PQ Transaction Signatures #014
Transcript
- Antonio Sanso
TG channel https://t.me/+ozVdiAeQleBhZDg0
- soispoke
it's SFI'd now :)
- soispoke
so "scheduled", not "considered" (CFI'd)
- Justin Florentine (Besu)
proof of work is back baby
- T. Wambsgans
I would say the main drawback is keygen. Caching the intermediate nodes in the Merkle tree can drastically reduce signing
- Simon Masson
the main cost in a ledger implementation is in the key generation. what is the benchmark in this case?
- Manuel Arto
is SPHINC (minus) non-FIPS compliant? Could this be a problem for instituion smart wallet migration to PQ?
- ooooooo [OKX]
Secp256k1 was nvr fips compliant either
- Matteo Vena | Riva Labs
What’s the signature budget?
- Nico
So actually yes k1 was never fips
- Nico
But I do have a FIPS compliant variant in the spgincs minus repo. It requires a big signer tho, like an HSM
- Matteo Vena | Riva Labs
thanks
- Nico
But FIPS compliance means you are using a FIPS compliant signer and no hardware is FIPS you need industrial grade HSM
- Post Quantum FBI
This is not how it works. Ledger rederives key material at each power up from the seed. This mean that switching profiles would require this amount of time.
- Nico
So chasing FIPS compliance is much harder than expected and probably not something for regular consumers
- ooooooo [OKX]
There is Hax for Rust iirc
- Simon Masson
Agreed with Post Quantum FBI, that's why I was asking the keygen benchmark because its 'kind of included' in the signing time in practice.
- Simon Masson
So this number should be included in the signing time (in practice), if keygen is done at every signing step.
- Nico
Amazing thanks a loot
- Post Quantum FBI
Nice (test boards) !
- T. Wambsgans
you can cache (1 KiB) is enough the Merkle intermediate nodes. Cache is not secret
- Justin Florentine (Besu)
so it stores the seed and re-derives on demand?
- Simon Masson
yes Justin
- Justin Florentine (Besu)
Reacted to "yes Justin" with 🙏
- Post Quantum FBI
how do you manage your 10 profiles in Rabby ? All precomputed ?
- Nico
You can indeed use the persistent ram to store the merkle in cache
- Nico
Fable for the win
- Simon Masson
Reacted to "Fable for the win" with 😂
- Post Quantum FBI
This is AMAZING.
- Simon Masson
22 cents
- Simon Masson
Do you have gas cost for a full verification including the expansion of the key?
- Simon Masson
yes, agreed on this :-)
- Stefano
Thank you everyone! See you in w2
Call summary
Targets
- •PQ1 hardware wallet consumer release — Q4 2026 - 00:31:44
- •PQ1 near-final hardware devices ready — ~September 15, 2026 - 00:37:11
- •Optimized MLDSA-44 EVM contract published — September 2–3, 2026 - 00:41:31
Decisions
- •No cryptographic precompiles (MLDSA, Falcon, etc.) to be shipped; EVM optimization results validate this direction - 00:10:49
- •Native account abstraction (frame transactions replacing EOA) is SFI for Hegota - 00:09:44
Highlights
- Mldsa Evm Optimization:
- ·Fireblocks (Oren): MLDSA-44 EVM verification reduced from ~8M gas to 1.2M gas (6× improvement); FIPS-compliant, open source, research quality - 00:39:18
- ·Key registration (one-time expanded key stored on-chain, ~20KB) costs ~4M gas; full cold verification ~9M gas unoptimized - 00:39:56
- ·Main savings: eliminating quadratic memory expansion (~2M gas saved), 256-bit batched lane operations, Yul/assembly rewrites; ~10% further reduction possible - 00:43:14
- ·At current gas prices, 1.2M gas verification costs ~$0.22; contract to be published same day or next - 00:46:10
- ·Result supports community position against MLDSA precompile for Hegota; pure EVM sufficient at this gas cost - 00:47:22
- Pq1 Hardware Wallet Demo:
- ·Freedom Factory PQ1 wallet: STM32U585 (Cortex-M33) + NXPSE050 secure element; XOR key split via TrustZone; SLH-DSA Minus C10 - 00:21:49
- ·On-chip signing: ~1.1s; cold boot (with key derivation): ~3s; SHA-256 hardware accelerator on STM32 aids performance - 00:24:43
- ·First EVT hardware received; all code open source (WIP); STM32U585 eval board ~$100 total to run today - 00:25:36
- ·Targeting Q4 2026 consumer device availability; uses account abstraction (modified base smart account), not native ECDSA replacement - 00:31:44
- ·Verification contract in Trail of Bits audit; exploring Lean/eCrypt formal verification via Rust-to-Lean toolchain - 00:32:24
- Slh Dsa Parameter Overview:
- ·SLH-DSA chosen as PQ replacement for ECDSA; no cryptographic precompiles will be shipped; aligns with hash-based consensus/DA layer direction - 00:09:23
- ·Moving away from Poseidon toward Blake/SHA via new 'Flock' system on Banner Fields; specific hash function TBD - 00:12:11
- ·NIST April 2026 SLH-DSA variant cuts signature from ~8KB to ~4KB but requires 1.45B hashes to sign — impractical for hardware wallets - 00:14:34
- ·SLH-DSA Minus C12 targets 2^14 signature budget (covers 99.99% of mainnet addresses); signing cost 37K hashes vs. 1.45B; still 47.5s on Ledger Nano S - 00:16:14
- ·Riva Labs achieved 1.5s signing on Ledger Nano S Plus (2^24 budget) via offline precomputation of public values + grinding; paper forthcoming - 00:18:03
Action Items
- •Oren (Fireblocks) - Publish optimized MLDSA-44 EVM verification contract to announced repository - 00:41:31
- •Nicola Ceornea (Freedom Factory) - Share Lean/eCrypt formal verification progress for SLH-DSA firmware with community - 00:34:33
Key decisions
No cryptographic precompiles (MLDSA, Falcon, etc.) to be shipped; EVM optimization results validate this direction
EVM optimization results validate that pure EVM implementations are sufficient, making precompiles unnecessary.Native account abstraction (frame transactions replacing EOA) is SFI for Hegota
IncludedFrame transactions replacing EOA are selected for inclusion in the Hegota upgrade.
AI Disclaimer: Some content or metadata on EIPsInsight may be AI-inferred or automatically compiled. If you find any discrepancy, please contact us at dev@avarch.org.