• No results found

Fault-Tolerant Protocols and Zero-Knowledge Proofs

A  Certifying  Compiler  for  Zero-Knowledge  Proofs  of  Knowledge  Based  on $\Sigma$-Protocols

A Certifying Compiler for Zero-Knowledge Proofs of Knowledge Based on $\Sigma$-Protocols

... The reason for the verification toolbox only considering the verifier code is that by definition [17] the soundness of the protocol essentially concerns providing guarantees for the verifier, regardless of whether the ...

22

Bringing  Zero-Knowledge  Proofs  of  Knowledge  to  Practice

Bringing Zero-Knowledge Proofs of Knowledge to Practice

... The goal of our ongoing and future research is to bring ZK-PoK to practice by making them accessible to crypto and security engineers. To this end we are working on compilers and related tools that support and partially ...

12

Isolated  Proofs  of  Knowledge   and  Isolated  Zero  Knowledge

Isolated Proofs of Knowledge and Isolated Zero Knowledge

... `-isolated proofs of knowledge (`-IPoK), where the cheating prover is restricted to communicating only ` bits of information with the environment during the run of the ...our protocols only need to ...

33

Efficient Zero-Knowledge Proofs and Applications

Efficient Zero-Knowledge Proofs and Applications

... Abstract Zero-knowledge proofs provide a means for a prover to convince a verifier that some claim is true and nothing ...conveying zero information beyond their veracity has profound ...

203

Round-Optimal  Zero-Knowledge  Proofs  of  Knowledge  for  NP

Round-Optimal Zero-Knowledge Proofs of Knowledge for NP

... basic protocols cannot be proved to be ...the zero-knowledge property of n parallel repetitions of the basic protocol, such as in ...of knowledge, because the fact that the ver- ifier is ...

12

Computational  soundness  of  symbolic  zero-knowledge  proofs

Computational soundness of symbolic zero-knowledge proofs

... (non-interactive) zero-knowledge proof needs to fulfill in order to serve as a computa- tionally sound implementation of symbolic zero-knowledge ...symbolically-sound ...

64

Composition  of  Zero-Knowledge  Proofs  with  Efficient  Provers

Composition of Zero-Knowledge Proofs with Efficient Provers

... of zero-knowledge ...input zero knowledge still seems to be the appropriate one for most ...plain zero knowledge is closed under a super-constant number of ...arbitrary ...

19

On  the  Existence  of  Three  Round  Zero-Knowledge  Proofs

On the Existence of Three Round Zero-Knowledge Proofs

... The adversarial verifier’s code does not do anything intelligent on its own, and simply uses its auxiliary input aux to compute its protocol message. Ruling out Rewinding Simulators. The above strategy for hiding the ...

31

Zero-Knowledge Multi-Prover Interactive Proofs

Zero-Knowledge Multi-Prover Interactive Proofs

... isolating zero-knowledge protocols for MIP with only two provers to the ...single-prover zero-knowledge proofs, there is a sequential composition theorem which states that ...

50

Improved  Zero-knowledge  Proofs  of  Knowledge  for  the  ISIS  Problem,   and  Applications

Improved Zero-knowledge Proofs of Knowledge for the ISIS Problem, and Applications

... work: zero-knowledge proofs of plaintext knowledge (ZKPoPK) for Regev’s LWE-based cryptosystem ([Reg05, ...Computation protocols, via the [IKOS07] transformation from MPC to ...

14

Linear Zero-Knowledegde - A Note on Efficient Zero-Knowledge Proofs and Arguments

Linear Zero-Knowledegde - A Note on Efficient Zero-Knowledge Proofs and Arguments

... our protocols have the smallest known asymptotic communication complexity among general proofs or arguments for ...the protocols to be practical in a realistic situation: both protocols are ...

20

CONSENSUS PROTOCOLS Or: How to Implement Fault Tolerant Transactions

CONSENSUS PROTOCOLS Or: How to Implement Fault Tolerant Transactions

... Now, suppose one of the replicas interacts with a client, and the client performs an update operation as part of a transaction. The replica becomes a Proposer, finds the next unused index in his log, call it i, and sends ...

9

On  the  Amortized  Complexity  of  Zero-knowledge  Protocols

On the Amortized Complexity of Zero-knowledge Protocols

... of Zero-knowledge Protocols Ronald Cramer ? , Ivan Damg˚ ard ?? , and Marcel Keller ? ? ? CWI/Leiden University, Aarhus University, and University of Bristol ...of zero-knowledge ...

25

Efficient  Generic  Zero-Knowledge  Proofs  from  Commitments

Efficient Generic Zero-Knowledge Proofs from Commitments

... enables Zero-knowledge proofs of linear ...efficient protocols for proving equality and inequality of bits in a string given two regular commitments to the Xor sharing of that ...build ...

33

Non-Interactive  Zero-Knowledge  Proofs  for  Composite  Statements

Non-Interactive Zero-Knowledge Proofs for Composite Statements

... • Proof of addition of committed elliptic curve points. We show efficient techniques for prov- ing knowledge of two committed elliptic curve points P, Q such that T = P + Q for a public point T . To do so, we ...

42

Non-Interactive  Zero-Knowledge  Proofs  of  Non-Membership

Non-Interactive Zero-Knowledge Proofs of Non-Membership

... BPV12. Olivier Blazy, David Pointcheval, and Damien Vergnaud. Round-optimal privacy-preserving protocols with smooth projective hash functions. In Ronald Cramer, editor, TCC 2012: 9th Theory of Cryptography ...

18

Compact  Zero-Knowledge  Proofs  of  Small  Hamming  Weight

Compact Zero-Knowledge Proofs of Small Hamming Weight

... In [1], Adida and Wikstr¨ om presented a new approach to this problem: They show how to construct an obfuscated program for shuffling a set of n ciphertexts. The obfuscatd program P π depends on a permutation π on n ...

31

Efficient  Delegation  of  Zero-Knowledge  Proofs  of  Knowledge  in  a  Pairing-Friendly  Setting

Efficient Delegation of Zero-Knowledge Proofs of Knowledge in a Pairing-Friendly Setting

... Shamir, zero-knowledge proofs have played a significant role in modern cryptography: they allow a party to convince another party of the validity of a statement (proof of membership) or of its ...

13

On  the  Implausibility  of  Constant-Round  Public-Coin  Zero-Knowledge  Proofs

On the Implausibility of Constant-Round Public-Coin Zero-Knowledge Proofs

... our knowledge, all constructions of ZK proofs in the literature are of this ...ZK proofs (which we call “canonical,” as all known ZK protocols fall in this category), a universal simulator for ...

23

Threshold  Decryption   and  Zero-Knowledge  Proofs  for  Lattice-Based  Cryptosystems

Threshold Decryption and Zero-Knowledge Proofs for Lattice-Based Cryptosystems

... a zero-knowledge protocol for proving knowledge of the plaintext contained in a given ciphertext, for Regev’s original cryptosystem as well as our ...of zero- knowledge from multiparty ...

19

Show all 10000 documents...

Related subjects