Skip to main content

Module aggregate

Module aggregate 

Source
Expand description

Aggregation of XMSS signatures on a common message.

Each signer has an independent tree, so a public key is a (root, public parameter) pair and both are per-signer. All signers sign the same message at the same epoch, and one proof stands for every signature.

The same aggregate is built two ways over one set of wires: circuit_xmss_multisig emits every signer’s verification inline, and circuit_xmss_multisig_chip states it once as an M4 chip and calls that chip per signer.

Both publish every signer’s key, so their statement grows with the number of signers.

A third form publishes one commitment to the whole set instead. That is what a statement has to look like before an aggregate can be a step in a tree.

Structs§

CommittedMultiSigWires
The wires a committed aggregate occupies.
MultiSigWires
The wires an aggregate verification occupies.
SignerWires
One signer’s public key and signature wires.

Constants§

SIGNER_BYTES
Bytes one signer contributes to a signer-set commitment.
SIGNER_SET_WIRES
Wires holding a signer-set commitment.

Functions§

circuit_xmss_multisig
Verifies every signer’s XMSS signature on the common message at the common epoch.
circuit_xmss_multisig_chip
circuit_xmss_multisig with each signer’s verification dispatched to a chip.
circuit_xmss_multisig_committed
The aggregate verification against a committed signer set rather than a published one.
signer_order_key
The order signers are declared in.
signer_set_digest
The commitment to a declared signer set.
sort_by_signer
Puts signatures into the declared order.