[Post-Sapling] Support delegated proving with privacy from the prover #3365
Labels
A-circuit
Area: zk-SNARK circuits
A-consensus
Area: Consensus rules
A-crypto
Area: Cryptography
elliptic curves
I-SECURITY
Problems and improvements related to security.
Network Upgrade Wishlist
not in Sapling
special to Daira
Threat Model
We know how to do this using proof-of-same-discrete-log:
We originally abandoned this approach due to complexity (which I think was a good decision for Sapling). Given the further analysis that has been done for Sapling since then, I think we know enough now to take the complexity hit for some future circuit version.
The text was updated successfully, but these errors were encountered: