Non-interactive Composition of Sigma-Protocols via Share-then-Hash

Non-interactive Composition of Sigma-Protocols via Share-then-Hash
复制标题

DOI:
10.1007/978-3-030-64840-4_25
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Masayuki Abe;Miguel Ambrona;Andrej Bogdanov;Miyako Ohkubo;Alon Rosen
Masayuki Abe;Miguel Ambrona;Andrej Bogdanov;Miyako Ohkubo;Alon Rosen
中科院分区:
其他
文献类型:
--
作者:
Masayuki Abe;Miguel Ambrona;Andrej Bogdanov;Miyako Ohkubo;Alon Rosen

文献摘要

相似文献

部分知识的证明证明了对给定的陈述集合拥有某些证人子集。Cramer、damg<s:1> rd和Schoenmakers (CDS)构建了部分知识的证明,给定单个语句的“原子”协议,方法是让证明者随机地秘密共享验证者的挑战,并将这些共享用作原子协议的挑战。这种简单且影响很大的转换已在许多应用程序中使用,从匿名凭据到环签名。我们考虑一下,如果证明者首先对它们进行散列,而不是直接使用这些股票作为挑战,会发生什么。我们证明了这种基本的增强可以带来显着的好处:证明每个语句包含一个单原子转录本,它足以证明原子协议是特殊的声音,当使用Fiat-Shamir启发性编译成签名方案时,它的不可伪造性可以在非可编程随机oracle模型中证明。CDS转换不满足上述任何一个特征。
Proofs of partial knowledge demonstrate the possession of certain subsets of witnesses for a given collection of statements. Cramer, Damgård, and Schoenmakers (CDS), built proofs of partial knowledge, given “atomic” protocols for individual statements, by having the prover randomly secret share the verifier’s challenge and using the shares as challenges for the atomic protocols. This simple and highly-influential transformation has been used in numerous applications, ranging from anonymous credentials to ring signatures.We consider what happens if, instead of using the shares directly as challenges, the prover first hashes them. We show that this elementary enhancement can result in significant benefits:the proof contains asingleatomic transcript per statement,it suffices that the atomic protocols are-special sound for,when compiled to a signature scheme using the Fiat-Shamir heuristic, its unforgeability can be proved in thenon-programmablerandom oracle model.None of the above features is satisfied by the CDS transformation.