New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

An introduction to post quantum signature schemes for Ethereum by Pierre Daix-Moreux | Devcon SEA

DevconThu, Oct 9, 2025, 12:00 AM

In this lightning talk, we will give attendees the opportunity to understand the various post-quantum signature schemes proposed to make Ethereum post-quantum ready. Speaker(s): Pierre Daix-Moreux Skill level: Beginner Track: Applied Cryptography Keywords: Cryptography, Signatures, Quantum resistance, scheme Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] [Music] hi all right so a bit of context about um why do we need postquantum signature schemes for ethereum um so what canum quantum computers do uh so you can think about it as a very good as quantum computers at being very good at exploring large search spaces which are typically the kind of spaces in which cryptography operates in so there was a a researcher called Peter Shaw that proposed one day an algorithm that would uh solve the discrete log uh problem very efficiently uh so the discret L problem is one of the most fundamental problem uh in crypto in cryptography and he showed a very efficient algorithm that would break uh this kind of problem uh very efficiently um and um hashing however is safe so there's there's quantum computers can make some improvements at it but we basically consider them to be safe so it's really about the ecdlp and things that ose the ecdlp and also pairings that will break catastrophically so what does it mean for ethereum and my goal here is just to give you a bit of um an intuition of what ethereum is faced with so here is a bit the what it will look like for ethereum in terms of constraints so the consensus layer in ethereum uses some aggregation scheme which um uh is BLS signatures and what we would like to to do for ethereum is basically to keep some aggregation scheme uh because it makes running a node um easy you don't have too much Hardware requirements so we would like to have an aggregation scheme uh that uh is that does not require too much Hardware from the node Runners and that will still uh be post Quantum uh ready same for the execution layer so we would like to have a postquantum scheme that lets us keep the account based model that we have on eum and yet minimize the requirements that will be made to wallet teams when we will when we ask them uh when ethereum will ask them to to change to maybe change the signature scheme that they use so that's the that's the constraint space that we have we want to to avoid uh to have uh signature schemes that impose too much of a load on nodes and also we want some signature schemes that make it possible to have a postquantum secure execution layer where we can make transactions safely so what kind of cryptographic objects do we have to do that what what is the toolbox that is at that is at our disposal to do that so here what we want is we want a cryptography that can run on our everyday computers but can still remain secure against adversaries that have access to quantum computers basically and so to do that we already have some uh some answers so we have harh functions as we saw before which are safe we can say U we also have laes uh so here laes are nice because they are pretty fast when you want to generate signatures but they generate pretty large ones and we also have things like isogenes which help us get small signatures but are kind of slow they are getting faster and they don't have an aggregation scheme yet but this is one of the crypto some of the cryp phography tools that we can use to help make ethereum postquantum safe and so I give some examples here so there is the m module based um ltis signature scheme which is a recent nist standard I think so here you see it use laes you also have the winter knit signatures which are hash based and you have also you can also use some stack based aggregation technique uh with a post postquantum resistance signature scheme and you can see in all of those proposals it's based on latices hashes isogenes and you will see those things come again and again and again in the proposals that will be that will be made for making for helping ethereum be postquantum secure so what's next uh so it's pretty hard to predict when a quantum computer is going to to come to come up and also at what rate it's going to come up maybe it's going to come up one day it's going to pop up and we are going to be like oh wow okay now we need to switch or maybe it's going to come up um U slowly but surely uh some think that quantum computers are are not even physically realizable recently there was a a blog post by Scott arenson where he was saying that basically he would be very surprised if quantum computers don't come in the next 10 years and um this is a probability density which pretty fat tail so I think it's not it's not very useful it's not very telling something and there was a proposal by Justin Drake that he was thinking about using Quantum canaries so um um the idea of making a puzzle that can only be broken by a quantum computer so that if you break it you get a lot of money but at least we will know that when the pral is broken it will be the time to switch to some postquantum uh schemes thank you thank you Pi question time do you want to throw it yeah okay so I can I cannot do it with my foot right I cannot I don't know can I guess you can oh well it's soft enough oh no no I can't okay thank you pretty good stroll um with nist approving just postquantum uh algorithms now for the first time do you think that the end or the governments in general know more already about the state of uh quantum computers available uh I have absolutely no idea like there's there's no public evidence of anything right that the Chinese or the us or anyone would have I would definitely lie on the paranoid side but I have absolutely no idea yeah okay next question what makes lates so well suited to postquantum security I hear them coming up a lot so um it's it's just that they to you can think of it as uh if you try to find the key that you use in your scheme if you use letes uh quantum computers are not at all efficient uh with this um so the goal of cryptography in general is to find very very hard problems and to turn those problems into um schemes basically and the problems that you have with Lees are uh very hard um and are and at for which quantum computers are not very good at so it's I think it's it's hard to go into the mathematical details first because I'm not very familiar with them uh but also like in 10 seconds it's in it's hard to explain in 10 seconds but basically um you can think of it as a as a very hard problem uh which is um still complex for Quantum commuters to solve yes and okay and what challenge is ethereum current uh facing in adopting the postcon signature or what issues may arise in this Pro progress oh that's a good question uh so so you have changed es on the consensus layer so for the clients that are that are trying to reach the in the proof of stake model that we have um you have changes uh in terms also in the execution layer so for all the transaction approving logic um so I think there will be uh engineering challenges for instance does that mean that we need to audit everything again um do we need to make standards again uh um so uh yeah yeah and also I think it depends of of the timeline because if one quantum computer pops up tomorrow then uh the challenge to do it will be much more pressing than than if we have like a much larger timeline to think about so it's it would also be an engineering and human problem yes yeah okay that's everything thank you [Applause] P our next speaker ER is Henry he is the head of ecosystem from darkar neck Foundation today

Automatic transcript — names and jargon may be misspelled.