GRIN Papyrus - a collection of important GRIN documents since Day-0

Regarding the remark

from mimblewimble.txt, note that where Maxwell wanted the transaction excess to be an unblinded zero:

Noether required it to not to be:

And it’s easy to see how Jedusor was inspired by Noether’s

In Monero’s RingCT, the recipient blinding factor and hence this excess, is determined by the sender, while use of Diffie-Helmann allows for secure sharing with the receiver.

Jedusor’s insight was to instead let the receiver pick their own blinding factor, making the excess a 2-of-2 multiparty key shared by sender and receiver.

[4] https://eprint.iacr.org/2015/1098.pdf Shen Noether, Ring Confidential Transactions