<oembed><type>rich</type><version>1.0</version><author_name>npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_name><author_url>https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2018-07-08&#xA;📝 Original message:You don&#39;t have to treat the hash as a group member for the purposes of&#xA;signing.&#xA;&#xA;Everything else about the algorithm works the same.&#xA;&#xA;This just enables signatures to be computed much more simply.&#xA;&#xA;On Sun, Jul 8, 2018, 11:32 AM Tim Ruffing via bitcoin-dev &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&#xA;&gt; Hi Erik,&#xA;&gt;&#xA;&gt; On Sun, 2018-07-08 at 10:19 -0400, Erik Aronesty via bitcoin-dev wrote:&#xA;&gt; &gt; Consider changing the &#34;e&#34; term in the schnorr algorithm to hash of&#xA;&gt; &gt; message (elligator style) to the power of r, rather than using&#xA;&gt; &gt; concatenation.&#xA;&gt;&#xA;&gt; How do you compute s = x*e if e is an element of group G?&#xA;&gt; (Similar question: How do you verify if e is element of G?)&#xA;&gt;&#xA;&gt; Are you aware of&#xA;&gt;  http://cacr.uwaterloo.ca/techreports/2001/corr2001-13.ps ?&#xA;&gt; This is a threshold signature scheme for Schnorr signatures, so what&#xA;&gt; you want is possible already with Schnorr signatures.&#xA;&gt;&#xA;&gt; Best,&#xA;&gt; Tim&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180708/d7a9e8b4/attachment-0001.html&gt;</html></oembed>