• No results found

Flawed NIZK Zero-Knowledge and Non-Deniability

Non-Interactive  Zero-Knowledge  Proofs  of  Non-Membership

Non-Interactive Zero-Knowledge Proofs of Non-Membership

... introduced zero-knowledge proofs with witness elimination which enable to prove that a committed message m belongs to a set L in such a way that the verifier accepts the interaction only if m does not ...

18

Perfect  Non-Interactive  Zero  Knowledge  for  NP

Perfect Non-Interactive Zero Knowledge for NP

... S IMULATING CORRUPTION . Suppose a simulated party P i is corrupted by A. Then we have to simulate the transcript of P i . We start by corrupting P ˜ i thereby learning all UC NIZK arguments it has verified. It is ...

24

Towards  Non-Interactive  Zero-Knowledge  for  NP  from  LWE

Towards Non-Interactive Zero-Knowledge for NP from LWE

... obtain NIZK proof systems for NP from a variety of parameter ...a NIZK proof system for dBDD α,γ where α and γ are polynomial in the security parameter, we can instantiate Theorem 1 even assuming LWE with a ...

34

Non-interactive  zero-knowledge  proofs  in  the  quantum  random  oracle  model

Non-interactive zero-knowledge proofs in the quantum random oracle model

... as a way of strengthening a specific kind of NIZK proofs to become multi-theorem adaptive ones. 15 (Actually, seen like this, their construction becomes a very natural one: the statement is hashed using the random ...

26

A  Note  On  Groth-Ostrovsky-Sahai  Non-Interactive   Zero-Knowledge  Proof  System

A Note On Groth-Ostrovsky-Sahai Non-Interactive Zero-Knowledge Proof System

... Groth-Ostrovsky-Sahai Non-Interactive Zero-Knowledge Proof System Zhengjun Cao 1 , Lihua Liu 2,∗ ...one non-interactive zero-knowledge (NIZK) proof system [new version, ...

6

Sub-linear  Size  Pairing-based  Non-interactive  Zero-Knowledge  Arguments

Sub-linear Size Pairing-based Non-interactive Zero-Knowledge Arguments

... an NIZK argument being ...perfect zero-knowledge variants of Groth, Ostrovsky and Sahai’s [GOS06b,GOS06a] NIZK arguments are ...using NIZK arguments with co-soundness, the adversary is ...

29

A  More  Efficient  Computationally  Sound  Non-Interactive  Zero-Knowledge  Shuffle  Argument

A More Efficient Computationally Sound Non-Interactive Zero-Knowledge Shuffle Argument

... Shorter CRS. In App. D, we show that one can transform both the Groth-Lu argument and the new argument, by using the Clos network [Clo53,DT04], to have a CRS of size Θ( √ n) while increasing the communication and ...

21

Minimizing  Non-interactive  Zero-Knowledge  Proofs  Using  Fully  Homomorphic  Encryption

Minimizing Non-interactive Zero-Knowledge Proofs Using Fully Homomorphic Encryption

... composable NIZK proof for ...F NIZK R in the F NIZK R F -hybrid ...F NIZK R running with dummy parties ˜ P 1 , ...F NIZK R in various ...F NIZK R takes full control over F ...

14

On  QA-NIZK  in  the  BPK  Model

On QA-NIZK in the BPK Model

... auxiliary-string non-black-box [21,42] (the simulator may use the code of the adversary, who has access to an arbitrary auxiliary string) NIZK is impossible in the BPK ...succinct non-interactive ...

30

Progression-Free  Sets   and  Sublinear  Pairing-Based  Non-Interactive  Zero-Knowledge  Arguments

Progression-Free Sets and Sublinear Pairing-Based Non-Interactive Zero-Knowledge Arguments

... Table 1. Comparison of NIZK Circuit-SAT arguments with (worst-case) sublinear argument size. Note that the summary length of the CRS and the argument corresponds to the zap length. |C| is the size of circuit, G ...

25

Concurrent non-malleable zero-knowledge and simultaneous resettable non-malleable zero-knowledge in constant rounds

Concurrent non-malleable zero-knowledge and simultaneous resettable non-malleable zero-knowledge in constant rounds

... More specifically, the commitment scheme we use has a salient feature, i.e., its security can be guaranteed even the adversaries have access to the committed-value ora- cle in the right. This advantage brings us the ...

15

Concurrent  Non-Malleable  Zero  Knowledge

Concurrent Non-Malleable Zero Knowledge

... a zero-knowledge proof of the statement X to Bob, and at the same time Bob is trying to give a zero-knowledge proof of some other statement X’ to ...of zero-knowledge tells us ...

28

Efficient  Designated-Verifier  Non-Interactive  Zero-Knowledge  Proofs  of  Knowledge

Efficient Designated-Verifier Non-Interactive Zero-Knowledge Proofs of Knowledge

... of Knowledge Pyrros Chaidos ? and Geoffroy Couteau ?? ...designated-verifier non-interactive zero-knowledge proofs (DVNIZK) for a wide class of algebraic languages over abelian groups, under ...

34

Zero  Knowledge  with   Rubik's  Cubes   and  Non-Abelian  Groups

Zero Knowledge with Rubik's Cubes and Non-Abelian Groups

... words: Zero-Knowledge, Rubik’s cube, authentication, symmet- ric group, cryptographic protocol, NP-completude 1 Introduction The puzzles based on the Rubik’s cube meet a great ...

17

Black-Box  Non-Black-Box  Zero  Knowledge

Black-Box Non-Black-Box Zero Knowledge

... Since in generalized proofs of set membership a verifier can query an element i ∈ 2 poly(n) for any polynomial poly chosen by the verifier, with the extendable Merkle tree in hands, one can think that this problem is ...

73

One-Message  Zero  Knowledge   and  Non-Malleable  Commitments

One-Message Zero Knowledge and Non-Malleable Commitments

... same-tag non-malleable ...concurrent non-malleability. Finally, we provide new candidate 4-tag non-malleable commitments ...construct non-malleable commitments for constant number of ...

59

Non-Interactive  Zero-Knowledge  Proofs  for  Composite  Statements

Non-Interactive Zero-Knowledge Proofs for Composite Statements

... • Proof of addition of committed elliptic curve points. We show efficient techniques for prov- ing knowledge of two committed elliptic curve points P, Q such that T = P + Q for a public point T . To do so, we ...

42

Lower  Bounds  for  Non-Black-Box  Zero  Knowledge

Lower Bounds for Non-Black-Box Zero Knowledge

... Claim 8.8. Under the assumptions of Theorem 8.1, the k(n)-times parallel composition of Proto- col 8.4 is a strong argument of knowledge, with soundness error s(n) = 2 −k(n) . Proof. Let P ∗ be any polynomial-time ...

71

Adaptive  Security  of  Concurrent  Non-Malleable  Zero-Knowledge

Adaptive Security of Concurrent Non-Malleable Zero-Knowledge

... the zero-knowledge proof in Stage 6 just as the simulator S does (H 4 i:2 uses Com 0 of AIDCom to generate commitments to the adjacency matrix of the permutated ...the zero-knowledge ...the ...

36

Succinct  Non-Interactive  Zero  Knowledge  for  a  von  Neumann  Architecture

Succinct Non-Interactive Zero Knowledge for a von Neumann Architecture

... of non-zero polynomials in A, ~ ~ B, ~ C is only about 52%, 15%, 71% ...to zero can be used towards reducing the size of pk, by switching from a dense representation to a sparse ...

37

Show all 10000 documents...

Related subjects