاض كفاءة معاملة Bitcoin بمقدار 17 مرة عند استخدامه مباشرة [4]. تحقق مما إذا كان تنفيذك يعيد إنتاج انخفاضًا مماثلًا، وإن كان كذلك، فكّر فيما إذا كان يستحق تنفيذ غلاف قائم على توقيع مجمّع أو STARK، باتباع تصميم LAS [4]، لاستعادة الكفاءة.
  9. إذا كنت تختبر بنية تخزين، افصل البيانات على السلسلة عن خارجها بوضوح. باتباع تصميم مخطط الصرافة، خزّن قيم تجزئة التوقيعات والمفاتيح العامة على السلسلة، وخزّن محتوى التوقيع والمفتاح الفعلي على IPFS [6]. قِس نمو التخزين على السلسلة وزمن استرجاع IPFS بشكل منفصل.
  10. إذا كنت تختبر آلية انتقال، نفّذ تدفق commit-delay-reveal. يسمح هذا البروتوكول للمستخدمين بنقل الأموال إلى مخطط مقاوم للكم، وهو مصمم للعمل كتفريعة لينة، حتى إذا تم اختراق ECDSA بالفعل [15]. حاكِ مراحل الالتزام (commit) والتأخير (delay) والكشف (reveal) على شبكة اختبار أو سلسلة خاصة، وقِس تأثير نافذة التأخير على تجربة المستخدم وعلى فرصة المهاجم، إذ لا يذكر أي مصدر في هذه المجموعة هذا العبء مباشرة.
  11. أبلغ عن كل رقم مع ظروفه التجريبية الدقيقة. اذكر المعيار، وعينة العمل أو الحمل، وإعداد البرنامج/الجهاز لكل قيمة مقاسة، متبعًا النمط المستخدم في هذه المذكرة بأكملها؛ لا تُبلغ عن نسبة مئوية أو مضاعف مجرد دون السياق المذكور في الورقة المصدرية.
  12. نقاط الفشل الشائعة التي يجب التحقق منها. تأكد من أن إصدارات مكتبات Dilithium وFalcon وSPHINCS+ تطابق مجموعات المعاملات المشار إليها في وثائق التوحيد القياسي [13] [12]؛ تأكد من الشرط النمطي لإثبات QROM إذا كنت تعتمد عليه [13]؛ وأبقِ التهديد المتعلق بخوارزمية Grover على التعدين منفصلًا تمامًا عن عمل قياس مخططات التوقيع، إذ يعالجان جزأين مختلفين من النظام بنماذج هجوم مختلفة [2].

ما الذي كنا سنبنيه

كنا سنبني هيكل قياس أداء (benchmark) قابل لإعادة الإنتاج بلغة Python يقيس زمن التوقيع والتحقق وحجم التوقيع لكل من ECDSA وFalcon وCRYSTALS-Dilithium وSPHINCS+ عبر مجموعة من أحجام معاملات Bitcoin المحاكاة، متبعين هيكل دراسة محاكاة Python القائمة [1]. كنا سننفذ زوجَي التكامل الموصى بهما من تلك الدراسة، BB84 مع CRYSTALS-Dilithium وSPHINCS+ مع E91، باستخدام مكتبات مرجعية قياسية لمخططات ما بعد الكم ومحاكيات قياسية لبروتوكولات الاتصال الكمي [1].

سيُقيَّم المشروع مقابل خطي أساس ملموسين: أداء ECDSA الخام كحد أدنى للسرعة [1]، ورقم عبء SPHINCS+ المُبلَّغ عنه البالغ 93.5% كهدف لإعادة إنتاجه أو تحسينه بوحدة صريحة ومذكورة [1]. سنحاول أيضًا إعادة إنتاج الانخفاض المُبلَّغ عنه بمقدار 17 مرة في كفاءة المعاملات عند استخدام CRYSTALS-Dilithium مباشرة في صيغة معاملة Bitcoin مبسّطة [4]، للتحقق مما إذا كان هذا الرقم يصمد في تنفيذنا الخاص.

