Thanks. Yes, that's mostly correct. A few minor notes:
You don't necessarily need to use the same PQ key $Q$ for publishing the "timestamp" (commitment) transaction.
You (the wallet user) don't need to publish the commitment transaction - you can delegate that to an untrusted 3rd party: an "aggregator", who publishes a merkle tree that merges many users' commitments together, a la opentimestamps.
hehe sorry, the miner incentives game-theory appendix at the end was rather long-winded, but necessary if i wanted to argue security. Otherwise one could claim the scheme is broken by just saying "Miners will collude"
Thanks. Yes, that's mostly correct. A few minor notes:
hehe sorry, the miner incentives game-theory appendix at the end was rather long-winded, but necessary if i wanted to argue security. Otherwise one could claim the scheme is broken by just saying "Miners will collude"