Crypto Prices

Coinbase Prepares for Quantum Threats in Bitcoin Security with Innovative Custody Solutions

51 minutes ago
2 mins read
1 views

Coinbase’s Response to Quantum Computing Threats

As the threat of quantum computing looms over the security of Bitcoin and other cryptocurrencies, Coinbase aims to bolster its defenses against this potential risk. Yehuda Lindell, the company’s head of cryptography, shared insights during a recent segment on MARA Foundation TV, stressing that Coinbase is proactively developing its post-quantum security strategies. This forward-looking approach is vital in preparing for diverse technological evolutions that Bitcoin and the broader digital assets ecosystem might encounter as they face quantum adversaries.

Post-Quantum Signature Schemes

Lindell highlighted the ambiguity surrounding the future of Bitcoin’s post-quantum signature schemes. He noted,

“It’s improbable that there will be one uniform signing scheme utilized across all networks,”

indicating that readiness for various blockchain outcomes is crucial. As Coinbase manages around $250 billion in assets for major clients like BlackRock, they’ve dedicated significant effort over the years to enhance their operational protocols against evolving threats.

Multi-Party Computation (MPC)

Currently, one of the key technologies under consideration is Multi-Party Computation (MPC), which shares similarities with Bitcoin’s multi-signature setups. MPC allows for the division of a private key into shares held by different entities, permitting multiple signatories to manage transactions while minimizing the risk of key exposure on any single device. In contrast to Bitcoin’s traditional on-chain multi-signature mechanisms, which create enforceable quorum rules, MPC operates off-chain using specific cryptographic functions. This system helps prevent a single point of failure by requiring a necessary subset of key shares for each transaction implementation.

Challenges with Hash-Based Signatures

However, as the industry anticipates advancements in post-quantum technology, experts are concerned that some signature schemes, particularly those based on hash functions, may not be compatible with MPC. The reason hash-based signatures are deemed secure against quantum threats lies in their lack of a predictable mathematical structure, which complicates their integration into MPC frameworks. Lindell echoed this sentiment, stating,

“MPC-friendliness or non-MPC-friendliness makes a very big difference.”

Despite prior beliefs about the incompatibility of executing MPC with hash-based signatures, leading cryptographers like Dan Boneh are investigating feasible solutions, as illustrated in the innovative “PRAWNS” paper. Nonetheless, this research remains in the experimental stage, leaving the possibility of establishing an effective MPC-like protocol for hash-based signatures still up for debate.

Contingency Plans and Security Measures

The potential drawbacks of hash-based signatures have also raised concerns among developers, including Ledger’s CTO, Charles Guillemet. Should Bitcoin opt for a post-quantum signature scheme that proves incompatible with MPC, Coinbase is contemplating a contingency plan that revolves around programmable Hardware Security Modules (HSMs). These HSMs serve as digital vaults, securely housing encrypted keys within protected environments. In this framework, private keys would be encrypted using post-quantum cryptography but would only come together within the secure confines of the HSM, despite the theoretical security risks posed by temporarily consolidating the complete key.

Lindell dismissed these security concerns, noting the stringent physical protections and code-upload controls that accompany HSM implementations, contributing to his confidence in this approach. Given the uncertainty surrounding Bitcoin’s transition to a post-quantum signature system, Coinbase is ensuring that its custody operations can adapt to any emerging signing methodology that Bitcoin might champion in the future. Although the timeline for finalizing these post-quantum security measures remains unclear, Lindell expressed optimism, stating,

“Once it’s complete, I’ll be able to say, ‘I can support anything.’ We won’t fear a blockchain choosing a scheme we are unable to accommodate.”

Popular