Skip to content

Prove that signing then verifying accepts #21

Description

@tcoratger

Depends on one-time signature correctness, the Merkle path lemma, and signing landing first.

The headline theorem for this tree: a signature this specification produces is one this specification accepts.

key generation gives (sk, pk),  signing at an in-range epoch gives a signature
  =>  verification of that signature returns true

The proof is an assembly rather than new work. Signing only succeeds once it has found a randomizer whose encoding is admissible, and the verifier recomputes the encoding from the same public parameter, message, randomizer and epoch, so both see the same 42 digits. One-time signature correctness then makes the recovered chain values the honest ones, so the recomputed leaf is the honest leaf, and the Merkle path lemma carries that leaf to the honest root.

This is the theorem worth naming in the README once it lands.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions