ECEC 04
The candidate replacements
Standfirst — one sentence stating the claim. To be written.
The honest framing
PROSE · SPEC §3.4
This is a blocksize problem wearing a cryptography costume. Bitcoin's constraint is bytes on
chain, and every post-quantum scheme is dramatically larger than a 64-byte Schnorr signature.
Source: —— · Dated: ————-——-—— · Review due: ————-——-——
Hash-based
PROSE · SPEC §3.4
Minimal assumptions — security rests on the hash. Stateful variants are operationally
dangerous, and that danger is an operations problem, not a cryptography one.
Source: —— · Dated: ————-——-—— · Review due: ————-——-——
Lattice
PROSE · SPEC §3.4
Newer assumptions, less scrutiny, smaller signatures. Say what "less scrutiny" means in years
and in eyes.
Source: —— · Dated: ————-——-—— · Review due: ————-——-——
Isogeny
PROSE · SPEC §3.4
Smallest signatures, and dropped from BIP-360 on verification cost. State the ratio as an
order of magnitude and no more precisely — it depends on implementation and platform, and
false precision here is the kind of thing this audience checks.
Source: —— · Dated: ————-——-—— · Review due: ————-——-——
Block-space arithmetic
PROSE · SPEC §3.4
The genuinely novel section: what each candidate does to a block, worked through. Squarely in
the owner's professional domain and the reason this page exists.
Source: —— · Dated: ————-——-—— · Review due: ————-——-——
EQUATION · component-specs §6
EQ 1: transactions per block as a function of signature and public-key size.