[PDF] Top 20 On Constant-Round Concurrent Zero-Knowledge from a Knowledge Assumption
Has 10000 "On Constant-Round Concurrent Zero-Knowledge from a Knowledge Assumption" found on our website. Below are the top 20 most common "On Constant-Round Concurrent Zero-Knowledge from a Knowledge Assumption".
On Constant-Round Concurrent Zero-Knowledge from a Knowledge Assumption
... of zero-knowledge proofs contemplated a single prover and a single verifier executing a single protocol session in ...isolation. Concurrent zero-knowledge [DNS98] (cZK) extends ... See full document
31
Statistical Concurrent Non-malleable Zero-knowledge from One-way Functions
... use. From a result shown in [GLP + 15], we can obtain a constant-round κ-robust one-one CCA-secure commitment scheme from one-way functions for every constant κ ∈ N as fol- ...scheme ... See full document
38
Round-Optimal Fully Black-Box Zero-Knowledge Arguments from One-Way Permutations
... the zero-knowledge to the hiding property of the commitments made by the ...different from those presented in [PW09] in that the verifier only reveals a subset of the challenges, where essentially ... See full document
22
Towards Non-Interactive Zero-Knowledge for NP from LWE
... linear assumption or symmetric external Diffie-Hellman assumption over bilinear groups [GOS12]) or from indistinguishability obfuscation [SW14, BP15] (see Section ...the assumption that ... See full document
34
Promise Zero Knowledge and its Applications to Round Optimal MPC
... switch from using real honest inputs (in an intermedi- ate hybrid) to random inputs on the look-ahead threads, the probability of extraction of adversary’s inputs and trapdoors remains ...switch from real ... See full document
79
Proving the correct execution of concurrent services in zero-knowledge
... We now describe a prior system that implements VSMs; our goal is to introduce concepts necessary to describe Spice and to highlight why prior systems are inefficient. We focus on Pantry [25]; Section 8 discusses other ... See full document
26
An Improved Security enabled Distribution of Protected Cloud Storage Services by Zero Knowledge Proof based on RSA Assumption
... a constant number of levels by using identity based broadcast encryption with key ...suffered from exponential degradation in the depth of the hierarchy, so these systems were only proven fully secure for ... See full document
5
An Efficiency-Preserving Transformation from Honest-Verifier Statistical Zero-Knowledge to Statistical Zero-Knowledge
... of zero-knowledge proofs, called instance- dependent zero-knowledge, and show that it suffices for the [8] approach when constructing a compiler from honest-verifier statistical ... See full document
23
Augmented Black-Box Simulation and Zero Knowledge Argument for NP
... all zero knowledge protocols are black-box zero ...bounded concurrent constant-round zero knowledge ar- gument for NP which was proved not to exist in black-box ... See full document
23
Concurrent Zero Knowledge in the Bounded Player Model
... of concurrent sessions are ...of concurrent sessions is bounded (even when there is a single identity), but instead our goal is to obtain unbounded concurrent zero ... See full document
26
A Transform for NIZK Almost as Efficient and General as the Fiat-Shamir Transform Without Programmable Random Oracles
... interactive constant-round public-coin honest-verifier zero-knowledge (HVZK) proof system and in making it a NIZK argument through the so called Fiat-Shamir (FS) transform ...indistinguishable ... See full document
30
Improved Zero-knowledge Proofs of Knowledge for the ISIS Problem, and Applications
... the knowledge extractor: The latter is only guaranteed to be O(n) e larger than the former in the case of the infinity norm, where n denotes the dimension of the corresponding worst-case lattice ...security ... See full document
14
Efficient Batch Zero-Knowledge Arguments for Low Degree Polynomials
... Zero Knowledge and ...efficient zero-knowledge ...first zero-knowledge argument for circuit-satisfiability with poly-logarithmic com- munication complexity, but with high ... See full document
28
Obfuscation-based Non-black-box Simulation and Four Message Concurrent Zero Knowledge for NP
... Our requirements from obfuscation are actually weaker than stated above. We do not need obfuscation for the class of all (polynomial size and running time) Turing machines; instead we only require the obfus- ... See full document
40
From Laconic Zero-Knowledge to Public-Key Cryptography
... To illustrate the techniques used, we sketch the proof of a slightly simplified ver- sion of Theorem 1.1. Specifically, we construct a PKE given a cryptographically hard language L with a single-round ... See full document
25
Efficient Statistical Zero-Knowledge Authentication Protocols for Smart Cards Secure Against Active & Concurrent Attacks
... Authentication protocols are ubiquitous in everyday computing. They are present when checking email, making monetary transactions, connecting to a mobile/wireless network, and so on. From one point of view, the ... See full document
39
Efficient Generic Zero-Knowledge Proofs from Commitments
... for Zero-knowledge are starting to ...for Zero-knowledge proofs of generic ...for Zero-knowledge ...small constant of bits by And gate (roughly ... See full document
33
Efficient Adaptively Secure Zero-knowledge from Garbled Circuits
... original constant-round 2PC protocol where the GC constructor has no input; this yields full malicious secu- rity at little overhead over the semi-honest case as Yao’s protocol in this case is already ... See full document
47
On the Existence of Three Round Zero-Knowledge Proofs
... In a private coin protocol, however, this notion of bad α’s does not work. In fact in a private coin protocol, for any α and any random tape, an accepting γ may always exist! Indeed, any three-round proof system ... See full document
31
Constant-Round Concurrent Zero-knowledge from Indistinguishability Obfuscation
... follows from the global proof of knowledge property of WIUA, that the witness of each WIUA is well-defined, therefore, we can refer to the machine M committed in Phase 1, the statement q committed in Phase ... See full document
33
Related subjects