In the modern digital world, multisignatures are crucial for applications requiring consensus from multiple parties. This thesis addresses the theoretical and practical aspects of Schnorr multisignatures. The work begins with an overview of cryptographic fundamentals and a detailed analysis of the standard Schnorr signature. The core of the thesis is dedicated to the formal Accountable-Subgroup Multisignature (ASM) model, which provides full flexibility and signer accountability through the use of zero-knowledge proofs of knowledge and Merkle trees. The scheme's security is proven in the random oracle model via a reduction to the hardness of the discrete logarithm problem. Subsequently, a modern alternative, the MuSig2 signature scheme, is presented. MuSig2 reduces the number of communication rounds to two and enables key aggregation, thereby achieving greater efficiency and privacy in exchange for accountability. An empirical analysis confirms the theoretical advantages of these schemes: while the verification time for a series of individual Schnorr signatures grows linearly, it is significantly lower for the ASM scheme and constant for MuSig2. The thesis concludes that the choice between these schemes represents a trade-off between accountability and efficiency, and is dependent on the specific requirements of the application.
|