The excess is in each payload. Why does the commitment need to be there also?
Under data provision of your design, the inner nodes j ∈ {2...n-1}
are to be provided with
- commitment Ci,j-1
- excess share xi,j
Since Ci,j-1 is actually calculated by node j-1
, I don’t understand why we would need for it to be part of the encrypted payload.