Global Feed Post Login
Replying to Avatar Tim Bouma

I am thinking about creating the concept of a “cpub” or child public key of a root npub. The idea is that the cpub can be provably traced back to a npub. I can have as many cpubs as I want, that map back to the same ‘identity’. If a cpub keypair gets compromised, I can publish an event that invalidates that cpub.

As for clients, when they see what is a cpub, they can resolve back to the root npub and present that identity instead.

The driving requirement is to have a protected root npub that corresponds to my identity; it is high-value so I only want to sign with it when absolutely necessary - keeping it on a hardware signer device.

Any comments on this approach?

Avatar
il_lost_ 2mo ago 💬 1

you can choose between frost or higher

Reply to this note

Please Login to reply.

Discussion

Avatar
Tim Bouma 2mo ago

Yeah, frost I need to take a close look.

Thread collapsed