ZmnSCPxj [ARCHIVE] on Nostr: š
Original date posted:2020-03-12 š Original message: Good morning tbast, ...
š
Original date posted:2020-03-12
š Original message:
Good morning tbast, rusty, and list,
> As for ZmnSCPxj's suggestion, I think there is the same kind of issue.
> The secrets we establish with anonymous multi-hops locks are between the *sender*
> and each of the hops. In the route blinding case, what we're adding are secrets
> between the *recipient* and the hops, and we don't want the sender to be able to
> influence those. It's a kind of reverse Sphinx. So I'm not sure yet the recipient
> could safely contribute to those secrets, but maybe we'll find a nice trick in
> the future!
Not quite?
The recipient knows the secrets from the first recipient-selected-hop to itself, and, if it knows the payment scalar, can subtract those secrets from the receiver scalar.
Thus the sender only has to arrange to deliver the payment point to the first recipient-selected-hop, the rest of the recipient-selected-hops will add their blinding scalars (which come from the recipient), and the final recipient can linearly deduct those.
Regards,
ZmnSCPxj
Published at
2023-06-09 12:59:17Event JSON
{
"id": "41be51b07a8bad612194ecf12388a022c50c7b6821036c9ac000d06a902ceba3",
"pubkey": "4505072744a9d3e490af9262bfe38e6ee5338a77177b565b6b37730b63a7b861",
"created_at": 1686315557,
"kind": 1,
"tags": [
[
"e",
"bdf43e4bc08687232ed81714c7a2374ed959a034fef2fe272a2bb53b5a09849b",
"",
"root"
],
[
"e",
"bf6583b0b1578dc6cb518a4b78aeb604e5780765ab6e2244752630382710c67c",
"",
"reply"
],
[
"p",
"f26569a10f83f6935797b8b53a87974fdcc1de6abd31e3b1a3a19bdaed8031cb"
]
],
"content": "š
Original date posted:2020-03-12\nš Original message:\nGood morning tbast, rusty, and list,\n\n\n\u003e As for ZmnSCPxj's suggestion, I think there is the same kind of issue.\n\u003e The secrets we establish with anonymous multi-hops locks are between the *sender*\n\u003e and each of the hops. In the route blinding case, what we're adding are secrets\n\u003e between the *recipient* and the hops, and we don't want the sender to be able to\n\u003e influence those. It's a kind of reverse Sphinx. So I'm not sure yet the recipient\n\u003e could safely contribute to those secrets, but maybe we'll find a nice trick in\n\u003e the future!\n\nNot quite?\n\nThe recipient knows the secrets from the first recipient-selected-hop to itself, and, if it knows the payment scalar, can subtract those secrets from the receiver scalar.\nThus the sender only has to arrange to deliver the payment point to the first recipient-selected-hop, the rest of the recipient-selected-hops will add their blinding scalars (which come from the recipient), and the final recipient can linearly deduct those.\n\nRegards,\nZmnSCPxj",
"sig": "94f092ed6b21a22b51ed61c94fec96eaa8f0e7917acc591312c93c4984b24c09ec10e8fc39064f54585bfeea7d6ba46386954a8ef66e52e65eb8e59bab8bf6a5"
}