← index

Post-Quantum HD-Wallets, Silent Payments, Key Aggregation, and Threshold Signatures

An archive of delvingbitcoin.org · view original topic →

Jesse Posner · #1 ·

The algebraic structure of lattices suggests that HD wallets, silent‑payment–style addresses, key aggregation, and threshold signatures can be built on post‑quantum primitives and could, in principle, align with the current draft BIP‑360 (P2QRH) and ML‑DSA (Dilithium, FIPS 204).

Taken together, these papers indicate there is nothing inherently blocking lattice‑based post‑quantum replacements for BIP‑32, BIP‑352 silent payments, MuSig, or FROST.

Sanket Kanjalkar · #2 ·

Awesome. It is great to know that there is nothing conceptually blocking these technologies in PQ world.

Have you had time to investigate each scheme’s pros and cons compared to today’s ECDSA options? Maybe some of them might not be practical or some of them might be even more attractive than ECDSA alternatives. For example, it seems like Musig/Frost equivalent is only 1 round signing instead of 2 rounds which is big deal

Jesse Posner · #3 · · in reply to #2

That’s a great point! I will follow-up after I dig in deeper to understand all the tradeoffs.

conduition · #4 ·

Nice finds Jesse. My first major issue is that some of these articles are paywalled so I can’t read them in totality. For those that I can read, i have some critiques.

A Secure Hierarchical Deterministic Wallet with Stealth Address from Lattices