Non-interactive Composition of Sigma-Protocols via Share-then-Hash
Non-interactive Composition of Sigma-Protocols via Share-then-Hash
复制标题
DOI:
10.1007/978-3-030-64840-4_25
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Masayuki Abe;Miguel Ambrona;Andrej Bogdanov;Miyako Ohkubo;Alon Rosen
中科院分区:
文献类型:
--
作者:
Masayuki Abe;Miguel Ambrona;Andrej Bogdanov;Miyako Ohkubo;Alon Rosen
Proofs of partial knowledge demonstrate the possession of certain subsets of witnesses for a given collection of statements. Cramer, Damgård, and Schoenmakers (CDS), built proofs of partial knowledge, given “atomic” protocols for individual statements, by having the prover randomly secret share the verifier’s challenge and using the shares as challenges for the atomic protocols. This simple and highly-influential transformation has been used in numerous applications, ranging from anonymous credentials to ring signatures.We consider what happens if, instead of using the shares directly as challenges, the prover first hashes them. We show that this elementary enhancement can result in significant benefits:the proof contains asingleatomic transcript per statement,it suffices that the atomic protocols are-special sound for,when compiled to a signature scheme using the Fiat-Shamir heuristic, its unforgeability can be proved in thenon-programmablerandom oracle model.None of the above features is satisfied by the CDS transformation.