论文部分内容阅读
∑协议,又称为诚实验证者的特殊零知识证明,是一种非常强大的密码工具,被广泛应用于协议的设计。基于∑协议的OR合成是非常有趣和有效的技巧,特别是应用于构造那些具备不可区分性性质的实例时。理论上讲,不论其基本的∑协议是怎样的我们都能构造有效的OR合成。现有的基于∑协议的OR合成都是对称的,也就是说,协议中的两方都具有相同的形式。是否能实际地构造非对称的(我们称之为混合的)OR合成?论文描述了这个问题,并给出肯定的答案。同时,构造出一个具体实例子,并给出一些关于参数选取的注记。
Σ protocol, also known as the honesty verifier’s special zero-knowledge proof, is a very powerful cryptographic tool widely used in the design of protocols. OR synthesis based on the Σ protocol is a very interesting and effective technique, especially when it comes to constructing instances that have indistinguishable properties. In theory, we can construct efficient OR synthesis regardless of its basic Σ-protocol. The existing OR synthesis based on the Σ-protocol is symmetrical, that is, both parties in the protocol have the same form. Is it possible to actually construct an asymmetric (what we call mixed) OR synthesis? The paper describes the problem and gives a positive answer. At the same time, construct a concrete example, and give some annotation on parameter selection.