But doesn’t the ECDH share a⋅Bscan differ for each output with a silent payment code, i.e. a different Bscan? What I meant was this proof needs to be computed and attached for each silent payment code, i.e. each output, so there would be input * output many proofs in worst case where each input has a unique signer and each output has a unique Bscan.