لا يحدد أي ادعاء في مجموعة الأدلة هذه جدولًا زمنيًا للتنفيذ أو حجم فريق لبناء مثل هذا الهيكل، لذا لا تقدّر هذه المذكرة أيًا منهما. ستقتصر التكلفة على وقت الهندسة والحوسبة الاعتيادية، إذ لا يتطلب أي من المخططات المعنية أجهزة كمية متخصصة لمحاكاته كلاسيكيًا. سيكون الناتج إجابة واضحة قابلة لإعادة الإنتاج حول أي مخطط وزوج تكامل يحقق أفضل توازن بين السرعة وأمان ما بعد الكم لعبء معاملات معين، مذكورة بوحدات دقيقة، على عكس رقم العبء الغامض في الدراسة المصدرية.

الادعاءات والمراجعة

  1. factمدعوم

    No cryptographically-relevant quantum computer (CRQC) exists today, and the gap to one is large.

    [2] Quantum Horizon: An evaluation of quantum computing as a threat to Bitcoin and Ethereum, section Executive summary
    Quantum computing is a real, broad-based, but bounded and substantially mitigable threat to Bitcoin and Ethereum, and recent results are compressing the timeline. The four core findings: 1. No cryptographically-relevant quantum computer (CRQC) exists today, and the gap to one is …
  2. factمدعوم

    Shor's algorithm can break the signature schemes ECDSA over secp256k1 and BLS over BLS12-381.

    [2] Quantum Horizon: An evaluation of quantum computing as a threat to Bitcoin and Ethereum, section Executive summary
    Quantum computing is a real, broad-based, but bounded and substantially mitigable threat to Bitcoin and Ethereum, and recent results are compressing the timeline. The four core findings: 1. No cryptographically-relevant quantum computer (CRQC) exists today, and the gap to one is …
  3. factمدعوم

    Grover's algorithm does not meaningfully threaten Bitcoin's proof-of-work because its speedup is only quadratic, it is crushed by fault-tolerant per-operation cost and a K√K parallelization wall, and difficulty adjustment cancels the speedup.

    [2] Quantum Horizon: An evaluation of quantum computing as a threat to Bitcoin and Ethereum, section Executive summary
    Quantum computing is a real, broad-based, but bounded and substantially mitigable threat to Bitcoin and Ethereum, and recent results are compressing the timeline. The four core findings: 1. No cryptographically-relevant quantum computer (CRQC) exists today, and the gap to one is …
  4. uncertaintyمدعوم

    The elliptic curve signature scheme used by Bitcoin could be completely broken by a quantum computer as early as 2027, by the most optimistic estimates.

    [7] Quantum attacks on Bitcoin, and how to protect against them, abstract arXiv:1710.10377v1
    The key cryptographic protocols used to secure the internet and financial transactions of today are all susceptible to attack by the development of a sufficiently large quantum computer. One particular area at risk are cryptocurrencies, a market currently worth over 150 billion U…
  5. resultمدعوم

    The proof-of-work used by Bitcoin is relatively resistant to substantial speedup by quantum computers in the next 10 years.

    [7] Quantum attacks on Bitcoin, and how to protect against them, abstract arXiv:1710.10377v1
    The key cryptographic protocols used to secure the internet and financial transactions of today are all susceptible to attack by the development of a sufficiently large quantum computer. One particular area at risk are cryptocurrencies, a market currently worth over 150 billion U…
  6. resultمدعوم

    Of Bitcoin's roughly six million quantum-exposed coins, only about 2.3 million are irreducibly at risk.

    [2] Quantum Horizon: An evaluation of quantum computing as a threat to Bitcoin and Ethereum, abstract arXiv:2606.14484v1
    Quantum computing poses a real, broad-based, but bounded and substantially mitigable threat to Bitcoin and Ethereum. We separate the two quantum algorithms that public discussion routinely conflates: Shor's algorithm breaks the elliptic-curve signatures (ECDSA over secp256k1, BLS…
  7. resultمدعوم

    50 to 65% of Ether sits at key-revealed accounts that can adopt post-quantum protection.

