Re: "Pay-to-Address" / "Pay-to-Public-Key": Non-Interactive Transaction Solution for Mimblewimble


dear Gary,

> 5. Alice calculates (q*P) and attach it to the transaction kernel as the restriction to spend its PTXO. ONLY who owns the private key of this public (q*P) can spend this PTXO.

> To summarize the difference of the transaction kernel between ITX and PTX, PTX has 3 additional fields which ITX doesn’t have:
> - (q*P): 33 bytes
> - v': 8 bytes
> - even/odd of R.y: 1 bit

In MW, after tx aggregation, there is no more visible relation between
the PTX kernel and output.
So how does your scheme prevent Alice from spending the output?


