Crypto industry may be running out of time to prepare for quantum attacks Google’s latest research suggests the cryptocurrency industry may have less time than expected to prepare for quantum computing. In a whitepaper, Google examines risks to elliptic curve cryptography, the system securing most blockchain networks. The researchers revisit earlier assumptions about how difficult it would be for a quantum computer to break these protections, concluding that the required resources may be lower than previously estimated. “To share this research responsibly, we engaged with the U.S. government and developed a new method to describe these vulnerabilities via a zero-knowledge proof, so they can be verified without providing a roadmap for bad actors. We urge other research teams to do the same to keep people safe,” researchers said. At the core of the analysis is Shor’s algorithm, which can solve the mathematical problems underlying digital signatures. The team estimates that breaking the elliptic curve discrete logarithm problem for widely used parameters could require roughly 1200 to 1450 logical qubits and tens of millions of quantum gate operations. These figures represent an improvement over earlier estimates and point to steady progress in quantum algorithm design. A key takeaway is how quickly such an attack could happen. The researchers estimate a quantum system could derive a private key in under half an hour, and in some scenarios as little as nine minutes. That falls within the time it takes for a blockchain transaction to be confirmed. That matters because blockchain transactions are not instantaneous. During the interval between broadcast and confirmation, an attacker could extract a public key, compute the corresponding private key, and submit a competing transaction, known as an “on-spend” attack. Two other categories of quantum attacks are also outlined. “At-rest” attacks target public keys exposed over long periods, such
Crypto industry may be running out of time to prepare for <b>quantum</b> attacks
Read the original article
helpnetsecurity.com →