    [2] Quantum Horizon: An evaluation of quantum computing as a threat to Bitcoin and Ethereum, abstract arXiv:2606.14484v1
    Quantum computing poses a real, broad-based, but bounded and substantially mitigable threat to Bitcoin and Ethereum. We separate the two quantum algorithms that public discussion routinely conflates: Shor's algorithm breaks the elliptic-curve signatures (ECDSA over secp256k1, BLS…
  8. methodمدعوم

    In a Python simulation environment, ECDSA, Falcon, CRYSTALS-Dilithium, and SPHINCS+ were analyzed in combination with quantum communication protocols BB84, E91, and SARG04.

    [1] Integrating Post Quantum Cryptography Into Bitcoin Sidechains: A Simulation Based Study, abstract S2 9701bb77f1fd
    The arrival of quantum computing poses a huge threat to conventional public key cryptography used in blockchain systems such as Bitcoin. To address this challenge, we proposes and evaluates a quantum resistant sidechain framework that integrates post quantum digital signature sch…
  9. resultمدعوم

    ECDSA remains the fastest baseline scheme but lacks quantum resistance.

    [1] Integrating Post Quantum Cryptography Into Bitcoin Sidechains: A Simulation Based Study, abstract S2 9701bb77f1fd
    The arrival of quantum computing poses a huge threat to conventional public key cryptography used in blockchain systems such as Bitcoin. To address this challenge, we proposes and evaluates a quantum resistant sidechain framework that integrates post quantum digital signature sch…
  10. resultمدعوم

    SPHINCS+ provides the highest security with an expected overhead of 93.5%.

    [1] Integrating Post Quantum Cryptography Into Bitcoin Sidechains: A Simulation Based Study, abstract S2 9701bb77f1fd
    The arrival of quantum computing poses a huge threat to conventional public key cryptography used in blockchain systems such as Bitcoin. To address this challenge, we proposes and evaluates a quantum resistant sidechain framework that integrates post quantum digital signature sch…
  11. resultمدعوم

    Among quantum protocols, BB84 achieved the best overall efficiency across transaction sizes.

    [1] Integrating Post Quantum Cryptography Into Bitcoin Sidechains: A Simulation Based Study, abstract S2 9701bb77f1fd
    The arrival of quantum computing poses a huge threat to conventional public key cryptography used in blockchain systems such as Bitcoin. To address this challenge, we proposes and evaluates a quantum resistant sidechain framework that integrates post quantum digital signature sch…
  12. resultمدعوم

    The optimal integration pairs were BB84 and CRYSTALS-Dilithium for speed/security balance, and SPHINCS+ and E91 for maximum quantum resilience.

    [1] Integrating Post Quantum Cryptography Into Bitcoin Sidechains: A Simulation Based Study, abstract S2 9701bb77f1fd
    The arrival of quantum computing poses a huge threat to conventional public key cryptography used in blockchain systems such as Bitcoin. To address this challenge, we proposes and evaluates a quantum resistant sidechain framework that integrates post quantum digital signature sch…
  13. limitationمدعوم

    CRYSTALS-Dilithium has the adverse limitation of causing Bitcoin's transaction efficiency to fall by 17 times.

    [4] Improving Bitcoin’s Post-Quantum Transaction Efficiency With a Novel Lattice-Based Aggregate Signature Scheme Based on CRYSTALS-Dilithium and a STARK Protocol, abstract DOI 10.1109/access.2022.3227394
    This paper proposes a novel lattice-based aggregate signature (LAS) scheme that bring post-quantum security to the Bitcoin system without sacrificing its transaction efficiency. Bitcoin currently employs Elliptic Curve Digital Signature Algorithm (ECDSA), which is insecure agains…
  14. methodمدعوم

    The proposed LAS scheme, based on CRYSTALS-Dilithium and a zero-knowledge Scalable Transparent Arguments of Knowledge (STARK) protocol, generates signatures with post-quantum security and small signature sizes.

    [4] Improving Bitcoin’s Post-Quantum Transaction Efficiency With a Novel Lattice-Based Aggregate Signature Scheme Based on CRYSTALS-Dilithium and a STARK Protocol, abstract DOI 10.1109/access.2022.3227394
    This paper proposes a novel lattice-based aggregate signature (LAS) scheme that bring post-quantum security to the Bitcoin system without sacrificing its transaction efficiency. Bitcoin currently employs Elliptic Curve Digital Signature Algorithm (ECDSA), which is insecure agains…
  15. resultمدعوم

    Lattice-based schemes offer better computational efficiency, while code-based schemes provide stronger security guarantees at the cost of increased communication overhead.

    [3] Lightweight Post-Quantum Authentication Framework of Lattice and Code-Based Post-Quantum Signature Schemes under Mobility Constraints in MANETS, abstract S2 a024baff691f
    The rapid advancement of quantum computing poses a significant threat to conventional public-key cryptographic mechanisms deployed in Mobile Ad Hoc Networks (MANETs). Due to their decentralized architecture, dynamic topology, and resource-constrained nodes, MANETs require securit…
  16. methodمدعوم

    The study compares NIST-recommended post-quantum signatures with ECDSA in a Bitcoin exchange scheme, recording hash values of signatures and public keys within the blockchain and storing their actual content using IPFS.

    [6] A Quantum-Resistant Blockchain System: A Comparative Analysis, abstract DOI 10.3390/math11183947
    Blockchain transactions are decentralized, secure, and transparent, and they have altered industries. However, the emergence of quantum computing presents a severe security risk to the traditional encryption algorithms used in blockchain. Post-quantum signatures are required to p…
  17. factمدعوم

    Bitcoin uses the Elliptic Curve Digital Signature Algorithm (ECDSA) which is not considered post-quantum secure due to the Shor's algorithm.

    [12] Towards Post-Quantum Bitcoin Blockchain using Dilithium Signature, abstract S2 cb3f9a365986
    Bitcoin is one of the famous cryptocurrencies in the world. It is a permissionless blockchain, and all transactions are stored in a public decentralized ledger. In its security design, Bitcoin utilizes various cryptographic primitives, such as hash functions and signature schemes…
  18. factمدعوم

    NIST initiated a process to standardize post-quantum cryptographic primitives in December 2016.

    [12] Towards Post-Quantum Bitcoin Blockchain using Dilithium Signature, abstract S2 cb3f9a365986
    Bitcoin is one of the famous cryptocurrencies in the world. It is a permissionless blockchain, and all transactions are stored in a public decentralized ledger. In its security design, Bitcoin utilizes various cryptographic primitives, such as hash functions and signature schemes…
  19. factمدعوم

    Dilithium emerged as one of the winners of the NIST competition and is standardized as ML-DSA (FIPS 204).

    [12] Towards Post-Quantum Bitcoin Blockchain using Dilithium Signature, abstract S2 cb3f9a365986
    Bitcoin is one of the famous cryptocurrencies in the world. It is a permissionless blockchain, and all transactions are stored in a public decentralized ledger. In its security design, Bitcoin utilizes various cryptographic primitives, such as hash functions and signature schemes…
  20. factمدعوم

    Quantum computers are theoretically capable of breaking the underlying computational hardness assumptions for many existing cryptographic schemes.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, section 1 Introduction
    Quantum computers are theoretically capable of breaking the underlying computational hardness assumptions for many existing cryptographic schemes. Therefore, it is vitally important to develop new cryptographic primitives and protocols that are resistant to quantum attacks. The g…
  21. factمدعوم

    NIST selected three digital signature schemes for standardization: Falcon, SPHINCS+, and CRYSTALS-Dilithium.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, section 1 Introduction
    Quantum computers are theoretically capable of breaking the underlying computational hardness assumptions for many existing cryptographic schemes. Therefore, it is vitally important to develop new cryptographic primitives and protocols that are resistant to quantum attacks. The g…
  22. factمدعوم

    CRYSTALS-Dilithium was identified as the primary choice for post-quantum digital signing.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, section 1 Introduction
    Quantum computers are theoretically capable of breaking the underlying computational hardness assumptions for many existing cryptographic schemes. Therefore, it is vitally important to develop new cryptographic primitives and protocols that are resistant to quantum attacks. The g…
  23. factمدعوم

    The hardness of CRYSTALS-Dilithium is based on Module Learning with Errors (MLWE), Module Short Integer Solution (MSIS), and SelfTargetMSIS.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, abstract arXiv:2312.16619v2
    In the wake of recent progress on quantum computing hardware, the National Institute of Standards and Technology (NIST) is standardizing cryptographic protocols that are resistant to attacks by quantum adversaries. The primary digital signature scheme that NIST has chosen is CRYS…
  24. uncertaintyمدعوم

    SelfTargetMSIS is novel and, though classically as hard as MSIS, its quantum hardness is unclear.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, abstract arXiv:2312.16619v2
    In the wake of recent progress on quantum computing hardware, the National Institute of Standards and Technology (NIST) is standardizing cryptographic protocols that are resistant to attacks by quantum adversaries. The primary digital signature scheme that NIST has chosen is CRYS…
  25. resultمدعوم

    The paper provides the first proof of the hardness of SelfTargetMSIS via a reduction from MLWE in the Quantum Random Oracle Model (QROM).

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, abstract arXiv:2312.16619v2
    In the wake of recent progress on quantum computing hardware, the National Institute of Standards and Technology (NIST) is standardizing cryptographic protocols that are resistant to attacks by quantum adversaries. The primary digital signature scheme that NIST has chosen is CRYS…
  26. resultمدعوم

    The new security proof for Dilithium is applicable under the condition q = 1 mod 2n.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, section Evaluating the security of 𝖢𝖱𝖸𝖲𝖳𝖠𝖫𝖲​-​𝖣𝗂𝗅𝗂𝗍𝗁𝗂𝗎𝗆\mathsf{CRYSTALS}\raisebox{1.0pt}{-}\mathsf{Dilithium} in the quantum ra
    previous work by Kiltz, Lyubashevsky, and Schaffner (EUROCRYPT 2018) that gave the only other rigorous security proof for a variant of 𝖣𝗂𝗅𝗂𝗍𝗁𝗂𝗎𝗆\mathsf{Dilithium}, our proof has the advantage of being applicable under the condition q=1​mod​ 2​nq=1\ \mathrm{mod}\ 2n, where qq deno…
  27. resultمدعوم

    Under the same security level, the public key size and signature size are about 2.9 times and 1.3 times larger, respectively, than those proposed by Kiltz et al.

    [13] Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model, section Evaluating the security of 𝖢𝖱𝖸𝖲𝖳𝖠𝖫𝖲​-​𝖣𝗂𝗅𝗂𝗍𝗁𝗂𝗎𝗆\mathsf{CRYSTALS}\raisebox{1.0pt}{-}\mathsf{Dilithium} in the quantum ra
    previous work by Kiltz, Lyubashevsky, and Schaffner (EUROCRYPT 2018) that gave the only other rigorous security proof for a variant of 𝖣𝗂𝗅𝗂𝗍𝗁𝗂𝗎𝗆\mathsf{Dilithium}, our proof has the advantage of being applicable under the condition q=1​mod​ 2​nq=1\ \mathrm{mod}\ 2n, where qq deno…
  28. factمدعوم

    Bitcoin already faces a quantum threat through Shor attacks on elliptic-curve signatures.

    [14] Kardashev scale Quantum Computing for Bitcoin Mining, abstract S2 baadf09957d0
    Bitcoin already faces a quantum threat through Shor attacks on elliptic-curve signatures. This paper isolates the other component that public discussion often conflates with it: mining. Grover's algorithm halves the exponent of brute-force search, promising a quadratic edge to an…
  29. resultمدعوم

    At the most favourable partial-preimage setting (b = 32, 2^224 marked states), a superconducting surface-code fleet requires about 10^8 physical qubits and about 10^4 MW.

    [14] Kardashev scale Quantum Computing for Bitcoin Mining, abstract S2 baadf09957d0
    Bitcoin already faces a quantum threat through Shor attacks on elliptic-curve signatures. This paper isolates the other component that public discussion often conflates with it: mining. Grover's algorithm halves the exponent of brute-force search, promising a quadratic edge to an…
  30. resultمدعوم

    Tightening to Bitcoin's January 2025 mainnet difficulty (b about 79) explodes the bill to about 10^23 qubits and about 10^25 W.

