DahLIAS: Discrete Logarithm-Based Interactive Aggregate Signatures

Posted by waxwing/ AdamISZ

Apr 26, 2025/17:05 UTC

The email discusses a realization regarding the inadequacy of using "proof of knowledge of R" as a defense mechanism in cryptographic contexts, specifically within Bitcoin development. Initially, it was considered that this method could potentially safeguard against key subtraction attacks, which are a notable concern in cryptographic security. However, upon further reflection, it becomes apparent that this strategy does not offer protection against Wagner type attacks. These attacks involve grinding nonces in parallel signing sessions, which could ultimately lead to the creation of a forgery on a victim's single key. This insight leads to the retraction of a previously suggested question, acknowledging the limitation of the proposed defensive approach in ensuring cryptographic security. This discussion highlights the complexities and evolving understanding of cryptographic security measures in the context of Bitcoin development.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from authoritative bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiBitcoin Transcripts Review
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project?

Give Feedback