A proof of work (PoW) is an important cryptographic construct enabling a party to convince others that they invested some effort in solving a computational task. Arguably, its main impact has been in the setting of cryptocurrencies such as Bitcoin and its underlying blockchain protocol, which received significant attention in recent years due to its potential for various applications as well as for solving fundamental distributed computing questions in novel threat models. PoWs enable the linking of blocks in the blockchain data structure and thus the problem of interest is the feasibility of obtaining a sequence (chain) of such proofs. In this work, we examine the hardness of finding such chain of PoWs against quantum strategies. We prove that the chain of PoWs problem reduces to a problem we call multi-solution Bernoulli search, for which we establish its quantum query complexity. Effectively, this is an extension of a threshold direct product theorem to an average-case unstructured search problem. Our proof, adding to active recent efforts, simplifies and generalizes the recording technique of Zhandry (Crypto'19). As an application, we revisit the formal treatment of security of the core of the Bitcoin consensus protocol, the Bitcoin backbone (Eurocrypt'15), against quantum adversaries, while honest parties are classical and show that protocol's security holds under a quantum analogue of the classical ``honest majority'' assumption. Our analysis indicates that the security of Bitcoin backbone is guaranteed provided the number of adversarial quantum queries is bounded so that each quantum query is worth $O(p^{-1/2})$ classical ones, where $p$ is the success probability of a single classical query to the protocol's underlying hash function. Somewhat surprisingly, the wait time for safe settlement in the case of quantum adversaries matches the safe settlement time in the classical case.
翻译:工作量证明(PoW)是一种重要的密码学构造,使一方能够使他人相信其在解决计算任务中投入了努力。可以说,其主要影响体现在比特币等加密货币及其底层区块链协议中——由于其在不同应用中的潜力以及在新型威胁模型下解决基本分布式计算问题的能力,该协议近年来受到广泛关注。PoW使得区块链数据结构中的区块得以链接,因此关键问题在于获取此类证明序列(链)的可行性。本文研究了在量子策略下寻找PoW链的困难性。我们证明,PoW链问题可归结为一个我们称之为“多重解伯努利搜索”的问题,并确定了其量子查询复杂度。实际上,这是将阈值直接乘积定理推广到平均情况下的无结构搜索问题。我们的证明简化并推广了Zhandry(Crypto'19)的记录技术,为近期活跃的研究进展做出贡献。作为应用,我们重新审视了比特币共识协议核心——比特币主干(Eurocrypt'15)——在量子敌手(诚实方为经典方)下的安全性形式化处理,并证明该协议的安全性在经典“诚实多数”假设的量子类比下成立。我们的分析表明,只要量子敌手的查询次数满足上限,使得每次量子查询等价于O(p^{-1/2})次经典查询,比特币主干的安全性即可得到保证,其中p为单次经典查询协议底层哈希函数的成功概率。令人意外的是,量子敌手情况下安全结算的等待时间与经典情况下的安全结算时间一致。