    [14] Kardashev scale Quantum Computing for Bitcoin Mining, abstract S2 baadf09957d0
    Bitcoin already faces a quantum threat through Shor attacks on elliptic-curve signatures. This paper isolates the other component that public discussion often conflates with it: mining. Grover's algorithm halves the exponent of brute-force search, promising a quadratic edge to an…
  31. methodمدعوم

    The paper proposes a commit-delay-reveal protocol that allows users to move funds to a quantum-resistant signature scheme, functioning even if ECDSA is compromised, and implementable as a soft fork.

    [15] Committing to quantum resistance: a slow defence for Bitcoin against a fast quantum computing attack, abstract DOI 10.1098/rsos.180410
    Quantum computers are expected to have a dramatic impact on numerous fields due to their anticipated ability to solve classes of mathematical problems much more efficiently than their classical counterparts. This particularly applies to domains involving integer factorization and…
  32. factمدعوم

    The review highlights key algorithms such as CRYSTALS-Dilithium, Falcon, and SPHINCS+ in the NIST PQC process.

    [20] Exploring Post-Quantum Cryptography: Review and Directions for the Transition Process, abstract DOI 10.3390/technologies12120241
    As quantum computing advances, current cryptographic protocols are increasingly vulnerable to quantum attacks, particularly those based on Public Key Infrastructure (PKI) like RSA or Elliptic Curve Cryptography (ECC). This paper presents a comprehensive review of Post-Quantum Cry…

