Skip to content

Which cryptosystem for v0.1 of anonymous credentials ? #3

@ariard

Description

@ariard

Blinded BIP341 Schnorr signatures are vulnerable to Wagner’s attack. While there is a known mitigation it is yet to be evaluate if it fits the Staking Credentials sessions.

Blinded 2-party ECDSA has been studied in Bitcoin context and there is implementation of such protocol.

There is also more complete anonymous credentials based on homomorphic commitment already deployed in Bitcoin context.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions