This lecture explains how to correctly implement cryptographic primitives in blockchain systems, focusing on threshold signatures for key protection. The instructor distinguishes between two types of threshold signatures: accountable threshold signatures (ATS) which reveal which parties signed a message for consensus purposes, and private threshold signatures (PTS) which hide the signing parties and threshold to protect keys. The lecture emphasizes that multi-sig is inefficient and cannot support proactive refresh, while BLS and Schnorr-based threshold signatures are preferred. A critical security concern discussed is perpetual leakage, where attackers gradually compromise secret key shares over time, which can be mitigated through proactive refresh protocols that periodically refresh shares without changing the public key. The instructor also highlights emerging cryptographic tools like confidential computing and zero-knowledge proofs that are being increasingly applied to solve blockchain challenges such as MEV (Maximal Extractable Value) problems.
Dan Boneh: Cryptographic Best Practices for Blockchain Security | Crypto Startup School 2023
Added:[Music] thank you all right thank you Jeff this was uh it's wonderful to be here it's wonderful to see all the teams I'm really really excited and looking forward to seeing what comes out of what you're building so welcome all and let's get started so I guess I should say also by the way thank you to a16z for hosting this wonderful event so so let's get started so I guess when people ask me what I work on I typically say that I I work on the science of blockchains yeah so there's blockchains and then there's the science of blockchains the science of blockchains is basically the underlying technology that makes blockchains work and it's amazing how much technology is needed to make blockchains work and in fact the world of blockchains is dramatically pushing forward different tiers of Science and you know much of the rest of society can benefit from that as well so I primarily am a cryptographer yeah I work on cryptography cryptography for uh for blockchains and in fact as you might have heard there is a lot of cryptography used in the world of blockchains yeah so just to give you a few examples uh you know blockchains use a lot of uh data Integrity mechanisms like digital signatures commitment schemes uh proof systems and so that's all kind of about data Integrity what's interesting is also in in kind of the recent year or so it turns out there's also a need for other types of cryptography in blockchains primarily having to do with privacy and security these are things like zero knowledge proof systems it turns out even fancy encryption schemes um now come up in the in the world of blockchains specifically to address some Mev proposals and I think I'll talk about that towards the end of the lecture it's really really quite fascinating uh what's happening in this in the Mev space it's really dragging in a lot of very fancy encryption schemes into the blockchain space and that's going to have a lot of implications on uh what's happening in blockchains and uh Beyond and then there's also applications for multi-party computation what what's interesting is that traditionally cryptography was uh had a primary customer the customer was the internet yeah so we want want to make sure that as you type in your credit card and you send it to Amazon that credit card gets to Amazon in a secure way that type of cryptography primarily focuses on confidentiality making sure that the attackers can can't look at your data and so on so that was one type of crypto in the blockchain space is as I say here most of the cryptography that's been used up until now focuses on Integrity not so much on confidentiality because on a blockchain as you know whatever you post at least on ethereum things are kind of public for the world to see so it's kind of interesting that that it uses a different type of crypto that's what's used in the internet although as I say in the bottom this is kind of changing now even confidentiality is becoming important in the world of blockchains and we'll talk about that towards the end of the lecture okay great lots of crypto used uh in the world of blockchains the problem is you have to know what you're doing right if you try to implement cryptography is one of these things that's like an area where a little bit of knowledge is really quite dangerous yeah if you just know roughly how things work and you kind of try to throw things together very likely the system will work but it will be insecure yeah this is a very important thing to remember it's easy to get systems to work so that you know they'll they'll do what they're supposed to do but they'll be insecure and you'll never know it until somebody else points it out for you so in that sense it's an area where it's really important to know to use cryptography correctly if you use it incorrectly you end up with a bunch of hacks and that's actually what I want to talk about today basically how to use cryptography correctly in the world of blockchains so I'm going to start with signatures yeah so signatures are kind of the bread and butter of blockchains and since this is like day like week one uh what week two day two day two week one of the of the school I wanted to kind of uh start from zero yeah so let's Let Me Assume uh nobody you guys don't haven't heard of signatures let's start from the beginning we will walk through it quickly just to bring everybody up to speed so right so in the physical world we know what a signature is right when you sign a check you just you know sign your name on the check and that binds you to the to the check the problem is that in the digital world this can't possibly work right in the digital world if you just attached a a picture of your signature to a document anyone can just take that picture and stick it on a different document that maybe binds you to a much larger check and so on so we have to do something different if we're going to implement signatures in the digital world they fundamentally have to be different from signatures in the real world in the physical world so the solution is what the solution is to make it so that the signature on a document actually depends on the contents of the documents yeah so s so every time I sign a document there's a different signature attached to each document that I sign so that's how digital signatures work in the physical world in the digital world yeah so signature depends on the contents of the document and so let's dive a little bit more deeply and see what the syntax of a digital signature is and so there are three algorithms in a signature system yeah there's a key generation algorithm what's a key generation algorithm does is it generates what we call a secret key and a public key right the secret key is used to sign messages the public key is used to verify signature signatures then there's a signing algorithm that uses the secret key to sign a particular message and it outputs a signature and then there's a verify algorithm that takes the public key the message and a signature and says yes this is a valid signature or no this is an invalid signature yeah that's kind of the syntax for a digital signature scheme I hope many of you have seen it before one thing that I want to stress is when we talk about cryptographic Primitives it's more important it's important to talk about what the API is which is what I showed you here but it's more important to talk about what does it mean for the Primitive to be secure yes I always want you to think about security for these Primitives and so what does it mean for a digital signature scheme to be secure well there's a formal model that explains what security means I didn't want to bore you with like formal definitions in cryptography so I just wrote Things in English plain English so what does it mean for a signature scheme to be secure it means that an adversary who gets to see many many signatures on messages of their choice of course the adversary also gets the public key so public key plus many signatures of messages of their choice can't produce a signature for some new message yeah that's what we call existential unforgeability yeah the word is existential unforgeability I can I can give you as many signatures as you want for any messages that you want you will never be able to sign another message that's the security property for a signature scheme terrific okay so now we know what a signature scheme is I was actually going to tell you a little bit about how to Future proof the signing key and to protect yourself from potential future Quantum attacks but I think in the interest of time maybe I'll skip over this and we'll come back to this if you guys are interested in protection against Quantum attacks we'll come back to this uh at the end of the lecture so I'll skip this for now and let's talk about other ways to protect the signing key okay so how do we protect uh the signature key you know the signature key is really crucial for us right this is how we sign transactions if somebody steals your secret key they can they're basically you right they can steal all the assets from your from your wallet they can uh issue transactions on your behalf and unfortunately these things really do happen in the real world so how do we protect the signing key again I'm going to start slow and then we'll build up from there I hope many of you have heard of what's called thresholds cryptography threshold signatures but let's walk slowly and see what these things are so this is a way to protect a signing key how do we protect it we protect it basically by splitting it up into pieces okay and so uh yeah so here's an example of splitting up a key in a two out of three way yeah so basically let's see so we'll have a key generation procedure here I'll show it to you again we have a key generation procedure that will generate three secret keys sk1 sk2 and sk3 and three different parties will have those secret keys and these keys are set up in such a way that when somebody wants to sign a message they can send the message to these three parties