One of the big improvements is that multi-signature transactions, where both Alice and Bob have to sign to spend some money, used to require adding N signatures (number of signers) to the block chain to have a valid transaction. So it improves efficiency and should allow squeezing more transactions, but it also improves privacy, because there's no way to tell if how many parties are involved in the transaction.
Merkelised Abstract Syntax Tree (MAST) are the other big feature that allows for more complex scripting to also be represented in a compressed and obfuscated way (example in the link).
See the full implementation here by Delft University of Technology scientists and students. [1] Security needs work, functionality works. (disclaimer, I'm the responsibile professor)
[1] https://github.com/Tribler/trustchain-superapp#luxury-commun...
If accepted by the miners, Bitcoin will a bunch of low-level upgrades:
- more compact signatures (decrease blockchain size)
- paves the way to smart contract
- improve transaction privacy
https://bitcoinmagazine.com/technical/taproot-coming-what-it...Usually the rule is just "provide a digital signature with key X", or some threshold of keys. Though they can be more much complicated, and even simple scripts can have powerful applications (e.g. https://bitcoincore.org/en/2016/02/26/zero-knowledge-conting... )
The flexibility is nice but there are some gotchas-- Your rules are included in the transaction, storing and transmitting expends system resources, costs you fees, distinguishes your transactions from other users, and in doing so discloses information about your business practices.
Taproot addresses this by doing some relatively simple elliptic curve crypto magic to effectively hide the conditions inside a public key without impairing it or making it larger. Then, if the parties transacting cooperate they can keep their fancy conditions private and just sign using a single jointly controlled key. If the parties don't cooperate some of the conditions may need to be exposed, but only the absolute minimum to show the transaction is allowable. Cooperation is likely however, because non-cooperating won't create a benefit.
The effect is that instead of being limited to a few thousand bytes of operations for the rules governing your coin, you could have gigabytes of rules, and yet never expose them (and burn network resources and your privacy) -- or if you do need to to expose some of them, you only need to show a small amount. ... and as a bonus have your transactions look just like a really boring maximally simple wallet's transactions.
There are also some small efficiency gains: somewhat smaller signatures and making batch signature validation possible.
It's a little difficult to estimate the impact this improvement will have: Most users only use relatively simple rules, and as a result they will just become a little more private and a little more efficient. But if taproot was marketed like most altcoins are the headline would be "Taproot increases script expressiveness FORTY ORDERS OF MAGNITUDE while reducing resource usage!", because-- indeed-- you could make a script that was 1.3e41 times larger than the current rules allow if only you had a computer powerful enough to handle such data locally. :P So for common uses it's a small to moderate efficiency and privacy improvement, but it could enable some new and interesting applications.
... and you might not ever know about some application that benefited from it, because unless you're a party to its transactions there may be nothing identifying published about them. :) Not the best for marketing, but better for human rights.
Question though: why is it called Taproot?
One is that if you imagine the probability-of-usage weighed tree over the DNF form of your script, taproot is most efficient and private if most the probability mass is clustered along a central path-- like a botanical taproot-- particularly the "all participants agree" case that almost always exists.
The other when you spend using one of the hidden scripts, you tap into the public key to expose a hash tree root hash.
But really, the name exists because easier to talk about stuff when you have a name for it, the idea long predates having a formal spec for the construction, and taproot was the name I picked. Today we could also call it BIP341.
If I have e.g. a 1GB script, how much of it will I need to reveal if my counterparty doesn’t cooperate?
For example, is it realistic to have 1GB of script and only needing to reveal, say, 1KB in case the other party doesn’t cooperate?
So, for example, if you create a coin which could be spent by any Californian (assuming you knew a key for each), your full script would be 1.17 GB, but when someone spends the coin their signature would be 896 bytes, assuming you set it up to be equally efficient for all people. That 896 bytes plus the 32 byte public key would be all that ever hits the blockchain.
You're not constrained to assume equal-probablity however: if you have a probability model for how likely each condition is you can construct a huffman tree and the overhead for any particular condition is just the number of bits in its huffman codeword times 32 bytes. If your probabilities are accurate this will minimize the average size.
So for example, say your directory had a list of 100 known bitcoiners that were overwhelmingly likely to spend the coin their signature could be 288 bytes, while being just a bit larger for the other residents. If you, correctly, assumed that I would be the most likely to spend the coin you could stick my key at the root and I could spend it with just 64 bytes -- the same as an ordinary wallet controlled by one person rather than controlled by 40 million people.
For some usages there is a key creation vs spending size tradeoff-- e.g. you can expand the tree further to make the revealed nodes smaller, at a cost of an exponential blowup in the time it takes you to construct the script.
One thing that some protocols should be able to do (at least eventually) is set things up so that in the event of non-cooperation the additional transaction fees get mostly covered by the non-cooperating party.
This sounds amazing. I’m really looking forward to seeing what can be built on top of Bitcoin if this activates.
Semi-off topic: In another comment you said you're no longer developing BTC, what on earth could be more appealing right now?