On adaptor security (in protocols)



Summary:

In a recent post, AdamISZ/waxwing raised concerns about the security of using signature adaptors. While there is already substantial work on the topic, AdamISZ/waxwing wanted to explore scenarios of multiple adaptors or multiple signing sessions with the same adaptor. The work done by AdamISZ/waxwing is currently unreviewed and is available on GitHub for people to provide corrections or comments. The analysis was only done around MuSig and not MuSig2. The third case of "multiple signing sessions, same adaptor" proved to be the most interesting, as an issue around sequencing was found while trying to reduce it to ECDLP. AdamISZ/waxwing is interested in hearing from experts in the field regarding security reductions for this primitive in the case of multiple concurrent signing sessions.


Updated on: 2023-06-16T18:08:05.843166+00:00