yeah so they all get to see the message and then maybe I don't know maybe two of them decide to respond so so they check some policy that the message is valid you know this is a valid transaction that you know the user is authorized to request signatures and assess messages and then let's say two of them respond with uh what we call Signature shares yeah so we'll use I couldn't avoid I couldn't resist using some Greek letters in this talk so we'll use Sigma 1 and sigma 2 for the signature shares yeah so they respond with the shares and then there's another party called a combiner that takes the signature shares combines them together into the actual signature that uh that you can publish to the world and anyone can verify that signature using the public key yeah so that's basically kind of how a threshold signature works again I imagine many of you uh have seen it before by the way the reason I'm showing you this is uh one of the points that I want to make is that again there's a lot of cryptography used in blockchains I know a lot of people when they talk about cryptography and blockchains now they hone in on zero knowledge proofs which is a Big Tool in blockchains but and we're going to talk about zero knowledge proofs in week three I think yeah so there's a whole week devoted to the topic but I want to stress that there's a lot more to cryptography than just your knowledge proofs yeah and everything has to work correctly it's not just enough to get your proof system to work correctly good so uh yeah so let's continue our story with threshold signatures so that's what they are right so we can generate these signatures in a threshold way and there are a couple of applications uh for this yeah so the two applications that come to mind are one as we said it's a way to protect the secret key so for example you can take your secret key break it up into three shares store the shares on different machines maybe some of the shares are stored in a safe that's offline uh but you can you can uh split your key in this way the point is if the adversary breaks into just one of the shares and steals steals one of the shares he does not get your secret key what's interesting about this application is if you take your secret key and split it up let's say into nine shares or five are needed to generate a signature if you're doing it to protect the secret key maybe you want to hide actually what the threshold is yeah so the attacker maybe can compromise the attacker can compromise less than T shares and he's not going to be able to uh generate to generate fake false signatures on your behalf but maybe you want to even make it so they attack so the attacker doesn't even know what the threshold is in that case right so if you do a five out of nine scheme ideally you want to hide the fact that you're using five out of nine so the attacker the poor attacker doesn't even know that they're supposed to steal five shares right so we'll talk about how to do that in just in just a second so that's one applications basically to make sure that the key is protected and the attacker doesn't even know how many shares they need to steal the other application of course is when we want consensus for example in a bridge uh you know the bridge might author if it's a you know mint and burn Bridge the bridge might need to have a coalition of parties sign and approve minting or approve burning of um of assets in which case we would use threshold signatures to uh to indicate agreement right so if five out of the nine trustees share a sign that means oh five out of the nine trustees agree that this is a valid operation and then the operation can go forward yeah so there are two applications for threshold signatures one to protect keys and the other one to indicate agreement indicate consensus that an operation is supposed to um to happen and again I stress that these are very different applications for threshold signatures and in fact it turns out this is important to remember in fact for these two applications we need to use different types of threshold signatures yeah so so I want you again when you use threshold signatures I want you to think why are we using them are we using them for consensus or are we using them for protection of the key and let me explain what I mean by that what I mean by that oh okay so before I explain what I mean by that I guess I have to go through the API of threshold signatures so let's do that very quickly what does it mean what is a threshold signature what's the syntax and then we'll come back and see what the differences are between protection and consensus so what's the syntax well let's see so there's again a key generation algorithm but now the key generation algorithm is a little bit different right the key generation algorithm will generate a public key here let me use my magical stick here so the key generation algorithm will generate a public key and then it will generate uh n shares if we want to generate uh shares for end parties so in the 5 out of 9 case we'll generate nine secret keys and we'll give one secret key to each party then there's a signing algorithm the signing algorithm is something that each party runs on its own yeah so it'll take one of the secret Keys one of the nine secret Keys the message and potentially the set that's actually generating is generating a signature this is called a quorum right so the Quorum of five out of the nine that's generating the signature and it'll generate what's called a signature share Sigma sub I then there's a combined algorithm that will check that will take all the signature shares that have been generated by the Quorum and if the Quorum contains more than the threshold number of parties it will generate the actual signature yeah so if you have fewer than a threshold number of parties sorry you cannot generate a signature but if I give you enough shares then the signature uh becomes uh you know you can generate that signature in fact anyone can generate the signature just using the public key and of course finally there's a verify algorithm that checks that the signature is valid does this make sense to everyone so uh yeah this is kind of the standard API for a digital signature system and again as I said it's more important to to understand what the API is it's more important to State what is what is the security property for a threshold signature scheme so here security is a little bit harder to say the state so again we're going to State it just informally let me try to explain what the security property is the security property basically says if the adversary is given the public key and somehow by Magic the adversary was able able to recover up to T minus one secret Keys yes in the case of five out of nine maybe the adversary was able to recover three of the secret Keys literally by breaking into three machines the adversary was able to recover three secret Keys that's not enough for the adversary to fake to forge signatures yeah he needs five shares to afford signatures but uh we also gave him the ability to uh go to any party that he wants and say hey Mr Bob give me give me a signature share on this particular message okay so we give the adversary some shares and we give the some secret key shares and we allow the adversary to ask individual parties to sign messages on his behalf and and the adversary even he has though he has all this power he shouldn't be able to produce a signature on any message for which he has less than t-shares yeah that's the requirement so unless he gets teeth unless he gets T signature shares for a particular message he can't actually produce a valid signature um on on the message on a new message that he wants yeah so that's kind of informally what the security property uh is and it turns out actually we can build these uh we can build um uh threshold signature schemes that are quite efficient and pay attention because there's a quiz coming so uh I'm gonna ask you the quiz in just a second so let's go back to the two types of threshold signatures that I wanted to tell you about so again when you talk about app when you try to use threshold signatures yourself I'm sure you're going to be using them in your projects yeah these are so inherent now to blockchains I'm sure you're going to be using threshold signatures in your project and so I went again kind of organize this in your mind that there are really two families of threshold signatures and they're really quite unrelated to one another the first one is what what we call accountable threshold signatures ATS yes the word is ATS accountable threshold signatures this is what you use when you want um when you want to use threshold signatures for consensus yeah in an ATS settings you want to make sure that if a certain Quorum signs a message the signature that they produce should identify the Quorum that generated that signature let's so specifically in the five out of nine case if these five people agreed to sign a message that caused the bridge to release some funds we want the signature that they are generated to identify those five so that if they incorrectly sign the message you know they are countable we can go and blame them we can slash them we can do all sorts of things to them yeah we can kick them out of the system and so on so this is called an accountable threshold signature and the security property means that if another set of five signs a message they cannot generate a signature that looks like a different set of five generated at that signature yeah so when I look at the signature I should be able to verifiably know which set of five parties generated that signature so if something went wrong there are they are held accountable so that's what we call an accountable threshold signature that's one type the other type is what we call a private threshold signatures a pts a private threshold signature this is used this is what's used when you want to protect the secret key by splitting it up so in a private threshold signatures we want the exact opposite yeah the signature should reveal nothing about the core under generated it and more importantly the signature should reveal nothing about the threshold