Selling timestamps (via payment points and scalars + Pedersen commitments ) [try2]



Summary:

The discussion revolves around a practical way to pay for decommitment idea to any commitment scheme. The Pedersen commitments and pay to point is considered the most suitable approach, but this can be generalized in payment channels with hashes if there were something like OP_CAT. The concept of HTLC unlocks based on whether one can provide an r such that H(r || x) == C is also introduced. However, the zkp already proves that C was generated based on x, so the timestamp is obtained free of cost. The interactive zero-knowledge protocol is suggested as an alternative. If one knows x and r, they can generate C and R and a zero knowledge proof of the relationship between x, C, and R that does not reveal r.


Updated on: 2023-06-02T20:18:34.637840+00:00