Author: Johnson Lau 2019-03-21 08:37:54
Published on: 2019-03-21T08:37:54+00:00
In a discussion on the bitcoin-dev mailing list, ZmnSCPxj sought clarification regarding the script format for implementing eltoo with NOINPUT. The initial proposal suggested using either of two scripts: CHECKSIGVERIFY CHECKSIG or CHECKSIGVERIFY CHECKSIG. In response, aj clarified that either script can be used. If the former is chosen, Alice and Bob exchange the NOINPUT signature and add the required non-NOINPUT signature when necessary. On the other hand, if the latter is used, A and B will cosign the muSig(A,B) with NOINPUT, and they will share the private key of Q to produce a non-NOINPUT signature when required. Although the first style is simpler, the second is more efficient with three or more parties. However, watchtower requires the use of the second style, which means sharing the private key for Q with the watchtower. Despite this, it remains better than anyone-can-replay.
Updated on: 2023-05-20T20:03:32.681351+00:00