Schnorr signatures – Why is the exponent b only one of two nonces in MuSig2?


In MuSig2 R_i'' Added to itself b times (in Multiplication notationher exponent b) but R'_i not (has no exponent b).

Why is there only one exponent of non-missing characters b And not both? I expected:

R_i = (R'_i.R''_i)^b

I suppose it saves on the exponent and somehow offers the same safety (because b fragmentation of both R'_i And the R_i'')?

The following is taken from Tim Ruffing’s slides [Real World Crypto 2021][3]:



Source link

Related Posts