bitcoin-dev

Schnorr signatures BIP

Schnorr signatures BIP

Original Postby Sjors Provoost

Posted on: July 14, 2018 15:42 UTC

Pieter Wuille has proposed a BIP for 64-byte elliptic curve Schnorr signatures over the same curve as currently used in ECDSA.

The proposed BIP can be found on GitHub. Some questions have been raised regarding the implementation of compressed key serialization, the use of (e,s) instead of (R,s), and the method of randomly generating numbers for batch verification. Additionally, there are nits related to the motivation behind the proposal and the message array. Sjors has suggested some changes which can be viewed on GitHub.