EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coinbase计划为任何方案提供后量子比特币托管服务

2026-09-24 06:22:59
Bookmark

Coinbase 启动后量子托管系统设计,旨在保护约 2500 亿美元机构资产

Coinbase 正在为多种可能的后量子签名方案准备托管基础设施。哈希签名可能与许多加密货币托管商使用的多方计算(MPC)系统不兼容。可编程硬件安全模块可能为 Coinbase 提供一种替代的密钥保护方法。目前,比特币开发者尚未选择或激活任何后量子签名标准。

Coinbase 为多种签名方案做准备

MARA Foundation TV 主持了 Coinbase 首席密码学家 Yehuda Lindell 的访谈。他表示,Coinbase 希望其托管平台无论最终由区块链社区选择哪种后量子签名方案,都能保持可用性。比特币尚未确定用于实际后量子环境的签名方案,这使得托管服务商缺乏统一的技术标准来重建系统。Lindell 指出,不同的区块链社区可能会做出不同的决定,而不是采用单一的共同方案。

因此,Coinbase 正在为几种可能的结果做好准备,而不是围绕某一个候选方案构建系统。Lindell 表示,公司希望避免一种情况:即某个区块链批准了一种其托管基础设施无法处理的签名方案。

这项工作的重要性不言而喻,因为根据 Lindell 在节目中提供的数据,Coinbase 为客户保管着约 2500 亿美元的机构资产。其客户包括贝莱德(BlackRock),后者使用 Coinbase Custody 来管理与其投资产品相关的数字资产。一份今年早些时候的美国托管审查报告将 Coinbase 的机构资产规模列为约 3760 亿美元,并指出该公司保障了美国现货比特币和以太坊交易所交易基金(ETF)所持资产的 80% 以上。这两个总数之间的差异可能取决于各自的报告日期以及每个估算中包含的服务或资产范围。

托管系统负责保护授权交易所需的私钥。因此,比特币签名方法的任何未来变更都将要求大型托管服务商更新用于创建、存储和操作这些密钥的技术。

后量子签名对现有 MPC 托管构成挑战

许多机构级托管平台使用多方计算(MPC)技术,将私钥的控制权分散给多个参与方。在这种安排下,没有任何参与者需要持有或组装完整的私钥即可批准交易。Lindell 表示,许多后量子签名方案可能对“MPC 不友好”,因为其数学设计与主要区块链目前使用的签名不同。基于哈希的签名构成了一个特别的问题,因为它们缺乏传统加密密钥拆分所依赖的算术结构。

Lindell 提到,包括斯坦福大学密码学家 Dan Boneh 在内的研究人员正在研究将类似 MPC 的控制机制应用于此类签名的可行方法。然而,这项研究仍处于高度实验阶段,目前尚不清楚是否能为基于哈希的签名创建一个实用的 MPC 等效系统。

Coinbase 对该领域的兴趣早于最新的托管设计。今年一月,该公司成立了一个独立的量子计算与区块链顾问委员会,成员包括 Boneh、Lindell、以太坊基金会研究员 Justin Drake、德克萨斯大学教授 Scott Aaronson、EigenLayer 创始人 Sreeram Kannan 以及分布式系统专家 Dahlia Malkhi。据 Coinbase 介绍,其后量子路线图包括更改比特币地址处理方式、更新内部密钥管理系统,以及在 MPC 基础设施中支持 ML-DSA 等方案的研究。公司委托该顾问委员会评估量子发展动态、发布建议并应对重大技术进步。

Other hosting providers have begun testing one possible path. In June, BitGo tested it on its hosting platform using a quantum security MPC based on the ML-DSA protocol developed by Silence Laboratories. According to the two companies, the simulation retains distributed key control, policy checking, and separation of duties. ML-DSA has been included in FIPS 204, a post-quantum digital signature standard published by the National Institute of Standards and Technology (NIST). Lindell's comments suggest that if Bitcoin or other networks choose a different design, Coinbase wants to have an architecture that can handle alternatives to ML-DSA.

Hardware modules can be used as hosting alternative

To reduce reliance on MPC compatibility, Lindell revealed that Coinbase is exploring an alternative design with a programmable hardware security module (HSM) at its core. An HSM is a physically protective device used to store encrypted material and perform sensitive operations. In the architecture considered by Coinbase, private keys will remain encrypted using post-quantum cryptography and will only be assembled inside a secure HSM. Including the full key within the protected device will allow hosting providers to handle signature schemes that cannot be split through traditional MPC. Programmable modules can also make room for Coinbase to add support as blockchain developers establish new standards.

Lindell did not provide a completion date, indicating that technical work may take time. However, once the system is complete, he predicts that Coinbase will not have to predict which post-quantum solution each network will choose. "I will be able to say that I can support any solution," Lindell said.

Under the proposed model, physical security becomes even more important because the full key will temporarily exist inside the HSM. Therefore, Coinbase needed to ensure that modules could perform signature operations without exposing the key to external software or operators. This approach does not require Coinbase to abandon its use of MPC for the signature scheme that supports it. Instead, the HSM architecture will serve as an additional method of hosting when the network's chosen cryptography cannot be used with distributed key generation and signing.

Bitcoin has not yet approved the quantum migration plan

Bitcoin currently uses elliptic curve cryptography, and there is currently no publicly demonstrated quantum computer capable of deriving private keys from exposed public keys. Still, researchers and industry groups are calling for early preparation because changing Bitcoin's security model requires software development, testing, wallet upgrades and network consensus. Crypto.news reported in June that Coinbase's advisory board urged Bitcoin developers to start creating migration tools before cryptographically meaningful quantum computers emerge. The committee estimates that approximately 1.7 million BTC are stored in older pay-to-public-key addresses where public keys are exposed, and address reuse could result in as many as 5 million BTC being placed in the future risk category.

顾问委员会并未建议冻结、销毁或将易受攻击的硬币留给未来的攻击者。它表示,比特币社区应通过其共识过程决定如何在迁移截止日期之后处理仍保留在旧地址格式中的硬币。草案提案正在审查问题的各个独立部分。BIP 360(称为 Pay-to-Merkle-Root)旨在移除 Taproot 中易受量子攻击的密钥路径支出选项,而 BIP 361 描述了在比特币获得后量子输出方法后,逐步淘汰旧版 ECDSA 和 Schnorr 签名。

这两项提案均未激活。最近的迁移评估还发现,SHRINCS——一种正在讨论的实验性基于哈希的签名设计——仍然是一个未编号的草案,需要进一步审查和完成安全证明。

对于美国投资者而言,Coinbase 的准备措施涉及通过监管投资产品持有的资产以及由直接机构客户存储的硬币。现货比特币和以太坊 ETF 投资者并不控制基金持仓背后的私钥;这些密钥由发行人选择的托管服务商管理。如果比特币、以太坊或美国上市基金使用的其他网络采用新的密码学,Coinbase 支持多种签名方案的能力可能会变得相关。任何区块链迁移仍将取决于网络规则以及用户、钱包提供商、交易所、托管服务商和基金运营商的行动,而非仅由 Coinbase 单方面决定。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP