![]() |
MoneroResearch.info |
Goodell, B., Salazar, R., Slaughter, F., & Szramowski, L. (2025). A Further Review of the DL Gadget Of Interest. Unpublished manuscript. Added by: Rucknium (27/05/2025, 22:17) |
Resource type: Manuscript BibTeX citation key: Goodell2025 View all bibliographic details |
Categories: Monero-focused Subcategories: Full-Chain Membership Proofs Creators: Goodell, Salazar, Slaughter, Szramowski Collection: Cypher Stack |
Views: 59/59
|
Attachments
follow_up.pdf |
URLs https://github.com ... /divisor_deep_dive |
Abstract |
Eagen presented the barebones sketch of a scheme for demonstrating the correct computation of sums of points in an elliptic curve group in [Eag22], and is based on the theory of divisors (which goes back at least to [DW82]). Eagen’s approach lends itself to probabilistically checkable proof schemes, especially for efficient full-chain membership proofs for Monero as described in [Par24a]. Bassa investigated further in [Bas24c], [Bas24a], and [Bas24b]. An implementation Sage by Eagen is at [Eag24]. Eagen’s implementation inspired the implementation by Parker in Rust at [Par24a] (and Parker’s implementation is described in pseudocode by Parker at [Par24b]). These implementations are variations of the protocol described in [Bas24b], and both pass basic correctness tests. The overall approach was commented upon in [BHLS25] as possibly useful in exponent-VRFs. Cypher Stack also wrote a review of [Bas24c] in [CS].
Great material may come from Eagen’s work on divisors and Bassa’s follow-ups, but more time is necessary. Production deployment of code based on these approaches is premature. We find the following troubling issues have not fully been addressed, which range from superficial to serious. We describe the approach from a high level in Section 2, elaborating on our complaints along the way.
|