Interesting, do you have more info on this?
This seems more expressive and composable, probably with larger proof size.
There's a new paper "Anchored Merkle Range Proofs for Pedersen Commitments" (ePrint 2025/1811, October) which might stay within your existing primitives, maybe more suitable than bullet proofs for you.
How would you handle key compromise in the middle of the chain? Are the roles attached to the chain position?
Thread
Login to reply