Skip to main content

signer_set_digest

Function signer_set_digest 

Source
pub fn signer_set_digest(public_keys: &[XmssPublicKey]) -> [u8; 32]
Expand description

The commitment to a declared signer set.

The keys are hashed in the order given, so this binds an order as well as a set. Requiring that order to be strictly increasing is what makes the two the same thing.

The digest is the full 256 bits rather than the scheme’s truncated 128.

A signature needs its hashes to make a chosen target hard to collide. 128 bits carry that.

A set commitment needs any two sets to be hard to collide. 128 bits leave that at 64.