http://clszzn47y57uwkrgnfc7wllalvodopzqrp4spb6zbz2t3ulxngcfqsad.onion/index.php?action=list_LISTSOMERESOURCES_CORE&method=metaKeywordProcess&mType=all&id=21
[Cryptology ePrint Archive, Report 2021/1240] Added by: Plowsof Last edited by: Plowsof 6/3/25, 8:06 PM Jeffro256 " IIUC, if this could be applied to Monero, then all the rings signatures in a block could be combined non-interactively for much better anonymity sets It even has a notion of key-images, although they call them "same-message linkable extendable ring signatures" " As far as I can tell this relies on size-linear constructions, which are less efficient than Grootle proofs.