> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/online-courses/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/online-courses/blockchain-security/beyond-the-basics/advanced-cryptography-in-blockchain/commitment-schemes.md).

# Commitment schemes

A commitment "locks in" the value of data while keeping it secret. Hash functions are good for this: `C = H(nonce+data)`

A Pedersen commitment is an additively homomorphic commitment:

* `C(B1,d1) + C(B2,d2) = C(B1+B2,d1+d2)`

Pedersen commitments can be implemented using ECC:

* Choose a second generator `H = point(Hash(G))`
* `C = xG + aH`, where `x` is private key and `a` is data being committed
