Membuka halaman seterusnya.
Memaparkan bab seterusnya…
Psst… sesuaikan cara membaca Anda.
Fon dan tema tersedia di Tampilan. Keselesaan mata anda juga penting.
Memaparkan bab seterusnya…
The Bitcoin specification for a particular Schnorr signature scheme over secp256k1, used with Taproot spending.
Menyemak sokongan bacaan suara pada pelayar ini…
Bacaan ini kini tersedia dalam bahasa Inggeris. Antara muka menggunakan bahasa pilihan anda.
Baca teks asal bahasa Inggeris →Schnorr signatures are a family of cryptographic constructions, and BIP-340 defines the exact version used in Bitcoin. It specifies encoding, signing, verification, and related requirements over the secp256k1 curve. These details matter: two systems can both advertise Schnorr signatures without producing interchangeable signatures. BIP-341 connects the scheme to Taproot's transaction-output spending rules, so the signature specification and the rules governing what it authorizes are separate but related layers.
Schnorr's algebraic structure supports carefully designed protocols in which several participants cooperate to produce an aggregate signature. This can make a cooperative spend look simpler on-chain than revealing every participant's individual authorization. It does not mean users can safely add arbitrary signatures together or invent their own multisignature protocol. Secure participant setup, nonce handling, and resistance to malicious collaborators require additional protocol design beyond the base signature equation.
Taproot can reduce the information exposed when a transaction follows its cooperative key path, but it does not automatically hide amounts, recipients, or the entire transaction graph. Script-path spending can reveal different information. Signature size and verification properties are engineering features, not assurances that a wallet is anonymous or immune to key theft. When reading a wallet's feature list, distinguish BIP-340 support, Taproot address support, and support for a specific collaborative signing scheme.