h, are hard-coded s.t. the discreet log between them is unknown and are used for generating keys, commitments and proofs.
scalaris an integer modulo the Ristretto group order
|G| = 2^252 + 27742317777372353535851937790883648493
hare globally available generator points,
vis the secret scalar value and
ris the blinding factor.
merlinto generate random challenge scalars, instantiated using Keccak-f at 128 bits security level, to convert interactive sigma protocols to non-interactive proofs.