arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Obscura-PQ:基于格的可链接环签名的Algorand区块链后量子隐私保护协议

Obscura-PQ: Post-Quantum Privacy-Preserving Protocol for the Algorand Blockchain Using Lattice-Based Linkable Ring Signatures

Navid Azimi

arXiv 2608.22645首次发表:更新:

AI 中文总结

针对公共区块链隐私协议易受量子攻击的问题,提出可在Algorand链上原生验证的后量子隐私协议Obscura-PQ,基于格可链接环签名实现,完成测试网验证。

AI 中文摘要

公共区块链会公开完整的交易图,用于模糊交易图的隐私协议几乎完全依赖椭圆曲线密码学,其离散对数基础会被Shor算法破解。由于账本不可变,当前在经典假设下发布的每个匿名集都可能被未来的量子攻击者追溯去匿名化。转向后量子替代方案仍具挑战性,因为严格的智能合约资源限制禁止在链上原生验证计算密集型的后量子证明。为应对这些挑战,我们提出Obscura-PQ,一种可在Algorand区块链上原生验证的去中心化、非托管后量子隐私协议。其核心是基于分圆环$\u211d_q = \u2124_q[X]/(X^{512}+1)$的无设置格可链接环签名。存款是对短秘密的Ring-SIS绑定承诺;取款通过AOS/Borromean风格挑战链证明环开启的知识,该挑战链涉及两个响应共享线性关系,带有拒绝采样的短响应,同时发布确定性Ring-LWE序列号用于双重支出检测。我们将双重支出可靠性和可链接性归约到Ring-SIS,盗窃抗性归约到诚实生成存款的Ring-SIS,匿名性归约到Ring-LWE和经典随机预言模型中的显式决策链接假设。为克服严格的链上操作码和存储限制,Obscura-PQ完全在NTT域中评估验证关系。我们将前向NTT拆分到操作码池执行阶段,并通过可退款的盒式存储流式传输超大证明,实现O(1)的成员和双重支出检查。我们提供完整的Algorand测试网实现,证明在严格智能合约限制下后量子隐私协议的链上原生验证。

英文摘要

Public blockchains expose the complete transaction graph, and the privacy protocols deployed to obscure it rely almost exclusively on elliptic-curve cryptography, whose discrete-logarithm foundations fall to Shor's algorithm. Because ledgers are immutable, every anonymity set published today under classical assumptions can be retroactively deanonymized by a future quantum adversary. Transitioning to post-quantum alternatives remains challenging, as strict smart-contract resource limits prohibit native on-chain verification of computationally intensive post-quantum proofs. To address these challenges, we present \emph{Obscura-PQ}, a decentralized, non-custodial post-quantum privacy protocol that verifies natively on the Algorand blockchain. Its core is a setup-free lattice linkable ring signature over the cyclotomic ring $\mathcal{R}_q = \mathbb{Z}_q[X]/(X^{512}+1)$. A deposit is a Ring-SIS binding commitment to a short secret; a withdrawal proves knowledge of a ring opening via an AOS/Borromean-style challenge chain over two response-sharing linear relations with rejection-sampled short responses, while publishing a deterministic Ring-LWE serial number for double-spend detection. We reduce double-spend soundness and linkability to Ring-SIS, theft resistance to Ring-SIS for honestly generated deposits, and anonymity to Ring-LWE and an explicit decisional linking assumption in the classical random-oracle model. To overcome strict on-chain opcode and storage limits, Obscura-PQ evaluates verification relations entirely in the NTT domain. We split forward NTTs across opcode-pooled execution phases and stream oversized proofs through refundable box storage, enabling $O(1)$ membership and double-spend checks. We provide a complete Algorand testnet implementation, demonstrating native on-chain verification of a post-quantum privacy protocol under strict smart-contract limits.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