Expand description
Aggregation of XMSS signatures on a common message.
Each signer has an independent tree, so a public key is a (root, public parameter) pair and
both are per-signer. All signers sign the same message at the same epoch, and one proof stands
for every signature.
The same aggregate is built two ways over one set of wires: circuit_xmss_multisig emits
every signer’s verification inline, and circuit_xmss_multisig_chip states it once as an M4
chip and calls that chip per signer.
Both publish every signer’s key, so their statement grows with the number of signers.
A third form publishes one commitment to the whole set instead. That is what a statement has to look like before an aggregate can be a step in a tree.
Structs§
- Committed
Multi SigWires - The wires a committed aggregate occupies.
- Multi
SigWires - The wires an aggregate verification occupies.
- Signer
Wires - One signer’s public key and signature wires.
Constants§
- SIGNER_
BYTES - Bytes one signer contributes to a signer-set commitment.
- SIGNER_
SET_ WIRES - Wires holding a signer-set commitment.
Functions§
- circuit_
xmss_ multisig - Verifies every signer’s XMSS signature on the common message at the common epoch.
- circuit_
xmss_ multisig_ chip circuit_xmss_multisigwith each signer’s verification dispatched to a chip.- circuit_
xmss_ multisig_ committed - The aggregate verification against a committed signer set rather than a published one.
- signer_
order_ key - The order signers are declared in.
- signer_
set_ digest - The commitment to a declared signer set.
- sort_
by_ signer - Puts signatures into the declared order.