PQLN:比特币闪电网络链下表面的后量子安全
PQLN: Post-Quantum Security for the Bitcoin Lightning Network's Off-Chain Surfaces
- East Texas A&M University(东德克萨斯农工大学)
- North American University(北美大学)
- Florida Gulf Coast University(佛罗里达海湾海岸大学)
- Florida Institute of Technology(佛罗里达理工学院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对量子计算机对闪电网络链下密码学的威胁,提出混合后量子扩展 PQLN,利用 ML-DSA 和 ML-KEM 保护各表面,实现互操作且开销低。
AI中文摘要:
一台具有密码学相关性的量子计算机将破解比特币及其闪电网络(最广泛使用的支付通道网络)背后的椭圆曲线密码学。即使比特币进行后量子共识升级,也无法覆盖闪电网络的链下表面,因此其 gossip 协议、节点间传输、发票、支付洋葱路由和报价需要单独保护。攻击者如今即可记录闪电网络的加密流量,并在此类计算机问世后对其进行解密。因此,闪电网络可以立即转向后量子密码学,无需等待比特币,从而阻止此类“先收集、后解密”攻击,以及节点冒充、发票伪造和支付去匿名化。在本文中,我们提出 PQLN,一种闪电网络的混合后量子扩展,利用基于格的标准化算法 ML-DSA 和 ML-KEM 保护所有这些表面。PQLN 通过闪电网络的 gossip 分发后量子节点身份,混合传输握手,为发票添加后量子签名,在报价中提交后量子密钥,并使支付洋葱路由混合化。由于后量子材料远大于椭圆曲线对应物,我们引入了将其适配到闪电网络现有消息格式和大小限制中的技术。我们分析了 PQLN 在量子对手下的安全性,并在闪电网络的主要实现 rust-lightning 中实现了它。我们使用真实闪电节点进行的评估表明,PQLN 节点可与未修改的节点互操作。新增的密码学操作最多耗时 0.33 毫秒,主要成本在于通信,因为 gossip 数据在 ML-DSA 下增长约十倍,在使用较小的 Falcon 时增长约四倍。据我们所知,PQLN 是首个针对闪电网络的后量子设计、实现和评估。
英文摘要:
A cryptographically relevant quantum computer will break the elliptic-curve cryptography behind Bitcoin and its Lightning Network, the most widely used payment channel network. Even a post-quantum consensus upgrade of Bitcoin would not cover Lightning's off-chain surfaces, so its gossip, peer transport, invoices, payment onions, and offers need separate protection. An adversary can already record Lightning's encrypted traffic today and decrypt it once such a computer exists. Lightning can therefore move to post-quantum cryptography now, without waiting for Bitcoin, and stop such harvest-now-decrypt-later attacks along with node impersonation, invoice forgery, and payment deanonymization. In this paper, we propose PQLN, a hybrid post-quantum extension of Lightning that protects all of these surfaces with the lattice-based standards ML-DSA and ML-KEM. PQLN distributes post-quantum node identities through Lightning's gossip, hybridizes the transport handshake, adds post-quantum signatures to invoices, commits post-quantum keys in offers, and makes payment onions hybrid. Since post-quantum material is much larger than its elliptic-curve counterpart, we introduce techniques that fit it into Lightning's existing message formats and size limits. We analyze the security of PQLN against a quantum adversary and implement it in rust-lightning, a major Lightning implementation. Our evaluation with real Lightning nodes shows that PQLN nodes interoperate with unmodified nodes. The added cryptographic operations take at most 0.33 milliseconds, and the main cost is communication, since gossip data grows about tenfold with ML-DSA and about fourfold with the smaller Falcon. To our knowledge, PQLN is the first post-quantum design, implementation, and evaluation for Lightning.