{"type":"rich","version":"1.0","author_name":"npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","author_url":"https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2018-07-08\n📝 Original message:You don't have to treat the hash as a group member for the purposes of\nsigning.\n\nEverything else about the algorithm works the same.\n\nThis just enables signatures to be computed much more simply.\n\nOn Sun, Jul 8, 2018, 11:32 AM Tim Ruffing via bitcoin-dev \u003c\nbitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\n\u003e Hi Erik,\n\u003e\n\u003e On Sun, 2018-07-08 at 10:19 -0400, Erik Aronesty via bitcoin-dev wrote:\n\u003e \u003e Consider changing the \"e\" term in the schnorr algorithm to hash of\n\u003e \u003e message (elligator style) to the power of r, rather than using\n\u003e \u003e concatenation.\n\u003e\n\u003e How do you compute s = x*e if e is an element of group G?\n\u003e (Similar question: How do you verify if e is element of G?)\n\u003e\n\u003e Are you aware of\n\u003e  http://cacr.uwaterloo.ca/techreports/2001/corr2001-13.ps ?\n\u003e This is a threshold signature scheme for Schnorr signatures, so what\n\u003e you want is possible already with Schnorr signatures.\n\u003e\n\u003e Best,\n\u003e Tim\n\u003e _______________________________________________\n\u003e bitcoin-dev mailing list\n\u003e bitcoin-dev at lists.linuxfoundation.org\n\u003e https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180708/d7a9e8b4/attachment-0001.html\u003e"}
