Aranha, D. F., Hall-Anderson, M., Nitulescu, A., Pagnin, E., & Yakoubov, S. 2021. Count me in! : Extendability for threshold ring signatures. [Cryptology ePrint Archive, Report 2021/1240]  
Last edited by: Plowsof 3/9/22, 5:28 PM
"IIUC, if this could be applied to Monero, then all the rings signatures in a block could be combined non-interactively for much better anonymity sets

It even has a notion of key-images, although they call them "same-message linkable extendable ring signatures" "

      As far as I can tell this relies on size-linear constructions, which are less efficient than Grootle proofs.
