Hi NTL,
One property of this construction that isn't in the Motivation or
Security sections, and which I think is worth stating: it makes
script-path-only Taproot outputs *provably* so after the fact, to
anyone handed the policy -- and that has a post-quantum use.
Under current rules a CRQC that solves Q can key-path spend any P2TR
output regardless of how Q was built; on-chain, a tweaked NUMS key
and a bare untweaked key are indistinguishable. So for rescue
mechanisms of the shape "prove the key path was never spendable,
then recover via script path", the question is whether the holder
can produce evidence the attacker cannot. With an ad-hoc r the
holder can show r, but a rescue rule can't specify one uniform
verification, and r is one more thing to have kept. With this BIP
the evidence is the policy itself: recompute the chain code, derive
the internal key from H, rebuild Q. The attacker holds q but not the
policy, so cannot produce it. Your Security section already notes
that anyone can verify derivation from H; the PQ angle is that the
*policy* becomes the secret whose knowledge a rescue rule can demand.
The versioned tag leaves room for such a rule to pin a version. It
may be worth a sentence in Motivation, since it is a reason to adopt
beyond interoperability.
This came up in the exposure-classification thread [1], where
conduition raised holder-provability for P2TR; the two pieces of
work look complementary.
duncan0k
[1]
https://gnusha.org/pi/bitcoindev/010001a06dd4cdd9-b8082042-8750...@email.amazonses.com/