Learning Objectives:
-
Master MPC fundamentals
-
Understand MPC applications in blockchain
-
Analyze MPC security properties
2.7.1: MPC Fundamentals
Definition:
Secure Multi-Party Computation (MPC) enables multiple parties to jointly compute a function over their private inputs while keeping those inputs private.
Core Concept:
MPC Scenario: Party 1: Private Input x₁ Party 2: Private Input x₂ ... Party n: Private Input xₙ Goal: Compute f(x₁, x₂, ..., xₙ) Security Requirements: 1. Privacy: Inputs remain private 2. Correctness: Output is correct 3. Independence: No party can influence result Example: Private vote counting - Each person votes privately - Public result: Vote count - Individual votes remain secret
2.7.2: MPC Protocols
1. Garbled Circuits:
Garbled Circuit Protocol: 1. Circuit representation of function 2. Garbling: Encrypt truth table entries 3. Evaluation: Decrypt with input keys 4. Output: Final result Benefits: - Constant rounds - Secure against semi-honest - Extensible to malicious Limitations: - Circuit size large - Communication heavy - Preprocessing required
2. Secret Sharing:
Secret Sharing:
Shamir Secret Sharing:
Polynomial f(x) = a₀ + a₁x + ... + a_{t-1}x^{t-1}
Secret: a₀ = f(0)
Shares: f(1), f(2), ..., f(n)
Threshold: t-of-n shares needed
MPC using Secret Sharing:
1. Share inputs among parties
2. Compute operations on shares
3. Reconstruct final output
4. Inputs remain private
3. Oblivious Transfer:
Oblivious Transfer (OT):
1-out-of-2 OT:
- Sender: Messages m₀, m₁
- Receiver: Choice bit b ∈ {0,1}
- Receiver learns m_b
- Sender learns nothing
Properties:
- Sender's privacy: Other message hidden
- Receiver's privacy: Choice hidden
- Information-theoretic security
Applications:
- Garbled circuits
- PSI (Private Set Intersection)
- Private information retrieval
2.7.3: MPC in Blockchain
1. Threshold Signatures:
Threshold Signatures (MPC): Participants: - n parties with private key shares - t parties needed for signature Benefits: - Distributed key generation - No single point of failure - Secure key storage - Fault tolerance Applications: - Exchange security - Corporate wallets - DAO governance - Recovery mechanisms
2. Private Key Generation:
Distributed Key Generation (DKG): 1. Each party generates random share 2. Share commitment (Feldman VSS) 3. Public key = sum of shares × G 4. No single party knows full key Benefits: - No key holder - Distributed security - No single point of failure - Fault tolerant
3. Confidential DeFi:
Private DeFi with MPC: 1. Private Order Book: - Orders encrypted - Match private - Trade execution verified 2. Private Liquidity Pools: - Liquidity hidden - Trades private - Fees distributed 3. Private Credit Scoring: - Borrower data private - Score computed jointly - Lender sees score only
2.7.4: MPC Security
Security Models:
MPC Security Models: 1. Semi-Honest (Honest-but-Curious): - Parties follow protocol - But may try to learn extra info - Weaker security model 2. Malicious: - Parties may deviate - Arbitrary behavior - Stronger security 3. Covert: - Parties may cheat - Risk of detection - Balanced model 4. Information-Theoretic: - Security against unlimited computation - Perfect security - Requires trusted setup
Attack Vectors:
| Attack | Description | Mitigation |
|---|---|---|
| Active Attack | Malicious behavior | Verification, ZK proofs |
| Passive Attack | Eavesdropping | Encryption, secret sharing |
| Sybil Attack | Fake identities | Identity verification |
| Collusion | Parties cooperate | Threshold schemes |
| Fault Injection | Protocol errors | Error correction |
ADDITIONAL DEEP TECHNICAL NOTES:
1. MPC Protocols Comparison
| Protocol | Rounds | Communication | Computation | Security |
|---|---|---|---|---|
| Garbled Circuits | Constant | O(n²) | O(circuit) | Semi-honest |
| Secret Sharing | O(depth) | O(n²) | O(n) | Information-theoretic |
| OT Extension | O(1) | O(n) | O(n) | Computational |
| SPDZ | O(1) | O(n²) | O(n) | Malicious |
2. MPC Use Cases in Blockchain
Use Cases:
| Use Case | Description | Participants |
|---|---|---|
| Key Management | Distributed custody | Multiple institutions |
| Cross-Chain Swaps | Atomic swaps | Trading parties |
| Private Auctions | Blind bidding | Bidders |
