페이지를 넘기고 있습니다.
다음 장을 불러오고 있습니다…
잠깐… 나만의 읽기 환경을 만들어 보세요.
글꼴과 테마는 화면 설정에서 설정하세요. 눈의 편안함도 중요합니다.
다음 장을 불러오고 있습니다…
The Bitcoin specification for a particular Schnorr signature scheme over secp256k1, used with Taproot spending.
브라우저의 읽어주기 지원을 확인하는 중…
이 읽기 자료는 현재 영어로 제공됩니다. 인터페이스에는 선택한 언어가 적용됩니다.
영어 원문 읽기 →Schnorr signatures are a family of cryptographic constructions, and BIP-340 defines the exact version used in Bitcoin. It specifies encoding, signing, verification, and related requirements over the secp256k1 curve. These details matter: two systems can both advertise Schnorr signatures without producing interchangeable signatures. BIP-341 connects the scheme to Taproot's transaction-output spending rules, so the signature specification and the rules governing what it authorizes are separate but related layers.
Schnorr's algebraic structure supports carefully designed protocols in which several participants cooperate to produce an aggregate signature. This can make a cooperative spend look simpler on-chain than revealing every participant's individual authorization. It does not mean users can safely add arbitrary signatures together or invent their own multisignature protocol. Secure participant setup, nonce handling, and resistance to malicious collaborators require additional protocol design beyond the base signature equation.
Taproot can reduce the information exposed when a transaction follows its cooperative key path, but it does not automatically hide amounts, recipients, or the entire transaction graph. Script-path spending can reveal different information. Signature size and verification properties are engineering features, not assurances that a wallet is anonymous or immune to key theft. When reading a wallet's feature list, distinguish BIP-340 support, Taproot address support, and support for a specific collaborative signing scheme.