codexproof

glossary / Schnorr lineage

the signature design family started by Claus-Peter Schnorr - simple, provably secure in the random-oracle model, and linear in a way that makes batch verification and aggregation natural; Ed25519 is its most successful descendant.

blake3ed25519sigstore
Schnorr lineage - Thirty years on one timeline: publish, patent, detour, expiry, bloom

Thirty years on one timeline: publish, patent, detour, expiry, bloom.

Etymology and backstory

Schnorr published the scheme around 1989-1991 and patented it - and that patent, which ran until 2008, is why the world spent two decades on DSA and ECDSA, both designed to route around it. Pointcheval and Stern proved Schnorr-style schemes secure in 1996 using the forking lemma. Once the patent died, the family bloomed: EdDSA in 2011, and Bitcoin adopted Schnorr proper in its 2021 Taproot upgrade (BIP 340) precisely for the linearity - signatures that can be aggregated.

Ecosystem

EdDSA everywhere, BIP 340 in Bitcoin, MuSig multi-signatures, and most modern zero-knowledge-adjacent identification protocols trace to Schnorr's three-move dance.

In codexproof

present through Ed25519. The linearity also underwrites a future optimization the paper leaves unclaimed: batch verification of many envelope signatures at once.

"Half of applied signature history is the industry waiting out one patent - and the moment it expired, everyone quietly went home to Schnorr."
References: Schnorr, "Efficient Signature Generation by Smart Cards," Journal of Cryptology (1991). Pointcheval and Stern, "Security Proofs for Signature Schemes," EUROCRYPT (1996). Wuille, Nick, Ruffing, BIP 340 "Schnorr Signatures for secp256k1" (2020).

All terms · Questions & answers · The verifier