MuSig2 已准备好等待两个新的 BIP:引入多重签名隐私的新时代

By Bitcoin 杂志 - 5 个月前 - 阅读时间:3 分钟

MuSig2 已准备好等待两个新的 BIP:引入多重签名隐私的新时代

Traditionally, creating an n-of-n multisig using CHECKMULTISIG means you’ll publish a proportional number of signatures and public keys on the blockchain to signers in the transaction. This approach not only reveals the total number of participants in the transaction, but also incurs progressively higher transaction fees as the number of signers grow. MuSig, on the other hand, allows a group of users to generate a single signature and public key to validate a transaction, which enhances privacy and lowers the transaction costs for all the signers involved.

When MuSig was initially introduced in 2018, its main shortcoming compared to CHECKMULTISIG was user experience, specifically the requirement for three rounds of interactive communication between signers. With the introduction of 信号2 (BIP 327) in 2020, as the successor to the 2018 MuSig (also called MuSig1), we made significant progress in non-interactive signing, bringing us a much more desired experience.

运行流程

MuSig2 反映了其前身的功能,将所需的通信轮数从三轮减少到两轮。 MuSig2 的钱包设置首先收集所有参与者的扩展公钥 (xpub),并由每个钱包构建描述符,所有这些都与现有的多重签名实践一致。

MuSig2 签名阶段包括:

First-Round Message: During the wallet setup, nonces are generated, added to the Partially Signed Bitcoin Transactions (PSBTs), and shared amongst the other signers.Second-Round Message: The nonces received are used to create a partial signature and are sent back to each of the other signers.

让每个签名者直接将其随机数和部分签名传达给其他签名者的另一种方法是引入第三方协调员来简化通信过程。

In the signing process, each signer's nonce is composed of two elliptic curve points. These points are transmitted to other signers through the Partially Signed Bitcoin Transactions (PSBTs). These nonces require careful handling for accuracy and integrity in the process, but secure storage is not necessary since they are not confidential information. If all the individuals partial signatures are valid, then the produced Schnorr signatures are valid.

后续实施步骤

上个月, 周安迪 put forward two BIP drafts, MuSig2 PSBTsMuSig2 Descriptors, which are a necessary step in MuSig2 adoption and wallet integration. The first BIP adds fields for the nonces, public keys, and partial signatures in the PSBTs, and the second BIP provides a method for describing transaction outputs that are controlled by a MuSig2 wallet. Together, these BIPs and specifications are all we need for integration of MuSig2 wallets!

Many wallet developers and collaborative custody have long requested this standardization of the MuSig2 protocol. Now, with the formalized BIPs in place, it's in the community's hands to review, give feedback, and help raise awareness. At Blockstream, we look forward to participating in the public discussions and letting the formal BIP review process take place.

This is a guest post by Kiara Bickers. Opinions expressed are entirely their own and do not necessarily reflect those of BTC Inc or Bitcoin 杂志。

原始来源: Bitcoin 杂志