bitcoin-dev

Schnorr signatures BIP

Schnorr signatures BIP

Original Postby Erik Aronesty

Posted on: September 13, 2018 20:20 UTC

The discussion revolves around building up threshold signatures via concatenation in Bitcoin.

The paper suggests that M of N signatures are required to validate one of the permutations of M that signed, rather than using a scheme like a polynomial function where the threshold is built into the system. It also touches upon the Musig, which being M of M, is prone to loss. However, it is possible to create M-of-N threshold MuSig signatures for any M and N with 0 implemented at a specific link provided on Github. The author wonders if there is another mechanism present as it seems too simple to mention. Andrew Poelstra, the research director of Mathematics Department, Blockstream, responds to this discussion.