English Chinese (Simplified)
Pedersen commitments are cryptographic algorithms that allow a prover to commit to a certain value without revealing it or being able to change it 佩德森承诺是一种密码算法,它允许验证者在不暴露或无法更改某个值的情况下提交该值。
["commitments", "commitment", "pedersen", "pedersen-commitment", "pedersen-commitments"]
The Basics 基础知识
Pedersen commitments are cryptographic algorithms that allow a prover to commit to a certain value without revealing it or being able to change it. 佩德森承诺是一种密码算法,它允许验证者在不暴露或无法更改某个值的情况下提交该值。
When you spend Monero, the value of the inputs that you are spending and the value of the outputs you are sending are encrypted and opaque to everyone except the recipient of each of those outputs. Pedersen commitments allow you to send Monero without revealing the value of the transactions. Pedersen commitments also make it possible for people to verify that transactions on the blockchain are valid and not creating Monero out of thin air. 当您使用门罗币时,您所花费的输入值和您发送的输出值,对每个人都是加密且不透明的,除了这些输出的接收者。佩德森承诺允许您在不透露交易金额的情况下发送门罗币。佩德森承诺还使人们能够验证区块链上的交易是有效的,而不是凭空创造门罗币。
What It Means 它意味着什么
As long as the encrypted output amounts created, which include an output for the recipient and a change output back to the sender, and the unencrypted transaction fee is equal to the sum of the inputs that are being spent, it is a legitimate transaction and can be confirmed to not be creating Monero out of thin air. 只要加密输出金额创建了,其中就包括一个输出给接收方和一个找零输出回到发送方,而未加密的交易费等于被支付的输入和,它是一个合法的交易,可以确认不是凭空创造门罗币。
Pedersen commitments mean that the sums can be verified as being equal, but the Monero value of each of the sums and the Monero value of the inputs and outputs individually are undeterminable. Pedersen commitments also mean that even the ratio of one input to another, or one output to another is undeterminable. 佩德森承诺意味着可以验证的和是相等的,但是每个和的门罗币数量以及个体的输入和输出的门罗币值是不确定的。佩德森承诺还意味着,即使是一种输入与另一种输入的比例,或者一种输出与另一种输出的比例,也是无法确定的。
It is unclear which inputs are really being spent as the ring signature lists both the real inputs being spent and decoy inputs, therefore you don't actually know which input Pedersen commitments need to be summed. That's okay, because the @RingCT ring signature only has to prove that for one combination of the inputs the outputs are equal to the sum of the inputs. For mathematical reasons, this is impossible to forge. 目前还不清楚哪些输入真正被使用,因为环签名列出了实际使用的输入和诱饵输入,因此您实际上并不知道需要对哪些输入佩德森承诺进行求和。这没关系,因为@环机密交易中,环签名只需要证明对于输入的一个组合,输出和等于输入和。由于数学上的原因,这是不可能伪造的。
In-depth Information 深度信息
See information in [Ring Confidential Transactions paper](https://eprint.iacr.org/2015/1098.pdf) by Shen Noether of the Monero Research Lab. 参见,门罗币研究实验室的 Shen Noether 撰写的[环机密交易论文](https://eprint.iacr.org/2015/1098.pdf)。