Skip to content

Key image scheme isn't unlinkable for related keys #23

@kayabaNerve

Description

@kayabaNerve

For two keys K1 = R + o G, K2 = R + o' G, where R is the root key and o is some offset, their key images will be distinct by o' - o J. This allows anyone who knows the relationship of two keys to identify their key images and link them.

Defining J = H(K), a unique generator per key, prevents this under the DDH assumption.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions