Bitcoin Forum
December 12, 2024, 10:04:56 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Rangeproof in Mimblewimble?  (Read 966 times)
Amitabh S (OP)
Legendary
*
Offline Offline

Activity: 1001
Merit: 1005


View Profile
October 05, 2016, 03:18:02 PM
 #1

First of all, I must say its a very interesting idea. Somehow I couldn't find efficient NIZK range proofs and the mimblewimble paper kind of assumes it as "obvious".

Maybe I missed something but please point me to some efficient implementation of range proofs.

BTW the whitepaper is here
https://download.wpsoftware.net/bitcoin/wizardry/mimblewimble.txt

Coinsecure referral ID: https://coinsecure.in/signup/refamit (use this link to signup)
gmaxwell
Moderator
Legendary
*
expert
Offline Offline

Activity: 4284
Merit: 8816



View Profile WWW
October 05, 2016, 08:03:05 PM
 #2

First of all, I must say its a very interesting idea. Somehow I couldn't find efficient NIZK range proofs and the mimblewimble paper kind of assumes it as "obvious".

Maybe I missed something but please point me to some efficient implementation of range proofs.

BTW the whitepaper is here
https://download.wpsoftware.net/bitcoin/wizardry/mimblewimble.txt

https://bitcointalk.org/index.php?topic=1085273.0
kushti
Full Member
***
Offline Offline

Activity: 317
Merit: 103


View Profile WWW
October 06, 2016, 10:02:02 AM
 #3

Any security proofs behind both CT/MW schemes? both are looking pretty controversial in current form

Ergo Platform core dev. Previously IOHK Research / Nxt core dev / SmartContract.com cofounder.
gmaxwell
Moderator
Legendary
*
expert
Offline Offline

Activity: 4284
Merit: 8816



View Profile WWW
October 18, 2016, 08:39:47 AM
 #4

looking pretty controversial in current form
You are calling a binary decomposition range proof controversial? Really?
kushti
Full Member
***
Offline Offline

Activity: 317
Merit: 103


View Profile WWW
October 18, 2016, 08:46:24 AM
 #5

looking pretty controversial in current form
You are calling a binary decomposition range proof controversial? Really?


What are you talking about? Don't see any security proofs there: https://people.xiph.org/~greg/confidential_values.txt. Please provide a link.

Ergo Platform core dev. Previously IOHK Research / Nxt core dev / SmartContract.com cofounder.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!