[PDF] Top 20 RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations
Has 10000 "RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations" found on our website. Below are the top 20 most common "RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations".
RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations
... It is also important to mention the contributions of Benhamouda et al. [3] and Baum et al. [2], who generalized the commitment idea of [26] without using Stern’s approach. They instead use Fiat-Shamir with aborts, a ... See full document
30
ZKPDL: A Language-Based System for Efficient Zero-Knowledge Proofs and Electronic Cash
... is zero-knowledge proofs [47, 46, 17, 39], which provide a way of proving that a statement is true without re- vealing anything beyond the validity of the ...of zero-knowledge ... See full document
16
Lattice-Based Zero-Knowledge Arguments for Integer Relations
... quadratic relations [43], we manage to prove that the bits of X, Y, Z satisfy the above equations modulo 2, which is equivalent to X + Y = Z over Z ...a linear equation modulo ...additive relations ... See full document
34
Efficient Generic Zero-Knowledge Proofs from Commitments
... a linear code like Reed Solomon which can be done efficiently using the ...enables Zero-knowledge proofs of linear ...has knowledge of a witness w that satisfies the ... See full document
33
Relaxed Lattice-Based Signatures with Short Zero-Knowledge Proofs
... lattice- based group signatures that combines signature schemes (usually variants of Boyen’s signature [Boy10] or B¨ ohl signature [BHJ + 15]) with non-interactive zero-knowledge (NIZK) protocols, ... See full document
50
Compact Zero-Knowledge Proofs of Small Hamming Weight
... protocol based on a ‘gate scrambling’ ...and linear gates can be evaluated without ...phase based on TinyOT [35], but for larger tables (such as representations of the S-boxes in 3-DES or AES) this ... See full document
31
Efficient Designated-Verifier Non-Interactive Zero-Knowledge Proofs of Knowledge
... for multiplicative relation between Paillier ciphertext was first introduced in ...our knowledge, this is the most efficient currently known method for proving such statements non-interactively: all ... See full document
34
Sub-Linear Lattice-Based Zero-Knowledge Arguments for Arithmetic Circuits
... creating zero-knowledge proofs is the “Fiat-Shamir with Aborts” approach [Lyu09, Gro10b, ...of knowledge of a vector ¯ s with small coefficients (though larger than those in s) and a ring ... See full document
43
Lattice-Based Group Signatures and Zero-Knowledge Proofs of Automorphism Stability
... To demonstrate the practicality of our group signature scheme, we have implemented it in C. On a laptop with an Intel Skylake i7 processor, the implementation needs 428.7 ms to generate a group public key and one member ... See full document
37
Non-Interactive Zero-Knowledge Proofs for Composite Statements
... as knowledge of discrete-log in a cyclic group by representing the exponentiation circuit as a ...zk-SNARKs based on QAP, the prover cost is linear in the size of circuit and an honestly generated ... See full document
42
Nearly Linear-Time Zero-Knowledge Proofs for Correct Program Execution
... Kilian’s zero-knowledge argument relies on probablistically checkable proofs [AS98], which are still complex for practical use, but the invention of inter- active oracle proofs [BCS16] have ... See full document
75
Commitments and Efficient Zero-Knowledge Proofs from Learning Parity with Noise
... a zero-knowledge proof of knowledge is a two party protocol between a prover P and a verifier V which allows the former to convince the latter that it knows some secret piece of information without ... See full document
22
Leakage-Resilient Identification Schemes from Zero-Knowledge Proofs of Storage
... The witness indistinguishability property of the Sigma protocol is enough to derive the zero- knowledge property of the PoS. Witness indistinguishability means that the distributions of the transcript for ... See full document
21
Non-interactive zero-knowledge proofs in the quantum random oracle model
... the zero-knowledge property. Zero-knowledge means that an adversary cannot distinguish between real proofs and proofs produced by a simulator (that has no access to the ... See full document
26
Zero-Knowledge Proofs with Low Amortized Communication from Lattice Assumptions
... get coin-flipping among the players for free because the (honest) Verifier can simply provide the random value. Therefore, the communication cost of coin-flipping for a value is simply the size of the value. We will use ... See full document
23
On the Implausibility of Constant-Round Public-Coin Zero-Knowledge Proofs
... public-coin zero-knowledge (ZK) ...ZK proofs that admit a universal simulator (which handles all malicious verifiers), and show a connection between the existence of such proof systems and a ... See full document
23
Privacy-Preserving Multi-Party Reconciliation Secure in the Malicious Model (Extended version)
... are based on the semantically secure, additively homomorphic Pail- lier cryptosystem [33] and a series of non-interactive zero-knowledge proofs to provide veriable set ...homomorphic ... See full document
22
C$\emptyset$C$\emptyset$: A Framework for Building Composable Zero-Knowledge Proofs
... The hardness of discrete-log in extension fields has been studied for quite some time; recently quasi- polynomial time algorithms [40,57] have been designed for the special case of fixed-sized, i.e., small, ... See full document
53
Security and Efficiency Analysis of The Hamming Distance Computation Protocol Based On Oblivious Transfer
... knowledge of ` is capable of manipulating HD as it is easy to find g and h using above equation. This is interesting because of the following result: The authors in [41] propose a privacy- preserving protocol for ... See full document
10
Zero-Knowledge Protocols for Search Problems
... the zero-knowledge property (as in definition 11) is denoted by ZP − Search − ZK (as usual, ZK is replaced by CZK , SZK and P ZK depending on the quality of ... See full document
32
Related subjects