yeah remember in the five out of nine case I told you that we want to hide if we're protecting the key we want to hide the fact that the threshold is five so the attacker doesn't even know how many shares it needs to compromise in order to forge signatures okay so again I want to solidify this in your mind there are two types of threshold signatures and you would use a different type for different applications so if you're using it to protect Keys you would use a private threshold signatures if you're using it to to do consensus you would use an accountable threshold signature because you want accountability and these are very different constructions so let me show you the kind of the the um the simplest let's see so let me show you the simplest possible threshold signature in fact I'm going to ask you let's see if somebody can propose the simplest simplest threshold signature you know actually maybe I'll show you the signature scheme this threshold signature unless somebody has an idea like if I ask you to kind of build the trivial most threshold signature scheme what what would you do let's see if anybody has any ideas what would you do like the simplest simple simplest threshold signature that comes to mind well I kind of already wrote the answer on the slide yeah please perfectly exactly exactly so exactly so this is what's called multi-sig so multi-sig multisig is used in Bitcoin and inherited actually to in ethereum too multisig is what I call the trivial threshold scheme so let's see what how multi-sync works so in multi-sig what happens is we're going to give every every user every one of the nine shareholders is going to generate a private public key pair so their own let's say schnower signature key pair for themselves and so they're going to keep these these secret keys for themselves and the public key is just going to be the set of all public keys that these users generated okay so everybody just generates a a non-threshold a regular signature scheme signature key pair for themselves the public key is just the concatenation of all those public keys and the secret keys are just what they generated now when we want to sign a message what happens is again we send the message to all the parties you know some of the parties respond and the signature we simply append all the signatures that we got back together yeah so the signature is going to be Sigma 1 and sigma 3 which says you know two people signed and therefore this is a valid threshold signature yeah because the threshold is two in this case so we have a valid threshold signature because at least two you know two people signed so so we're happy so let me ask you this so um first of all look at the signature scheme and now you guys need to be able to answer this is this a private uh threshold signature a pts or is this an accountable threshold signature an ETS which one is it pts or ATS BTS uh let's see there's the threshold revealed does the signature reveal the threshold yes well if it's a if the signature reveals a threshold it's not private exactly this is an accountable threshold signature scheme right because when you look at the signature you literally see it says Sigma 1 and sigma 3. you literally see user number one signed and user number three sign so we know exactly who signed and therefore we have they have accountability yeah so this is used in Bitcoins uh multisig uh transactions right so when you sign uh you know exactly when in a multi-sig transaction you know exactly which subsets of the of the nine actually sign the message and you have accountability unfortunately this is I have to say this is the wrong way to implement an accountable threshold signature yeah and uh you can kind of be maybe my ambassadors here to say that if you need to implement accountable threshold signatures even though this is a trivial scheme and it's very easy to come up with this is not the right way to implement an ATS yeah this is an important message and so I'm going to explain why this is not the right way to implement an ATS first of all you realize that um ah yeah so we accept the signature if it contains valid at least T valid signatures so first of all you realize our public key is linear in size yeah because we have pk1 to pkt worse the signature is the size of the signature is linear in the threshold T right so if we have five out of nine every single signature now has to carry five signatures in it right that's kind of long five signatures so a it's a long signature B the poor verifier every time you want to verify the signature now you have to verify five signatures right this is five five times the verification work so it's long and it's inefficient to verify so these are just kind of inefficiency arguments why multisig is the wrong way to implement in ATS we're going to see a security argument uh in just a minute okay so good so then the question is how do we Implement threshold signatures ats's and pts's and it turns out basically we can take the classical signature schemes and convert them into either accountable threshold signatures or private threshold signatures how do we do it well so let's look at two families of signature schemes right so BLS signatures you know BLS signatures are used in ethereum too for consensus and snore signatures Schnur signatures are used in in Taproot and modern transactions in Bitcoin and in other blockchains as well okay so in BLS signatures it turns out it's trivial to convert it into a threshold signature you get a very efficient accountable threshold signature you get a very efficient private threshold signature uh it's just it's just fairly it's just straightforward it's like very very simple uh construction and it's nice and easy and nice and easy to use so of course maybe I'm a little biased but I highly recommend using those as an ATS and a PTS uh good Schnur signatures also give us accountable threshold signatures and private threshold signatures it's a little bit more complicated yeah there are systems to do it either using but now it requires a protocol a multi-round protocol between the combiner and the signers yeah you have to kind of go in a ping pong back and forth and you can do it in two rounds or in three rounds for a private threshold signature there's a system called Frost for an accountable threshold signature there's a system called music and it allows us to also get uh get these threshold signatures and in fact this is used in bitcoin's Taproot system I hope you guys have heard of Taproot the reason they moved uh to shinur signatures is exactly exactly so that they Implement multi-sig correctly yeah so they can use these more efficient multi-sig systems yeah and the point of this is this is much better than um traditional multi-sig just because we get shorter signatures much faster much faster to verify and uh it's just more efficient better so keep that in mind yeah if you need to use a threshold signature don't use multisig use use one of these correct threshold signatures and there are now many libraries that actually implement this for you including distributed key generation and so on so there are many open source projects that now implement this uh quite well although again you have to think do I want accountable or do I want private and many of these open source projects actually don't distinguish between the two so that's up to you you're gonna have to figure out which one you actually want terrific so uh so now we understand the kind of the core constructions now let me kind of switch gears and talk about kind of a cryptographic tool that's actually quite old in cryptography but somehow is not used in the blockchain space yeah so again I want you to know about this technique this is a very important technique for protecting secret keys that somehow very very few projects use so please I mean you need to be aware of this and I hope that in the school when you implement your systems you'll actually be using this this protection technique so this protection technique is what's called a proactive proactive refresh and the idea the problem that it comes to solve is this problem of what's called Perpetual leakage Perpetual leakage so let's go back to the Ronin hack yeah I'm sure many of you have heard of the Ronin hack Ronin was the bridge to the Ronin you know to the Ronin blockchain in that bridge used a five out of nine threshold signature yeah five out of nine and it wasn't a coincidence that I used five out of nine as my example that's exactly what Ronin used and unfortunately the attacker was actually able to control five of The Secret Keys yeah the attacker got control of five of The Secret Keys it was able to issue a fake signature to say that um uh you know the bridge should release funds to the attacker when it shouldn't have that signature was published yeah and the funds were lost this is this caused about what is it what was it about 600 million dollars or so uh were stolen in the Ronin attack and that by the way had a lot of it's a brilliant the Ronin attack is a very interesting story that had a lot of Downstream effects in the in the ecosystem maybe you've heard of what happened to tornado cash as a result and so on but let's focus on the attack itself the five out of nine uh secret shares so what happened in the uh in the rolling attack is again as I said um unfortunately um four of the shares were held by a single entity yeah and that entity one one employee at identity got hacked and as a result four of the shares got leaked so one lesson from this is if you're going to do threshold encrypt threshold signatures to protect your secret key you really have to give the secret shares to different entities it's not a great idea to have one entity hold multiple shares because that's not really what threshold cryptography is doing yeah okay but let's talk about the principles of this so the principle here is the attacker actually had a lot of time where it could just literally go entity by entity and spend as much time as it wants to extract the secret key from each entity this is what's called Perpetual leakage right the attacker invests a lot of energy and attacking one entity and gets their secret key then he turns on to another entity invests a lot of energy and gets a secret key over time he basically will eventually he will collect t-shares you know five shares and then he can issue signatures and cause a lot of damage yeah this is what's called again Perpetual leakage in threshold crypto so what do we do how do we defend against uh Perpetual leakage so actually let me ask you like what how do you how do you what would you do to defend against this Perpetual leakage problem yeah what what what comes to mind anybody have any ideas yeah please yeah in some ways like invalidate certain signatures like say remove them from the from the signing group ah I see so when a secret key is compromised maybe I see maybe you somehow kick that secret key out of the group so they can no longer sign yeah so that's a very interesting idea um there are two issues with that one is you might get hacked and you might not know that you got got hacked so your secret key might be exposed and you would never know it that's one problem the other problem is if you're going to remove a secret key from uh from a threshold signature typically that means that you have to generate a new public key yeah somehow we have to generate a new public key and then assign shares to the other eight parties and not to the one that got hacked changing the public key is kind of a painful process right because now if there are a lot of assets associated with the old public key now you have to issue transactions and pay for those transactions to move the assets from the old address to the new address yeah so changing a public key is kind of a painful painful process people do it actually a lot of the custodians they will actually generate new secret Keys every couple of months and they will spend the effort to actually move the move the funds around but we'd like to do something simpler so let me show you this trick yeah this is a good trick you need to know about this and I hope you actually get to use it in your projects so this is what's called proactive refresh it's an idea that dates back to 1991 so 30 years ago but again somehow it hasn't got somehow it hasn't reached the blockchain world so hopefully more projects will use it um we'll use it in the future and so what is the idea of a proactive refresh the idea is that we are going to constantly refreshing our secret keys so once a day let's say once an hour whatever let's say once a day we're going to refresh our secret keys but in such a way that the public key doesn't change that seems like magic right so we have like a secret sharing of of a secret key yeah a five out of nine sharing of a secret key it turns out we can actually change refresh all of our secret keys and the public key stays the same nobody the world doesn't even know that we did this refresh and because the world doesn't know we can do this as often as we want once an hour once a day and so on so let me explain how this works basically we have our parties let's say our nine part these they have their secret Keys what they're going to do is they're going to run a protocol amongst themselves this is called the proactive refresh protocol and at the end of this protocol they all all of a sudden hold new secret Keys yeah all their shares got refreshed but magically the public key doesn't change yeah magically the public key doesn't change now we can go into the mathematic mathematics of this but honestly I wanted to spare you the mathematics so I'm just going to keep it at a high level and we'll see a very very simple example in just a second okay so uh yeah so that's that so that's basically how uh the refresh works and the point of this the point of this is you know if the attacker breaks into one party today and then he breaks into another party tomorrow they'll get one secret key today from one party and they'll get a different secret key from another party tomorrow if the refresh happened in the meantime those two secret Keys tell him nothing they can't combine them anymore yeah so now the poor attacker you know he can't just take his time to attack enough parties until he gets to five parties he actually has to attack all five parties in one day that's the idea yeah and in fact if you do the refresh every hour the poor attacker now has to extract many many shares within one hour if he takes you know 90 minutes he's out of luck because the shares that he extracted in the first hour are going to be are not going to combine with the shares that he extracted in the second hour yeah does that make sense it's like you can see why this is such an important idea so it allows you again to refresh the shares and the public key does not change nobody knows nobody in the world knows that you did the refresh so you don't have to issue transactions you don't have to move assets around uh it's just a very simple and efficient way to protect your secret shares against Perpetual leakage terrific okay so we have our proactive refresh so how do we Implement that well it turns out there are um uh there are good constructions for this let's start with the basic threshold construction so the trivial basic construction is multi-sig remember multi-sig from Bitcoin go to all multi-sig well I told you it's inefficient so you shouldn't use it because it's inefficient even worse it turns out multi-sig cannot be refreshed you cannot do a proactive refresh if you use a multi-sync let's think for just one second why remember the public keys are basically pk1 to pkn right every it's a list of all public keys that all the users had if you break if the attacker breaks into user 1 and steals that user one's secret key the attacker is effectively now the same as user number one there is no way to refresh uh the shares the attacker will always be able to sign on behalf of user number one there's no way to do a refresh until you change the public key so without changing the public key in a multi-sig environment it's simply not possible to do a proactive refresh this is a really important thing to remember if you use multi-key if you're multi-sig you're effectively preventing a proactive refresh in your system so don't use multi-sig use the other threshold signature techniques okay so that's that's lesson number one problem this is a security problem with multi-sig which is one reason why we shouldn't be using it uh lesson number Point number two is that in fact we have uh we have Goods proactive refresh mechanisms for example in a private threshold signature scheme it's actually not that difficult to do a proactive refresh yeah there's a protocol it dates back to 1995. that shows how to do it let me give you a simple like a very simple uh example of this protocol let's suppose that we have two parties and we take our secret key and we break it up into a sum of two secret keys so SK is sk1 plus sk2 so this is what's called a two out of two sharing in that you need both shares in order to sign sk1 plus sk2 how do you refresh such as sharing well it's really quite simple I mean I wish I hadn't put on a slide so I could ask you to come up with it yourself but it's really quite simple what the parties will do is they would change they would choose some random number R and then one party would add R to sk1 that the other party would subtract R from sk2 and you notice the sum doesn't change so this is still a sharing of SK so the public key didn't change but now the shares are completely re-randomized that the shares are just we just added a random mask we added a mask to one and we subtracted a mask on the other so the shares are completely randomized but um but the public key didn't change so that's a very very simple mechanism that allows us to do a refresh for our private threshold signature and it turns out this also generalizes to five out of nine so if we have a 5 out of nine sharing um there's a there's a very cute observation maybe I I could ask you to think about this as a homework problem yeah it's actually quite easy to come up with a protocol that will refresh a five out of nine sharing maybe as a hint I'll tell you the idea is you choose a random polynomial whose constant term happens to be zero and you use that polynomial to refresh all the shares but let's leave it at that level I hope this is clear right that you can easily refresh a private threshold signature the question is what do we do about accountable threshold signatures and and in fact this is much harder yeah so can we refresh and accountable threshold signature in at first glance it seems like this is impossible you can't Refresh on accountable threshold signature because the private key is what's used for accountability right the way I know who signed the message is by basically tying them back to their private key so if we change the private key how are you going to do accountability but it turns out nevertheless it is possible and in fact this is this is some work that we did very recently it's harder to do but I put a link to the paper if you're interested in learning how this works but it's a very practical mechanism that allows you to do a refresh for accountable threshold signatures yeah so I uh again if you if that's what you need if you need thresholds secure threshold signatures for uh consensus uh it's important up until now it was kind of people thought oh maybe maybe accountability maybe refresh is not possible so we might as well use multisig but no actually refresh is possible if you use BLS or snore it's really quite practical and I think it's a technique that uh you know should be used by by more projects yeah please the vote like they put their reputation on the line such that you know who signed this transaction yeah exactly so that's exactly right yeah so they're accountable for their actions so if they if the for an accountable threshold signature if you sign if the Quorum of parties signs a message incorrectly like for example releasing funds from a bridge they will actually be accountable for their action we will know that those are the parties assign that message and then we can go slash them or penalize them you know in the case of ronin uh when the hack occurred you know it wasn't initially if they had used a private threshold signature we wouldn't have known which of the five out of the nine uh shares were compromised but because they used an accountable threshold signature it was very clear oh it's these five that were were hacked and in fact four of those as I said were held by a single party yeah so that's the beauty of an accountable threshold signature if something goes wrong you know exactly who misbehaved yeah who got hacked who did something incorrectly and then you can go and uh and penalize them in some way this by the way happens often in proof of stake consensus right there you often need accountable threshold signatures because if somebody signed a block incorrectly the accountability aspect allows you to see exactly who signed in correctly and then you can go and slash them a private threshold signature wouldn't work because you know the block would get signed an incorrect block would get signed and you would have no idea who did it yeah so private threshold signatures are used for protecting Keys accountable threshold signatures are used when they're needed for consensus there's a different threshold signature mechanisms and I hope I hope this talk kind of makes it clear to you that really when you use threshold signatures you have to think which version am I do I actually need yeah and this is a real separation between the two and the point of this is we can even do refresh for private threshold signatures we can do refresh for accountable threshold signatures we cannot do refresh for multi this is kind of an important point in the talk yeah interactive refresh cases are there ways to prevent previous rounds of refreshed keys from from leakage or a compromise there um right okay that's a good question so typically when you do so the question was you know enough you know when we do a refresh is there a way to prevent uh older version of the secret key from getting leaked so typically if the participants are honest what they would do is after the refresh they would destroy their old they would delete their old secret Keys yeah but you know maybe the participants got hacked or something right and they are um and they're not deleting the old secret Keys then uh if the attacker gets control over more than T shares in any round then there's a problem yeah so this basically uh would work as long as enough participants are honest to actually delete their shares after every refresh yeah which is kind of the normal operations but again the Assumption here is it it's very difficult it's difficult for the attacker to break into many parties at once so it's quite a reasonable thing to do yeah so it's a very good question yeah please just a question to understand the difference really clearly yeah because we need the accountability does it mean that we cannot we need to share some information about the keys right right so so um accountable threshold signatures necessarily reveal what the threshold is right because you can just look at the signature see who generated that signature and that reveals the threshold so you'll know so if you're an attacker you'll know oh I need to I need to uh break into five users five parties in order to recover the the secret key in a private threshold signature you don't know what the threshold is you can look at the signature you have no idea what the threshold is so you don't even know how many parties you have to break into yeah so that's like that's like why pts's are used for protecting keys and atss are used for consensus can we combine the two let's say if you want accountability oh my God of course oh that is such a wonderful question that is such a wonderful question so the question thank you so much for asking that so the question is I told you there's atss and pts's and you have to choose which one do you want so the wonderful question is is there a way to kind of get the best of both worlds can we have accountability and still have privacy so that sounds contradictory right I mean you know if if we have accountability we know who the parties are so how can we have privacy turns out there is a way to do it so there's another mechanism this is a paper that just appeared a year ago there's another mechanism it's called Uh private accountable threshold signatures Pats Pats uh and in a path what happens is um you have privacy from the public so the public would have no idea what the threshold is and no idea who generated a signature but there is a special secret accountability key so anybody who has the secret accountability key they can use their key to look at a signature and figure out exactly who generated that signature so we kind of uh you know we kind of have the Best of Both Worlds by having privacy from the public and accountability against an accountability Authority yeah and so the question of course who runs the authority and so on but you know that's that that can be arranged as well yeah so that was a wonderful wonderful question so if you're interested in that there's a there's this mechanism it's called paths I have to say it's right now the constructions for Pats are not the most efficient potentially we could build something more efficient uh but those are that's kind of uh you know directions for future research so if any of you are interested maybe you think from think about more more efficient patch systems for the future that was a wonderful question thank you for asking that great any more any more questions on this on the proactive refresh versus uh versus ats's great so in that case let's move on so I wanted to take a do a very quick Whirlwind tour in five minutes about an area that I think is really exciting and I hope it'll be exciting to you to you too so this is basically kind of more advanced cryptographic schemes that are not used in the blockchain space today but they could be used actually in the coming years and in and put to very good use in the in the ecosystem yeah so again hopefully in some of your projects these techniques will be will be useful so yes I call these Advanced cryptographic Primitives that could have applications in the coming years in the blockchain space so let's this is like a whirlwind tour of uh very very deep topics but I just want to give you a taste of what's coming so the first example of course is what's called confidential Computing so confidential Computing basically allows us to compute on data without knowing what the data is yeah it's kind of a remarkable thing how can you possibly compute on data if you don't know what the data is turns out crypto magic allows us to do that why is this relevant in the blockchain space well it comes up in the context of Mev yeah maximal extractable value Mev so here's the problem let me just make sure everybody's on the same page what is the what is the Mev problem Mev problem yeah the problem is you know imagine um imagine I'm a I'm a Searcher and I look around for various transactions that could make a profit for Me Maybe I find an Arbitrage opportunity you know something is being sold for of one value in one Marketplace and that's a different value and another Marketplace I can issue you know I can use I can issue an Arbitrage transaction and profit from the result you could one could argue that the Searcher is providing a service because if there's a gap in prices between different marketplaces the Searcher is equalizing those marketplaces and sure it's making a profit in the process but it's also providing a service that is equalizing uh these marketplaces terrific so how does a Searcher actually do this well not today but let's say a few years ago the Searcher will basically work hard to find these Arbitrage opportunities and then they would post the Arbitrage transactions onto the mempool to get to get posted what happens somebody tell me what happens once the Searcher posts these transactions into the mempool what happens exactly it gets sniped right so somebody looks and says oh thank you very much Searcher this is a really cool idea I'm just going to take your transaction and change it so that I'm the pro I'm the one who profits on the Arbitrage right and maybe I provide a higher um uh priority fee so that it'll Place get placed in the blockchain in the block earlier than uh than yours and now I basically stole your uh your Mev I stole your Arbitrage profits yeah so this is as you know this is a problem this actually if had if this had gone untreated this would have been a real problem because it causes price what's called price gas auctions in the mempool so it kind of degrades the blockchain experience for everybody because if you if I post a transaction and you try to snipe it I'm gonna try to snipe it back and you see we kind of have this kind of tit-for-tat battle in the in the mempool that's not what the mempool is for it's hurting everybody else's uh transactions on the main pool it causes high high gas gas prices and so on so good so this is exactly where flashbots comes from yeah so the the idea behind flashbots was to say well let's try to take all these you know Wars between Searchers The Searchers they're free to battle one another as much as they want but let's take all of that out of the main pool yeah so flashboss is kind of a way to do these auctions somewhere else so the mempool is used by people who are you know end users who don't have to suffer from this great so yeah so the ultimate solution however is so you know today basically we use MAV boost which is kind of what what it does kind of takes these price gas auctions out of the mempool but the ultimate solution that um uh we'd like to do is what's called uh flashbot flashbot Suave yeah so maybe you've heard of suave this is kind of the coming architecture I'll tell you the kind of the the rough idea of suave is to say that um somehow by Magic we want the Searchers who have transactions uh we want them to keep their transactions to themselves yeah so they don't have to tell the world what what the transactions are and nevertheless we want the builders the people who build blocks to be able to build blocks from the Searcher transactions yeah so somehow the transaction should be encrypted so the Searchers maybe when they post them they should be encrypted nobody can read what they are but the builders when they build blocks on these transactions they should be able to look at the contents of the transactions so they can package them in the ultimate way maybe from a gas point of view they need to be able to package them so that it optimizes some optimization function so that looks like again a contradiction if the transactions are encrypted how can you possibly right how can you possibly apply a building strategy to build efficient to build efficient blocks yeah so it's a contradiction and well this is exactly where cryptography shines whenever you have contradictory requirements remarkably cryptography can actually be used to solve the contradiction so the way Suave actually works what Suave is trying to do is sort of solve the following problem yeah we have Searchers on this on the on the what is it on the left right so Sam and Sue we have block builders on the right Bob and Brooke and so on and then we have the block proposer on the bottom that needs to sign the final the final uh block that gets gets constructed what we'd like to do is we'd like them all to provide their inputs so Sam and Sue will send their transactions their encrypted transactions Bob and Brooke will send various building strategies and the block proposal will contribute it's it's signing key because it needs to sign the block once it's created and then by Magic nobody will be able to read anybody's data right everybody's data will be kept hidden from everybody else by Magic somehow uh the block gets constructed correctly and gets signed that's the problem that Suave is trying to solve is that clear this this is a really difficult problem right somehow we need to be able to operate on these transactions on these encrypted transactions apply building strategies and then sign the block at the end without anybody looking at the block data how do we do that well that's exactly the magic of cryptography right so we do that using what's called confidential Computing the two methods I want to highlight is basically what's called MPC multi-party computation which allows us to do it and the other method is of course using Hardware enclaves so these are techniques that have not played a role yet in the blockchain space and now they're going to get pulled because of Mev they're going to get pulled into the blockchain space and play a very major role what's exciting to me about this is now all of a sudden the blockchain ecosystem is going to zoom in on these two techniques and just like zero knowledge improved dramatically as a result of blockchain attention these two areas are gonna we're gonna see massive improvements in these two areas because of blockchain attention so the fact that all of a sudden we're going to get efficient and practical Hardware enclaves this is a big deal right this has been an open problem now for a long time I think the blockchain attention is going to force the development of these enclaves and uh this is going to be a you know a major uh boost to the rest of society so this is a big deal so I just wanted you to know that this is coming if you're interested in kind of you know jumping in on this on this uh uh train that's going you know you can go learn more about multi-party computation learn more about Hardware enclaves but this is kind of a big technology development that's probably going to happen in the next two to three years uh because of the attention from the blockchain space I think it's really really interesting that this is this is happening so that's one technology I wanted to tell you about another technology I wanted to tell you about is something that enables private storage again this is something that's not used in the blockchain space yet but could very easily get used in the in the near future what is the idea of private storage so imagine we have a server that stores a bunch of data yep um there are and we want to read that data without revealing to the server what it is that we are reading okay so there are two techniques that I'll just tell you the names one is called private information retrieval the other is called oblivious Ram yeah these are two techniques that could help here and so private information retrieval makes it possible to read data from Storage without revealing to storage what I'm interested in yeah so I can read a cell and not the storage would have no idea what I just read an oblivious Ram allows me to run an entire program this is kind of a remarkable thing I can run an entire program and all the memory access patterns that that program makes to the storage is independent of the program that's running so I can run a secret program and the storage server will never know what program I'm actually running yeah so it's a way to access storage in a privacy preserving manner why is this useful in the blockchain space well there are these storage systems in a blockchain that we would like to maybe access privately in particular think of inferior Alchemy right today when we use when we access infer and Alchemy we basically are telling telling them exactly which contracts we're interested in you know exactly what data we're interested in it'd be nice if we could do it in a way that doesn't reveal to them what it is that we're doing and perhaps these techniques will be useful for that so again it's very interesting if the blockchain world focused on these privacy techniques they would see I know significant improvements in performance and that would benefit the rest of society as well the third example and then I'll stop yeah and then I wanna I wanna take I want to leave time for questions so then so then I'll stop the third example is a bit more theoretical but I do want you to know that this this is this exists and this is the idea of hiding secrets in code yeah if I have a secret key and I want to put it in in a program and give you the program I want to be able to do that in a way that you can look at the program and you will never be able to extract the secret key from that program yeah this is called code obfuscation yeah it goes but the technical name for this is virtual Black Box vbb uh code obfuscation the idea of an obfuscater is that it will actually take a program yeah it will take a program run it through this obfuscater and you'll get an a different program this new program is going to be identical to the old program yeah so it'll have the same input output Behavior as the old program but the magic is that this new program P Prime reveals nothing about how the program works Beyond its input output behavior all you will learn is a is the connection between the inputs to the program and the outputs to the program but you'll learn nothing about any secrets in the program that's what an obfuscater does it hides the inner workings of a program so that you can't actually see what it does in particular if there's a secret key embedded in the program you will never be able to extract that secret key from the program why is this useful well this is useful because now if we had an obfuscator we could actually publish solidity code and the solidity code would have secret Keys embedded in it such that the solidity code could sign messages and you will never be able to extract the signing key from the code so we can make sure that now the contract can sign messages only when certain conditions specified in the contract are specified are satisfied yeah and so this will be like do you agree this is like super duper cool you can kind of post programs to the chain they the chain itself will generate signatures and no one can can extract a secret key these signatures will only be generated when the code says that it's okay to generate those signatures so uh you know um Bridges become a lot simpler basically there's a whole bunch of applications that we become possible once obfuscation happens so this sounds great there's only one problem the one problem is that obfuscation right now is I would say uh you know it's polynomial time it's polynomial time so theoreticians would say great check mark but it's not practical yeah so just like zero knowledge you know 20 years ago zero knowledge was completely theoretical we would say it's not practical and lo and behold now it's super practical you know the hope is that uh with obfuscation today it's not practical the hope is that uh new ideas all it takes is one idea one idea by the way this is what happened with your knowledge one idea is what moved your knowledge from being impractical to being practical one idea 2013. yeah it's pretty interesting all it takes is one idea and we could end up with practical obfuscation and all of a sudden you will benefit you will benefit from secrets in your code so yeah please yeah so it's a good question so today basically the the problem is that the program P Prime the obfuscater program is too slow to run yeah the officecater the only secure obfuscators we have they even if they take very simple programs the output ridiculously large programs the programs will take hours perhaps even years to run yeah so not not practical what we want is an obfuscater will take a program p and produce a program an obfuscate a program P Prime whose running time is about the same as the running time of program p yeah that's what we'd like to have yeah if you have a moment what was the idea ah okay um well so there's a classic paper it's called the ggpr paper that what it did is basically it reduced the approver's running time from quadratic in the length of the computation to linear or quasi linear and the length of the computation so the move from quadratic to quasi-linear made it possible to do proofs for for Gigantic statements which is what actually we're seeing today we're going to talk about zero knowledge in week three so you're going to hear all about this the history of zero knowledge and how it was developed you're going to hear all about this in week three but yeah there was this one critical idea that reduced things from quadratic to linear and that actually enabled a whole bunch of applications here unfortunately with obfuscation we're not even at quadratic at this moment uh I think we're at like a quartic or it's like the algorithms are are quite inefficient the polynomial time they're quite inefficient and we have to go to linear for that to be for that to be practical but we could be one idea away so this is a challenge for all of you if you're interested as you can see there's like really cool problems to think about here yeah please foreign because that's a very important point so a16z has this wonderful wonderful zero knowledge Cannon I highly highly recommend looking at that it's a it contains a list of all kind of the key developments into your knowledge along with survey articles and books and so on so very very well done zero knowledge Canon please take a look you can see exactly how zero knowledge works and the history of how it was developed perfect so uh that's actually all I wanted to say so let me just summarize by saying that um this is an amazing time to be a cryptographer you know this is like this area is so much fun now I can't remember I've been doing this a long time I can't remember another period where I've had so much fun doing cryptography yeah it's like the the the the systems that we're building you know they can be deployed they affect Real World um real world blockchain applications there are applications outside of the blockchains it's just so much fun to be a cryptographer these days so um you know I'm really happy to see all of you here and I'm really excited to see all the projects that you're going to build but we're not done there's a lot more as I just showed you there's a lot more coming there's a lot more technologies that need to be reduced to practice and transitioned into the blockchain space and so I think the next decade is probably going to be as exciting as the decade that we just that we've just experienced so thank you very much and I'm happy to take any questions yeah please oh oh yeah yeah there's a mic hi uh thank you thank you so much for this uh for the talk your uh Your Enthusiasm is infectious for uh happy to hear it uh this is more of a philosophical question but I was curious for cryptography is it building towards the convergent brand unified vision of some end state of like the ultimate version of privacy and security or do you find it's more Divergent where it's like it's it's this incremental move movement towards different goals oh um no I think there are like multiple goals there's not there's not a single Target that we're going for I think different applications in the ecosystem require different tools you know in some cases you can't use something without unless it's private in other cases you can't use it unless it's transparent right so um I think there are actually different goals that uh that need to be you know satisfied as a result different Technologies are applicable to different applications so that's great right it's not there's not going to be a single solution that solves everything in the world you know we're going to have to build lots and lots of different tools thank you yeah for sure uh hi professor Bonnie I'm just saying I went to U of Waterloo for math um and learned RS encryption and like really big uh prime numbers a long time ago um but um so I uh I'm curious so I read about homomorphic encryption and that intuitively makes sense to me so I work with game studios and our use case would be like uh let's say like you're a big red Studio you have an Abbey course a million players and they're on the blockchain but you want to keep those users private to stop like Big Blue Studio from coming and airdropping and building a similar game and stealing them um so I think I I don't know enough about homorific encryption I just don't know like uh what's stopping us from implementing that today and what are some projects I should like follow in that space Oh yeah Nothing is Stopping Us so homophone encryption is a fantastic development uh in in crypto as well it's closely related to the confidential Computing that I mentioned earlier in fact you could say there are three techniques for confidential Computing multi-party computation Hardware enclaves and fully homorphic encryption all of those allow you to compute on data without actually seeing the data in the clear yeah so fully automatic encryption actually is quite is becoming quite practical if you want to follow the developments there's a startup it's called Zama z-a-m-a you should look yeah you should look at their tools it's really quite beautiful to see what they're doing so they're focusing right now on using fully homomorphic encryption for machine learning so you know you have like uh an encrypted data set that you want to run a model on they will actually run the model on your encrypted data set they will obtain encrypted class results and encrypted classification results send them back to you you can decrypt and get the results without them knowing ever without them ever knowing what your data was yeah so it's really quite amazing to see that actually getting used and so yeah I think Zama would probably right now as I said they're focused on machine learning but it would be equally applicable in the blockchain space in fact for the Mev application if fhe was sufficiently efficient it would be a terrific application for um for uh for Suave as I mentioned it's just a Suave problem the Suave computation is just so complex that it's probably beyond what fhc can do today but maybe in the future it will do that and there will be a perfect fit yeah for sure that's that's super cool thanks um and I think like machine learning it's kind of like you need a large centralized entity to collect all this data so it's like a Enterprise customer right whereas we interface with game studios directly and they could have like a million consumers and that's more of a faster consumer use case that's like on chain but yeah thank you thank you for that yeah makes sense thanks great question hi Emmanuel from Shield security I'm curious what kind of product and user experience manifestations do you see coming from that increased blockchain attention on things like NPC um as well as like proactive uh proactive refresh yes I would say like the MPC application that I mentioned multi-party computation that that is primarily a privacy mechanism so if you want to keep your data private like the Searcher who wants to keep their transaction private but they have to give it to somebody else they have to give it to somebody else so they can make a block out of it that's exactly that contradiction you know I want to keep the data private and yet I have to give it to someone so they can compute on it that contradiction is exactly what MPC Hardware enclaves and fhe comes to solve comes to solve so if you're in an environment where you are facing that contradiction I would say come talk to us yeah uh but in general that's exactly where these techniques would would apply yeah does that does that make sense does that answer the question yes it does yeah perfect perfect yeah yeah it's really cool that there are all these like very often there are these contradictions in the world where they seem like impossible to resolve but cryptography resolves them yeah because uh there's I'll give you just one more example of that there's very often situations where you want to compute and you want to compute like an analysis of a large amount of data but this data is very private and it belongs to your customers yeah typical example is um you know um you wanna you wanna know how people your browser manufacturer and you want to know how people use your how you people use your browser how people use your browser is a very private thing nobody's going to tell you how to use their brow your browser and yet you want to compute aggregate Statistics over how people use your browser it seems like a contradiction they won't tell you and yet you need to compute argument statistics it sounds like you can't do it but in fact you can there's these are contradictions that can be resolved using cryptography quite efficiently so again keep that in mind if you have a large user population that wants to keep their data private but somehow you want to learn aggregate information about what they're doing uh with their data sort of aggregate information about their data we can do that cryptographically actually quite efficiently here there's a system called prio prio that does this quite efficiently so it's another example of a contradiction that can be resolved using crypto thank you for your answer on fhe actually Zama have some test nets for private computation for others to look at yep I have a question on the implementation on like the limits of how large we can have uh quorum to be in pts so um can we have like really large large courses yeah without that overhead yeah like millions of users for example yeah yeah in fact uh in ethereum post merge they are using an accountable threshold signature effectively it's called a multi-signature there that has a quorum of 500 well the number of users of like currently 500 000 right there's a number of the number of the amount of validators grows they're going to have more and more and more um entity you know users basically signing transactions in that system so yeah you can have very very large user populations and very very large quorums and both pts and for both pts and ATS yeah these systems scale quite well yeah it's very very interesting yeah thanks it's a great question hi there great talk um Isaiah from Shield security ah yeah we also believe greater commitment to user security is definitely going to be what stimulates greater adoptions and what's how SSL did it in web 2. yep um the question that I have though is related to how do you see cryptography um combining with Quantum the quantum platforms that are in development and also AI um do you have like a broader long-term perspective of how those like come together to create something um great or is there anything in the short term that you've seen that has been really interesting uh oh boy that's a good question um let's start with the quantum World um so you're asking maybe I can interpret your question as what is the impact of quantum Computing on the blockchain right yeah I'm actually it's interesting that uh this question comes up uh quite a lot yeah so it's true that uh you know a quantum computer would have an impact on the current Primitives that are used in the blockchain but we know exactly what to do yeah in fact there are uh for every primitive that we use there's a Quantum secure primitive yeah so what's called a post Quantum affirmative that's secure even if the adversary has a quantum computer so the risk is actually not that great in the sense that as they come closer to fruition we will just transition to these uh post Quantum systems the one the one caveat of that is privacy if you're trying to protect privacy then today maybe you want to be protected even in 50 or 100 years when these quantum computers appear then um to protect privacy you might want to you might think about using a post Quantum system today so even if in 50 years somebody has a quantum computer they can't go back and unmask everybody's privacy yeah that's the one the one difference but again primarily in blockchains the application is integrity data Integrity not so much privacy and so um that's the sort of thing that as these computers become closer to reality we can just switch to Integrity mechanisms that are post Quantum secure yeah I hope that makes sense yeah awesome and then um yeah so maybe we'll leave it we'll leave it up and by the way I'm gonna stick around so I'm happy to these are these are long conversations I'm happy to kind of have these conversations also after the talk hi Prof thank you very much for the talk uh I have a question actually about the third application that you ended up uh obstacator yeah one so I just want to make sure if I understand it correctly so the purpose of that is to protect a contract from um everyone to see such that hackers and uh uh not quite not quite so so on the Chain everybody can read the code of the contract right the contract gets posted on chain in the clear everybody can read the code yeah what we want to do is we want to write the code in such a way that even if you can look at the code you can run it yourself you can do all sorts of things that you have the code even if you can look at the code you still can't extract the secret key from the code the only way to generate a signature is if the code says that it's okay to generate the signature that's the goal oh okay okay so what's the like applications that you see yeah so for example imagine uh you're building a bridge to bitcoin yeah if you want to build a bridge to bitcoin then um uh somehow you need to sign a message saying telling the Bitcoin side of the bridge it's okay to release funds yeah and so the way you would do that the way only way we know how to do that uh and again by the way this is because Bitcoin is too weak to verify as your knowledge proofs the way one way the way we do that today is basically we have off-chain parties that sign that jointly use a threshold mechanism to jointly sign a message saying telling Bitcoin yes it's okay to release the funds we could get rid of those parties if we had a contract on the ethereum chain that says yes it's okay to release yes here's a signed Bitcoin transaction that says it's okay to release the funds to do that we have to have a signing key on the ethereum Chain but if we put a signing key on the ethereum Chain everybody can just steal it and just issue signatures on their own so we have to be able to hide the signature key inside of a contract inside of solidity code so that you can't just steal the key you can only generate a signature if it's a valid if the conditions are satisfied for that signature to be generated oh okay I see okay got it yeah by the way this is specifically for bridging to bitcoin if if you're bridging between blockchains that can verify zero knowledge proofs there are easier ways to do there are easier ways to build bridges that don't require a set of authorities yeah and maybe yeah so I'll leave it at that thank you yeah yeah for sure hi Kristoff from Pimlico here how comfortable are you in betting the future of block building on Intel's sgx I see that's a that's a very good question wow um okay so I am not comfortable at all let's just say uh the reason I say that is because um first of all some blockchains who relied on sgx have already gotten bitten by the sgx vulnerabilities I can tell you that in many security conferences now there are entire sessions devoted to sgx bugs yeah so um I think it's a wonderful idea uh the the what Intel tried to do is a wonderful idea but it's a very difficult problem to solve so um I I would say that you know if we're going to rely on um Hardware enclaves for security of a blockchain or for security of an Mev system for example I would probably um think about using using a dedicated Hardware enclaves for that yeah so by the way you notice I use the word Hardware enclaves not sgx yeah sgx is just an example of a hardware Enclave but there could be many others and in fact one of the things that I'm excited about is the fact that the blockchain space is now generating interest in Hardware enclaves actually suggests that there's opportunity for startups to go and build more secure Hardware enclaves yeah this is an opportunity for all of you right we should we don't need to rely on sgx on Intel's sgx we can build like separate co-processors that would sit you know as a card on a device or maybe a separate machine that all it functions as a hardware Enclave yeah why don't we just build one that's custom made for that task and it is much harder to break so is that how you think flashbots should move forward after mov boost is using Hardware enclaves uh okay you know that's a that's a long conversation why don't we why don't we take that let's do that conversation thanks yeah great question Lucas from Target here earlier in the presentation in the QA you talked about Quantum resistant blockchain so I was wondering if you could go more in depth out of curiosity into Quantum attacks um well I'll talk maybe I'll talk about Quantum defenses yeah so there are post-quantum digital signature systems in fact uh I hope many of you know that the National Institute of Standards uh ran a competition oh that ran a a process to choose a post-quantum crypto systems yeah and they have in fact standardized on or there are standardizing on a number of post-quantum systems both for key exchange and for signatures um and so if you need to use post Quantum signatures now there are ones there are concrete proposals that are available on the nist post Quantum website one thing I would say is for signatures for example um uh software updates the software update mechanism the way we update everybody's software that's a process that's heavily dependent on signatures yeah uh and that's a process also where the length of the signature doesn't matter so much because I'm sending you megabytes of a software update it doesn't matter if I add a few tens of kilobytes for a post Quantum signature I would say that that's kind of a target for the first application of post Quantum signatures just for software update mechanisms yeah so keep that in mind also if you're building a software update mechanism for your wallet or for whatever it is that you're Distributing to end users that's a place where you should use what are called hash based signatures that are like very trusted to be soft to be post Quantum resistant um and like I said one of those is already available as part of the nist process um yeah so we know how to do it for key exchange we know how to do it for for digital signatures um and so uh we're literally just waiting it's going to take another year or two for the nist standards to come out uh yeah and then The Primitives will be ready for everyone to use so so that's where we are ready yeah excellent hey professor thanks for the fascinating talk Brandon yeah so it seems like in the proactive refresh uh scheme you're taking advantage of the property of time which is that there is some uh minimum amount of time T that an attacker would need to to exactly right is there any encryption uh research or scheme I've always been curious about this that takes advantage of that property within the encryption of the data itself for example can you encrypt data using a scheme s such that even if you had the key it's only valid for some time t oh only valid I mean the opposite is possible we can make it so that I can encrypt data to you so that you will not be able to decrypt it until time T has passed right so that that we can do that's called right that's called the basically time lock encryption where I can encrypt I can encrypt to the Future you have to spend time T before you can decrypt can you do the inverse where it's only so the Universe I think is uh where it's only decryptable for t for time t uh the inverse is uh not possible by cryptography alone but it would be possible for example using Hardware enclaves you can imagine the key would live in a hardware enclave and after a week the hardware Enclave will just erase the key and now you can no longer decrypt right um or or via sharing where enough parties would erase the key you know then you can no longer decrypt but cryptography by itself can't do what you said there needs to be some auxiliary mechanism that makes it possible got it okay thank you yeah great great question wow this is a fantastic set of questions thank you so much for all the questions and as I said I'm really really excited about everything you're building and I'm really looking forward to seeing to seeing your projects in the future so thank you all very much [Applause] foreign
Up Next

Hybrid Key Establishment in Production: Post-Quantum Cryptography
@durumcrustulum
14.7K views•2025-08-27

Threshold ECDSA and MPC for Cryptocurrency Custody | Yehuda Lindell
@unboundsecurity4074
3.7K views•2019-01-13

Operational Security Essentials: A Guide for Hacktivists (OPSEC)
@hitbsecconf
157.4K views•2012-11-26

Understanding Ethereum: A Comprehensive Beginner's Overview
@99Bitcoins
3.1M views•2018-06-26
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Blockchain & Crypto






































