PQ Transaction Signatures #015
Transcript
- Matteo Vena | Riva Labs
Was there any major difference between the Flex and baseline devices?
- Matteo Vena | Riva Labs
I mean In terms of performances
- Matteo Vena | Riva Labs
Nano S Plus
- Gustavo Frederico
What do you mean by Secure OS? Is it that the private key and your algorithm must live and run within some form of hardware wallet enclave?
- Matteo Vena | Riva Labs
Giulio is still working on this
- Gustavo Frederico
Can you please zoom in some more
- Gustavo Frederico
on the Ledger display?
- Matteo Vena | Riva Labs
You can zoom via Zoom
- LatticeLover
Reacted to "You can zoom via Z..." with 😂
- LatticeLover
Is this computing the keygen when signing?
- Matteo Vena | Riva Labs
This goes through a pre-compute phase that will be explained on the upcoming paper as Antonio explained
- LatticeLover
Reacted to "This goes through ..." with 👍
- Gustavo Frederico
Is there any article that describes the signing component (the rectangles to the left of NiceTry)?
- Antonio Sanso
Print paper upcoming in few weeks
- Gustavo Frederico
Are there plans for the MPC portion?
- Matteo Vena | Riva Labs
We developed a fully working MPC that uses the same basis
- Gustavo Frederico
is it involving 2 devices?
- Matteo Vena | Riva Labs
Any number of devices
- Stefano Gogioso
How long is the keygen at 2^20?
- LatticeLover
how long is the keygen (stenfano frontran me :-D)
- Gustavo Frederico
I thought a thresholdized version of SPHINCS+ didn’t exist. Are the MPC devices talking to each other as parties? Is there a paper that describes the MPC version of SPHINCS+?
Call summary
Targets
- •STARK signature aggregation experiments on daisugi.fyi testnet — next few weeks - 00:37:47
- •SPHINCS+ formalization paper — within next few weeks (before or at next PQTS breakout) - 00:52:36
Decisions
- •daisugi.fyi:3000 adopted as the permanent PQTS testnet going forward; next experiment: STARK-based signature aggregation - 00:37:47
Highlights
- Pqts Testnet Demo:
- ·New persistent testnet at daisugi.fyi:3000 launched; non-native account abstraction with SPHINCS+ verification via zkSNARK verifier - 00:37:21
- ·Software wallet SPHINCS+ signing: ~60 ms; Ledger Flex: ~10–12 s; Trezor Safe 3: faster than Ledger due to higher I/O bandwidth - 00:39:54
- ·Signing time increase (1.5 s → 10 s vs. prior demo) due to added Groth16 proof of canonical hypertree grinding; formalization paper upcoming - 00:45:08
- ·Stock SPHINCS+ verifier used on-chain; only signing side changes — software, hardware-constrained, and MPC paths all share the same verifier - 00:52:50
- ·MPC implementation complete (Linux servers, any number of parties, zero interactive signing rounds); no public paper yet - 00:54:15
- Zkproof Of Seed Update:
- ·zkBoo runs fully on Ledger Flex in user app space; all 6 HD-wallet statements proved and verified on-device - 00:05:41
- ·Hardened child key statement: ~22 MB proof, ~3 hours to stream out at 128-bit post-quantum soundness (438 responses) - 00:12:58
- ·Elliptic curve (secp256k1) statements optimized 350x since April; per-response size down 300x to 3 MB; full proof ~1 GB, ~1 week on-device - 00:13:24
- ·SP1 lifter: 280K gas for on-chain verification, 356-byte proof, ~now proving time; not post-quantum but proves full-stack feasibility - 00:13:39
- ·FLOC lifter: 12-second proving, 1.2 MB proof, best performance — on-chain verification gas cost not yet measured; priority for next steps - 00:26:46
Action Items
- •Giulio Rebuffo - Giulio to add gas cost breakdown and trace log to daisugi.fyi testnet explorer - 00:41:00
- •Riva Labs / Antonio Sanso - Riva Labs / Antonio Sanso to publish paper formalizing SPHINCS+ signing scheme security and pre-compute design - 00:52:28
Key decisions
daisugi.fyi:3000 adopted as the permanent PQTS testnet going forward; next experiment: STARK-based signature aggregation
Establishment of a permanent testnet for PQTS development and planning for future signature aggregation experiments.
AI Disclaimer: Some content or metadata on EIPsInsight may be AI-inferred or automatically compiled. If you find any discrepancy, please contact us at dev@avarch.org.