This property is not observed in MuSig2βs key generation, as it uses additive secret sharing and randomization.
18.01.2025 08:37 β π 0 π 0 π¬ 0 π 0@siv2r.bsky.social
libsecp256k1 dev supported by @spiralbtc | Prev: Maths @IITKgp, Intern @summerofbitcoin
This property is not observed in MuSig2βs key generation, as it uses additive secret sharing and randomization.
18.01.2025 08:37 β π 0 π 0 π¬ 0 π 0ChillDKG uses this property to commit its threshold public key to an unspendable script path, making it Taproot-safe.
18.01.2025 08:37 β π 0 π 0 π¬ 1 π 0Proof by Lagrange interpolation
While reviewing the ChillDKG BIP, I noticed a neat property: In a t-of-n Shamir sharing scheme, where combining shares s1, s2, and s3 gives a secret c. If you offset these shares by adding a constant k (i.e., s1 + k, s2 + k, s3 + k), the result will be an offset secret c + k.
18.01.2025 08:37 β π 0 π 0 π¬ 1 π 0