Add solution for 5i
This commit is contained in:
parent
4f30ac9392
commit
41d6269347
14
exam/ex.tex
14
exam/ex.tex
@ -292,7 +292,19 @@
|
||||
|
||||
\item \TODO
|
||||
|
||||
\item \TODO
|
||||
\item For completeness see 5e.
|
||||
|
||||
Special soundness: given two accepting transcripts for the same commitment
|
||||
$\mathsf{trans} = (G',\mathsf{ch},\phi_{ch}^{-1}\psi)$ and $\mathsf{trans}'
|
||||
= (G',\mathsf{ch'},\phi_{ch'}^{-1}\psi)$ we have \[ \psi =
|
||||
\frac{\mathsf{resp}-\mathsf{resp}'}{\phi_{ch}^{-1}-\phi_{ch'}^{-1}} \] which
|
||||
means that the witness can be extracted with probability 1.
|
||||
|
||||
For special HVZK: given $\mathsf{ch}\in\{0,\dots,2^{130}-1\}$ choose
|
||||
$\mathsf{resp}\xleftarrow{\$}\mathcal{I}_{1107}$ and calculate
|
||||
$G'\leftarrow\mathsf{resp}(G_{ch})$. The distributions of real transcripts
|
||||
and simulated transcripts are the same. A given valid transcript occurs with
|
||||
probability $1/2^{130}$.
|
||||
|
||||
\item \TODO
|
||||
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user