المصادر

  1. [1]
    Chol Hyun Park, Misael Ocas Olguin. Integrating Post Quantum Cryptography Into Bitcoin Sidechains: A Simulation Based Study. 2025 International Conference on Artificial Intelligence, Blockchain, Cloud Computing, and Data Analytics (ICoABCD), 2025.semanticscholar · primary · DOI 10.1109/ICoABCD67551.2025.11470764 · https://doi.org/10.1109/ICoABCD67551.2025.11470764
  2. [2]
    Iosif M. Gershteyn, Jacob A. Alber. Quantum Horizon: An evaluation of quantum computing as a threat to Bitcoin and Ethereum. arXiv, 2026.arxiv · primary · https://arxiv.org/abs/2606.14484v1
  3. [3]
    R. Priyavani, N. Kowsalya. Lightweight Post-Quantum Authentication Framework of Lattice and Code-Based Post-Quantum Signature Schemes under Mobility Constraints in MANETS. International Journal of Computer Science and Engineering, 2026.semanticscholar · primary · DOI 10.26438/ijcse.v14i1.7254 · https://doi.org/10.26438/ijcse.v14i1.7254
  4. [4]
    Yunjia Quan. Improving Bitcoin’s Post-Quantum Transaction Efficiency With a Novel Lattice-Based Aggregate Signature Scheme Based on CRYSTALS-Dilithium and a STARK Protocol. IEEE Access, 2022.openalex · primary · DOI 10.1109/access.2022.3227394 · https://doi.org/10.1109/access.2022.3227394
  5. [5]
    Robert Hugh Campbell. Evaluation of Post-Quantum Distributed Ledger Cryptography. The Journal of British Blockchain Association, 2019.openalex · primary · DOI 10.31585/jbba-2-1-(4)2019 · https://doi.org/10.31585/jbba-2-1-(4)2019
  6. [6]
    P. Thanalakshmi, A. Rishikhesh, Joel Marion Marceline, Gyanendra Prasad Joshi, Woong Cho. A Quantum-Resistant Blockchain System: A Comparative Analysis. Mathematics, 2023.openalex · primary · DOI 10.3390/math11183947 · https://doi.org/10.3390/math11183947
  7. [7]
    Divesh Aggarwal, Gavin K. Brennen, Troy Lee, Miklos Santha, Marco Tomamichel. Quantum attacks on Bitcoin, and how to protect against them. arXiv, 2017.arxiv · primary · https://arxiv.org/abs/1710.10377v1
  8. [8]
    Rohit Razdan, M. Nene. Post Quantum Signature for Blockchain. 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), 2025.semanticscholar · primary · DOI 10.1109/ICAFT66710.2025.11453249 · https://doi.org/10.1109/ICAFT66710.2025.11453249
  9. [9]
    Divesh Aggarwal, Gavin K. Brennen, Troy Lee, Miklós Sántha, Marco Tomamichel. Quantum Attacks on Bitcoin, and How to Protect Against Them. Ledger, 2018.openalex · primary · DOI 10.5195/ledger.2018.127 · https://doi.org/10.5195/ledger.2018.127
  10. [10]
    Adi Mutha, Jitendra Sandu. Literature Review of the Effect of Quantum Computing on Cryptocurrencies using Blockchain Technology. Journal of Informatics Education and Research, 2025.semanticscholar · primary · DOI 10.52783/jier.v5i2.3187 · https://doi.org/10.52783/jier.v5i2.3187
  11. [11]
    Tiago M. Fernández‐Caramés, Paula Fraga‐Lamas. Towards Post-Quantum Blockchain: A Review on Blockchain Cryptography Resistant to Quantum Computing Attacks. IEEE Access, 2020.openalex · primary · DOI 10.1109/access.2020.2968985 · https://doi.org/10.1109/access.2020.2968985
  12. [12]
    Michel Seck, Adeline Roux-Langlois. Towards Post-Quantum Bitcoin Blockchain using Dilithium Signature. IACR Commun. Cryptol., 2025.semanticscholar · primary · DOI 10.62056/ak5wom2hd · https://doi.org/10.62056/ak5wom2hd
  13. [13]
    Kelsey A. Jackson, Carl A. Miller, Daochen Wang. Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model. arXiv, 2023.arxiv · primary · https://arxiv.org/abs/2312.16619v2
  14. [14]
    Pierre-Luc Dallaire-Demers, Btq Technologies Team. Kardashev scale Quantum Computing for Bitcoin Mining, 2026.semanticscholar · primary · https://arxiv.org/abs/2603.25519
  15. [15]
    Iain D. Stewart, Dragos I. Ilie, Alexei Zamyatin, Sam M. Werner, Maziar Fayaz Torshizi, William J. Knottenbelt. Committing to quantum resistance: a slow defence for Bitcoin against a fast quantum computing attack. Royal Society Open Science, 2018.openalex · primary · DOI 10.1098/rsos.180410 · https://doi.org/10.1098/rsos.180410
  16. [16]
    Zebo Yang, Haneen Alfauri, Behrooz Farkiani, Raj Kumar Jain, Roberto Di Pietro, Aiman Mahmood Erbad. A Survey and Comparison of Post-Quantum and Quantum Blockchains. IEEE Communications Surveys & Tutorials, 2023.openalex · primary · DOI 10.1109/comst.2023.3325761 · https://doi.org/10.1109/comst.2023.3325761
  17. [17]
    Ohood Saud Althobaiti, Mischa Döhler. Cybersecurity Challenges Associated With the Internet of Things in a Post-Quantum World. IEEE Access, 2020.openalex · primary · DOI 10.1109/access.2020.3019345 · https://doi.org/10.1109/access.2020.3019345
  18. [18]
    Gorjan Alagic, Daniel Apon, David A. Cooper, Quynh H. Dang, Thinh Dang, John M. Kelsey. Status report on the third round of the NIST Post-Quantum Cryptography Standardization process, 2022.openalex · primary · DOI 10.6028/nist.ir.8413 · https://doi.org/10.6028/nist.ir.8413
  19. [19]
    Gorjan Alagic, Daniel Apon, David A. Cooper, Quynh H. Dang, Thinh Dang, John M. Kelsey. Status report on the third round of the NIST Post-Quantum Cryptography Standardization process, 2022.openalex · primary · DOI 10.6028/nist.ir.8413-upd1 · https://doi.org/10.6028/nist.ir.8413-upd1
  20. [20]
    Kanza Cherkaoui Dekkaki, Igor Alexander Bello Tasic, Maria‐Dolores Cano. Exploring Post-Quantum Cryptography: Review and Directions for the Transition Process. Technologies, 2024.openalex · primary · DOI 10.3390/technologies12120241 · https://doi.org/10.3390/technologies12120241