Short RSA exclusion proofs for Plasma Prime

The ceremony is a nice byproduct of the VDF project. It may make sense for some Plasma Prime implementers to participate in the MPC, and maybe the resulting modulus could become an industry standard. Having said that, there are various other options that make sense, e.g. using both RSA-2048 (as suggested by Vitalik) and the modulus from the ceremony, allowing to get security from both moduli.

What is your predicted timing of reviewable MPC code (where?) + target ceremony time?

An academic paper by the Ligero team should be released in December. There’s proof-of-concept code written by them which is promising. For 256 participants on 256 different Google Cloud instances (in the same data center) it takes 100ms-300ms to generate a 256-bit modulus. The expectation is that the (synchronous) ceremony will take ~10 minutes to generate a 2048-bit modulus for 1024 participants spread across the world. I’m hoping for reviewable code early 2019 and the actual ceremony mid 2019.

3 Likes