Bitcoin's Quantum-Secure Future: Lattice-Based Signatures Gain Momentum
Blockstream Research has published a comprehensive report on lattice-based signatures for Bitcoin. These signatures are crucial for authorizing transactions in Bitcoin, but they have extremely low costs and can be broken by a sufficiently powerful quantum computer.
In 1994, Shor proved that both Schnorr and ECDSA signatures could be broken by a powerful quantum computer. While there is still debate over when such machines will be built, it's essential to have a post-quantum signature deployment plan in place before the problem arises.
Lattice-based signature schemes are a leading candidate to replace existing signatures. They offer several advantages, including low public key and signature sizes (under 1.6 kilobytes) and future potential for supporting multisignatures and threshold signatures.
The report examines three lattice-based signature schemes: Dilithium, Falcon, and Hawk. The evaluation criteria include on-chain cost, implementation complexity, deployment risk, and future potential. The report compares the parameter sets across all security levels to help readers weigh the trade-offs.