Daniel Edgecumbe [ARCHIVE] on Nostr: π
Original date posted:2018-02-22 π Original message:> However, the ...
π
Original date posted:2018-02-22
π Original message:> However, the non-interactive schnorr aggregation trick[1] can be
applied to merge the S values of all graftroots and signatures in a
transaction into a single aggregate. With this approach only a single
R value for each graftroot need be published, lowering the overhead to
~32 bytes-- the same as taproot. This has a side benefit of binding
the published grafts to a particular transaction, which might help
avoid some screwups.
I don't think that binding grafts to a particular transaction requires this aggregation.
It seems to me that you could just sign H(txid, script) rather than H(script).
I'm not aware of whether this would break aggregation.
---
Daniel Edgecumbe / esotericnonsense
esotericnonsense at esotericnonsense.com
https://esotericnonsense.comhttps://danedgecumbe.comPublished at
2023-06-07 18:10:30Event JSON
{
"id": "6d2f8085565b5041e5561a07b0a16c8009b163f541bbab5cd60fda79275abb56",
"pubkey": "2e27fff07ed0d169b37fd290baf00d5ed55b1bc341c93b10d11e2a56a7aba1f7",
"created_at": 1686161430,
"kind": 1,
"tags": [
[
"e",
"2c4ac7b10c60a79e3222a978e68f7b31f3c05b671343599c2ea55f4413483685",
"",
"root"
],
[
"e",
"6b82261b51141c6994e536968e6a92c49608c7833488bc6f5946071a8d3c3825",
"",
"reply"
],
[
"p",
"2f55bf03677afdb15d004a39383afba6220aa6c059cafa7b8827b87934d3c254"
]
],
"content": "π
Original date posted:2018-02-22\nπ Original message:\u003e However, the non-interactive schnorr aggregation trick[1] can be\napplied to merge the S values of all graftroots and signatures in a\ntransaction into a single aggregate. With this approach only a single\nR value for each graftroot need be published, lowering the overhead to\n~32 bytes-- the same as taproot. This has a side benefit of binding\nthe published grafts to a particular transaction, which might help\navoid some screwups.\n\nI don't think that binding grafts to a particular transaction requires this aggregation.\nIt seems to me that you could just sign H(txid, script) rather than H(script).\nI'm not aware of whether this would break aggregation.\n\n---\nDaniel Edgecumbe / esotericnonsense\nesotericnonsense at esotericnonsense.com\nhttps://esotericnonsense.com\nhttps://danedgecumbe.com",
"sig": "6b9b022ef9f3fd184abe8e60282b8694050547998ca18507ce20c7ba8c36ea3bfcd0be45ad813e0849fdcdd4b058a75c250f87d34b572644a40870ec8a68efaf"
}