| Secure Matching | Trade execution | Buyers, Sellers |
| Decentralized Identity | Verifiable credentials | Issuers, Holders |
Lesson 2.8: Post-Quantum Cryptography for Blockchain
Learning Objectives:
-
Understand quantum computing threats
-
Master post-quantum cryptographic schemes
-
Analyze blockchain quantum resistance
2.8.1: Quantum Computing Threats
Quantum Computing Impact:
Quantum Computing Threats: Shor's Algorithm: - Factors integers exponentially faster - Breaks RSA, ECC, DSA - Impact: All public-key crypto Grover's Algorithm: - Searches unsorted databases quadratically faster - Weakens symmetric crypto (128→64 bits) - Impact: Hash functions, AES Timeline: - 10-20 years (speculative) - Quantum computers growing - Prepare for migration
2.8.2: Post-Quantum Cryptographic Schemes
1. Lattice-Based Cryptography:
Lattice-Based Schemes: NIST Standards: 1. Kyber (Key Encapsulation): - Module-LWE based - Fast and compact - FIPS 203 (soon) 2. Dilithium (Digital Signatures): - Module-LWE based - Small signatures - FIPS 204 (soon) 3. Falcon (Digital Signatures): - NTRU-based - Small signatures - FIPS 205 (soon) Security Assumptions: - Learning With Errors (LWE) - Ring-LWE - Shortest Vector Problem (SVP)
2. Hash-Based Signatures:
Hash-Based Signatures: SPHINCS+: - Stateless hash-based signatures - No state management - FIPS 206 (soon) Properties: - Quantum-resistant - Only hash functions - Secure signatures - No secret state XMSS: - Stateful hash-based - Efficient signatures - Requires careful state management - NIST approved (SP 800-208)
3. Code-Based Cryptography:
Code-Based Schemes: McEliece: - Classical code-based - Large public keys - Fast encryption/decryption - Quantum-resistant BIKE: - Binary LDPC codes - Smaller keys - Faster than McEliece - Under consideration
2.8.3: Blockchain Quantum Resistance
Current State:
Quantum Vulnerabilities: 1. Public Keys: - ECDSA: Quantum breakable - Schnorr: Quantum breakable - BLS: Quantum breakable 2. Addresses: - Bitcoin: 160-bit RIPEMD-160 - Security reduced to 80 bits - Still secure (for now) 3. Hash Functions: - SHA-256: 128-bit security (Grover) - Still secure - Post-quantum safe 4. Signatures: - All current schemes vulnerable - Need migration
Migration Strategies:
Quantum-Resistant Migration: 1. Hybrid Signatures: - ECDSA + Post-quantum - Backward compatible - Gradual migration 2. Signature Aggregation: - Post-quantum signatures - Different schemes - Gradual transition 3. Quantum-Safe Blockchains: - Post-quantum signatures - New consensus - Fully quantum-safe 4. Address Migration: - New address formats - Gradual transition - User awareness
2.8.4: Quantum-Safe Blockchain Projects
Examples:
Quantum-Safe Blockchain Initiatives: 1. QAN Platform: - Post-quantum consensus - Lattice-based signatures - Quantum-resistant 2. Quantum Resistant Ledger (QRL): - XMSS signatures - Post-quantum ready - Active development 3. Algorand: - Planning post-quantum - Signature aggregation - Future-proofing 4. Ethereum: - Research ongoing - Post-quantum roadmap - Gradual migration
2.8.5: Future-Proofing Blockchain
Recommendations:
Future-Proofing Strategies: 1. Use Larger Hash Sizes: - SHA-512 instead of SHA-256 - 256-bit security - Grover-resistant 2. Adopt Post-Quantum Signatures: - Dilithium, Falcon, SPHINCS+ - Multiple algorithms - Hybrid approach 3. Maintain Flexibility: - Upgradeable protocols - Multiple signature schemes - Migration capabilities 4. Plan Migration: - Regular security assessments - Quantum readiness - User education
ADDITIONAL DEEP TECHNICAL NOTES:
1. Post-Quantum Signature Comparison
| Signature | Public Key | Signature Size | Signing Speed | Verification Speed |
|---|---|---|---|---|
| Dilithium | 1.3 KB | 2.4 KB | Fast | Fast |
| Falcon | 0.9 KB | 0.7 KB | Fast | Very Fast |
| SPHINCS+ | 0.1 KB | 17-50 KB | Slow | Slow |
| XMSS | 0.1 KB | 2-8 KB | Medium | Medium |
2. Quantum Resistance Timeline
Migration Timeline: 2024-2026: - Research and standards - NIST standards finalized - Initial implementations 2026-2028: - Hybrid signatures - Testing and validation - Early adoption 2028-2030: - Industry migration - Major blockchains - Quantum-safe protocols 2030-2035: - Complete migration - Quantum computers - Legacy retirement