Add solution for 5i
This commit is contained in:
parent
4f30ac9392
commit
41d6269347
14
exam/ex.tex
14
exam/ex.tex
@ -292,7 +292,19 @@
|
|||||||
|
|
||||||
\item \TODO
|
\item \TODO
|
||||||
|
|
||||||
\item \TODO
|
\item For completeness see 5e.
|
||||||
|
|
||||||
|
Special soundness: given two accepting transcripts for the same commitment
|
||||||
|
$\mathsf{trans} = (G',\mathsf{ch},\phi_{ch}^{-1}\psi)$ and $\mathsf{trans}'
|
||||||
|
= (G',\mathsf{ch'},\phi_{ch'}^{-1}\psi)$ we have \[ \psi =
|
||||||
|
\frac{\mathsf{resp}-\mathsf{resp}'}{\phi_{ch}^{-1}-\phi_{ch'}^{-1}} \] which
|
||||||
|
means that the witness can be extracted with probability 1.
|
||||||
|
|
||||||
|
For special HVZK: given $\mathsf{ch}\in\{0,\dots,2^{130}-1\}$ choose
|
||||||
|
$\mathsf{resp}\xleftarrow{\$}\mathcal{I}_{1107}$ and calculate
|
||||||
|
$G'\leftarrow\mathsf{resp}(G_{ch})$. The distributions of real transcripts
|
||||||
|
and simulated transcripts are the same. A given valid transcript occurs with
|
||||||
|
probability $1/2^{130}$.
|
||||||
|
|
||||||
\item \TODO
|
\item \TODO
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user