Schnorr and BLS: two proposals to improve Bitcoin cryptography
Digital signatures resemble real signatures in that both allow proving that the sender of a message is who it claims to be. Within the scope of the blockchain, the digital signature serves to prove that a message comes from a specific person and not, for example, from a hacker.
For the signature of transactions in Bitcoin, a digital signature algorithm (DSA) was chosen. ECDSA (Elliptic Curve Digital Signature Algorithm), because it uses an elliptic curve as a tool to generate a public key from a private key, which allows signing messages and transactions, so that third parties can verify the authenticity of the signature , while the signer retains the ability to create the signature.
With ECDSA, arithmetic operations are performed on the curve . For example, to add P + Q, we first obtain the point -R, at the intersection of the prolongation of the PQ segment with the elliptic curve. The resulting point of the sum is R, the reflection of -R, as seen in the following graph:
Image: libroblockchain.com
If we assume that the point Q moves towards P, when this coincides with P, we will have a line tangent to the curve, which passes through P. In that case the resulting value of R will be:
R = P + P = 2P
In the following example, where a generator point G is chosen, the tangent technique is used three consecutive times, to obtain point 8G:
Image: libroblockchain.com
Who knows the private key and performs this cycle a great number of times, obtains the public key -for example, the x coordinate of the resulting point- in a relatively simple way, but the inverse process can not be reconstructed if the number of steps is not known. made. That is, you can not know what was the generating point of a particular point of the curve.
ECSDA fulfills its role of guaranteeing transactions between peers, but there are capacities that it does not have, such as the integration of multiple firms in a single firm.
Digital signatures Schnorr and another more recent proposal from Boneh-Lynn-Shacham, briefly as BLS , allow the management of multiple digital signatures, among other advantages compared to ECDSA.
Advantages of Schnorr firms
Schnorr signatures have a constant size that is independent of the number of participants in the multiple signature scheme. For this reason the performance of this scheme improves substantially by avoiding the requirement of validity each signature separately. In addition, verification of Schnorr signatures is slightly faster than those of ECDSA.
Several authors agree that the Schnorr method was the best at the time the White book Bitcoin, but it was not selected as it was patented at that time. It is just a matter of discussion at this time since the patent expired.
In Bitcoincore.org , the web portal of the main group of Bitcoin developers, is exposed in this document the functioning of Schnorr firms and the benefits they offer compared to ECDSA.