Add solution for 5i

This commit is contained in:
Tobias Eidelpes 2022-06-21 15:19:53 +02:00
parent 4f30ac9392
commit 41d6269347

View File

@ -292,7 +292,19 @@
\item \TODO \item \TODO
\item \TODO \item For completeness see 5e.
Special soundness: given two accepting transcripts for the same commitment
$\mathsf{trans} = (G',\mathsf{ch},\phi_{ch}^{-1}\psi)$ and $\mathsf{trans}'
= (G',\mathsf{ch'},\phi_{ch'}^{-1}\psi)$ we have \[ \psi =
\frac{\mathsf{resp}-\mathsf{resp}'}{\phi_{ch}^{-1}-\phi_{ch'}^{-1}} \] which
means that the witness can be extracted with probability 1.
For special HVZK: given $\mathsf{ch}\in\{0,\dots,2^{130}-1\}$ choose
$\mathsf{resp}\xleftarrow{\$}\mathcal{I}_{1107}$ and calculate
$G'\leftarrow\mathsf{resp}(G_{ch})$. The distributions of real transcripts
and simulated transcripts are the same. A given valid transcript occurs with
probability $1/2^{130}$.
\item \TODO \item \TODO