Global Feed Post Login
Replying to Avatar waxwing

Oh, no Alice wouldn't explicitly reveal even the combination of k values.

Back to the single signer case: s = k + ex. You never reveal k, only R (the "commitment" to k, as discussed before). You publish R and s, so revealing k would expose the key (x). It's the fact that there are *two* secret unknowns (k and x) on the RHS that provides the security against leakage. If I give you the number 41 and say it's the sum of two numbers (mod 43), I'm not telling you anything (it could be any sum of 2 numbers in range).

Same here; Alice will give Bob s_alice, the partial signature of Alice, which is: k_{A1} + bk_{A2} + hashes * x_alice. But she would never separately hand over just k_{A1} + bk_{A2} ; that's her secret nonce.

About notation like k_{A1} I'm just doing the same as in LaTeX, it means everything in the curly braces is the subscript of the thing before _ .

Avatar
Sjors Provoost 2y ago

When Nostr Latex rendering?

nostr:nevent1qqsp2skjvesppnmm8ehmzmqs2mxq05qn2cfjphps6dsmks6nvchgtyqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzqe6msnl8tcsk4w28capcaegeefmh2dmdmuza4ha6vfut6qfwr4egqvzqqqqqqypnjx78

Reply to this note

Please Login to reply.

Discussion

Avatar
roshii 2y ago

nostr:npub1gcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqlfnj5z may be able to implement this on #Amethyst ?

Thread collapsed