Membuka halaman berikutnya.
Menampilkan bab berikutnya…
Psst… sesuaikan cara membaca Anda.
Font dan tema ada di Tampilan. Mata Anda juga berhak memilih.
Menampilkan bab berikutnya…
The Bitcoin specification for a particular Schnorr signature scheme over secp256k1, used with Taproot spending.
Memeriksa dukungan baca nyaring pada peramban ini…
Bacaan ini saat ini tersedia dalam bahasa Inggris. Antarmuka menggunakan bahasa pilihan Anda.
Baca teks asli bahasa Inggris →Schnorr signatures are a family of cryptographic constructions, and BIP-340 defines the exact version used in Bitcoin. It specifies encoding, signing, verification, and related requirements over the secp256k1 curve. These details matter: two systems can both advertise Schnorr signatures without producing interchangeable signatures. BIP-341 connects the scheme to Taproot's transaction-output spending rules, so the signature specification and the rules governing what it authorizes are separate but related layers.
Schnorr's algebraic structure supports carefully designed protocols in which several participants cooperate to produce an aggregate signature. This can make a cooperative spend look simpler on-chain than revealing every participant's individual authorization. It does not mean users can safely add arbitrary signatures together or invent their own multisignature protocol. Secure participant setup, nonce handling, and resistance to malicious collaborators require additional protocol design beyond the base signature equation.
Taproot can reduce the information exposed when a transaction follows its cooperative key path, but it does not automatically hide amounts, recipients, or the entire transaction graph. Script-path spending can reveal different information. Signature size and verification properties are engineering features, not assurances that a wallet is anonymous or immune to key theft. When reading a wallet's feature list, distinguish BIP-340 support, Taproot address support, and support for a specific collaborative signing scheme.