Grimoire describing full-chain membership proofs.
Since writing this grimoire, we have proven that the LRS scheme presented here is only optionally linkable: a dishonest signer who varies the blinding key while fixing the secret key can produce distinct public keys with distinct linkability tags. Under the FCMP instantiation, this lets a dishonest user undetectably evade the view-all keys in the CARROT key architecture. Several security claims in this document no longer hold as written. We release this draft as a matter of record and expect to revise it substantively. Each compiled version is labeled with a Unix timestamp; the current draft lives in the project's GitHub repository. Readers should compare the timestamp on their copy against the latest commit before relying on its contents. Readers should also expect a change-log describing all differences between drafts.
MIT