MultiversX Tracker is Live!

Why does only one of the two nonce points in MuSig2 have the exponent b?

Bitcoin Stack Exchange

Bitcoin News / Bitcoin Stack Exchange 200 Views

A slight variant of MuSig2, named MuSig2*, sets one of the coefficients to 1 to make the key aggregation function slightly more efficient. This is described in a draft specification of MuSig2 : ↩

MuSig2* optimization: The specification uses an optimization that allows saving a point multiplication in key aggregation. The MuSig2 scheme with this optimization is called MuSig2* and proven secure in the appendix of the MuSig2 paper. The optimization is that the second distinct key in the list of public keys given to the key aggregation algorithm (as well as any keys identical to this key) gets the constant key aggregation coefficient 1.

I was myself confused by this when writing my blog post about MuSig2.

This trick resembles normalization of a polynomial, which is accomplished by dividing each term by the first terms' coefficient.


Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments