From 41d6269347ad7f50c8c8568d7085c545e6254271 Mon Sep 17 00:00:00 2001 From: Tobias Eidelpes Date: Tue, 21 Jun 2022 15:19:53 +0200 Subject: [PATCH] Add solution for 5i --- exam/ex.tex | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/exam/ex.tex b/exam/ex.tex index 80afcaf..93f3ce5 100644 --- a/exam/ex.tex +++ b/exam/ex.tex @@ -292,7 +292,19 @@ \item \TODO - \item \TODO + \item For completeness see 5e. + + Special soundness: given two accepting transcripts for the same commitment + $\mathsf{trans} = (G',\mathsf{ch},\phi_{ch}^{-1}\psi)$ and $\mathsf{trans}' + = (G',\mathsf{ch'},\phi_{ch'}^{-1}\psi)$ we have \[ \psi = + \frac{\mathsf{resp}-\mathsf{resp}'}{\phi_{ch}^{-1}-\phi_{ch'}^{-1}} \] which + means that the witness can be extracted with probability 1. + + For special HVZK: given $\mathsf{ch}\in\{0,\dots,2^{130}-1\}$ choose + $\mathsf{resp}\xleftarrow{\$}\mathcal{I}_{1107}$ and calculate + $G'\leftarrow\mathsf{resp}(G_{ch})$. The distributions of real transcripts + and simulated transcripts are the same. A given valid transcript occurs with + probability $1/2^{130}$. \item \TODO