• No results found

[PDF] Top 20 RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations

Has 10000 "RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations" found on our website. Below are the top 20 most common "RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations".

RLWE-based  Zero-Knowledge  Proofs  for  linear   and  multiplicative  relations

RLWE-based Zero-Knowledge Proofs for linear and multiplicative relations

... It is also important to mention the contributions of Benhamouda et al. [3] and Baum et al. [2], who generalized the commitment idea of [26] without using Stern’s approach. They instead use Fiat-Shamir with aborts, a ... See full document

30

ZKPDL:  A  Language-Based  System  for  Efficient  Zero-Knowledge  Proofs   and  Electronic  Cash

ZKPDL: A Language-Based System for Efficient Zero-Knowledge Proofs and Electronic Cash

... is zero-knowledge proofs [47, 46, 17, 39], which provide a way of proving that a statement is true without re- vealing anything beyond the validity of the ...of zero-knowledge ... See full document

16

Lattice-Based  Zero-Knowledge  Arguments  for  Integer  Relations

Lattice-Based Zero-Knowledge Arguments for Integer Relations

... quadratic relations [43], we manage to prove that the bits of X, Y, Z satisfy the above equations modulo 2, which is equivalent to X + Y = Z over Z ...a linear equation modulo ...additive relations ... See full document

34

Efficient  Generic  Zero-Knowledge  Proofs  from  Commitments

Efficient Generic Zero-Knowledge Proofs from Commitments

... a linear code like Reed Solomon which can be done efficiently using the ...enables Zero-knowledge proofs of linear ...has knowledge of a witness w that satisfies the ... See full document

33

Relaxed  Lattice-Based  Signatures  with  Short  Zero-Knowledge  Proofs

Relaxed Lattice-Based Signatures with Short Zero-Knowledge Proofs

... lattice- based group signatures that combines signature schemes (usually variants of Boyen’s signature [Boy10] or B¨ ohl signature [BHJ + 15]) with non-interactive zero-knowledge (NIZK) protocols, ... See full document

50

Compact  Zero-Knowledge  Proofs  of  Small  Hamming  Weight

Compact Zero-Knowledge Proofs of Small Hamming Weight

... protocol based on a ‘gate scrambling’ ...and linear gates can be evaluated without ...phase based on TinyOT [35], but for larger tables (such as representations of the S-boxes in 3-DES or AES) this ... See full document

31

Efficient  Designated-Verifier  Non-Interactive  Zero-Knowledge  Proofs  of  Knowledge

Efficient Designated-Verifier Non-Interactive Zero-Knowledge Proofs of Knowledge

... for multiplicative relation between Paillier ciphertext was first introduced in ...our knowledge, this is the most efficient currently known method for proving such statements non-interactively: all ... See full document

34

Sub-Linear  Lattice-Based  Zero-Knowledge  Arguments  for  Arithmetic  Circuits

Sub-Linear Lattice-Based Zero-Knowledge Arguments for Arithmetic Circuits

... creating zero-knowledge proofs is the “Fiat-Shamir with Aborts” approach [Lyu09, Gro10b, ...of knowledge of a vector ¯ s with small coefficients (though larger than those in s) and a ring ... See full document

43

Lattice-Based  Group  Signatures   and  Zero-Knowledge  Proofs  of  Automorphism  Stability

Lattice-Based Group Signatures and Zero-Knowledge Proofs of Automorphism Stability

... To demonstrate the practicality of our group signature scheme, we have implemented it in C. On a laptop with an Intel Skylake i7 processor, the implementation needs 428.7 ms to generate a group public key and one member ... See full document

37

Non-Interactive  Zero-Knowledge  Proofs  for  Composite  Statements

Non-Interactive Zero-Knowledge Proofs for Composite Statements

... as knowledge of discrete-log in a cyclic group by representing the exponentiation circuit as a ...zk-SNARKs based on QAP, the prover cost is linear in the size of circuit and an honestly generated ... See full document

42

Nearly  Linear-Time  Zero-Knowledge  Proofs  for  Correct  Program  Execution

Nearly Linear-Time Zero-Knowledge Proofs for Correct Program Execution

... Kilian’s zero-knowledge argument relies on probablistically checkable proofs [AS98], which are still complex for practical use, but the invention of inter- active oracle proofs [BCS16] have ... See full document

75

Commitments   and  Efficient  Zero-Knowledge  Proofs  from  Learning  Parity  with  Noise

Commitments and Efficient Zero-Knowledge Proofs from Learning Parity with Noise

... a zero-knowledge proof of knowledge is a two party protocol between a prover P and a verifier V which allows the former to convince the latter that it knows some secret piece of information without ... See full document

22

Leakage-Resilient  Identification  Schemes  from  Zero-Knowledge  Proofs  of  Storage

Leakage-Resilient Identification Schemes from Zero-Knowledge Proofs of Storage

... The witness indistinguishability property of the Sigma protocol is enough to derive the zero- knowledge property of the PoS. Witness indistinguishability means that the distributions of the transcript for ... See full document

21

Non-interactive  zero-knowledge  proofs  in  the  quantum  random  oracle  model

Non-interactive zero-knowledge proofs in the quantum random oracle model

... the zero-knowledge property. Zero-knowledge means that an adversary cannot distinguish between real proofs and proofs produced by a simulator (that has no access to the ... See full document

26

Zero-Knowledge  Proofs  with  Low  Amortized  Communication  from  Lattice  Assumptions

Zero-Knowledge Proofs with Low Amortized Communication from Lattice Assumptions

... get coin-flipping among the players for free because the (honest) Verifier can simply provide the random value. Therefore, the communication cost of coin-flipping for a value is simply the size of the value. We will use ... See full document

23

On  the  Implausibility  of  Constant-Round  Public-Coin  Zero-Knowledge  Proofs

On the Implausibility of Constant-Round Public-Coin Zero-Knowledge Proofs

... public-coin zero-knowledge (ZK) ...ZK proofs that admit a universal simulator (which handles all malicious verifiers), and show a connection between the existence of such proof systems and a ... See full document

23

Privacy-Preserving  Multi-Party  Reconciliation  Secure  in  the  Malicious  Model (Extended  version)

Privacy-Preserving Multi-Party Reconciliation Secure in the Malicious Model (Extended version)

... are based on the semantically secure, additively homomorphic Pail- lier cryptosystem [33] and a series of non-interactive zero-knowledge proofs to provide veriable set ...homomorphic ... See full document

22

C$\emptyset$C$\emptyset$:  A  Framework  for  Building  Composable  Zero-Knowledge  Proofs

C$\emptyset$C$\emptyset$: A Framework for Building Composable Zero-Knowledge Proofs

... The hardness of discrete-log in extension fields has been studied for quite some time; recently quasi- polynomial time algorithms [40,57] have been designed for the special case of fixed-sized, i.e., small, ... See full document

53

Security   and  Efficiency  Analysis  of  The  Hamming  Distance  Computation  Protocol  Based  On  Oblivious  Transfer

Security and Efficiency Analysis of The Hamming Distance Computation Protocol Based On Oblivious Transfer

... knowledge of ` is capable of manipulating HD as it is easy to find g and h using above equation. This is interesting because of the following result: The authors in [41] propose a privacy- preserving protocol for ... See full document

10

Zero-Knowledge  Protocols  for  Search  Problems

Zero-Knowledge Protocols for Search Problems

... the zero-knowledge property (as in definition 11) is denoted by ZP − Search − ZK (as usual, ZK is replaced by CZK , SZK and P ZK depending on the quality of ... See full document

32

Show all 10000 documents...