Secure Bit Commitment Function against Divertibility
Secure Bit Commitment Function against Divertibility
复制标题
针对可转移性的安全比特承诺功能
DOI:
10.1007/3-540-47555-9_27
复制
发表时间:
1992
期刊:
影响因子:
--
通讯作者:
A. Fujioka
中科院分区:
文献类型:
--
作者:
K. Ohta;T. Okamoto;A. Fujioka
Some zero-knowledge interactive proofs (ZKIPs) have divertibility, that is, evidence of proof issued by a genuine prover,A, can be transferred to plural verifiers,Band thenC, where the intermediate verifier,B, acts asA, withA’s help, to confound the other verifierCwithout revealing the relation between theA-Binteraction and theB-Cinteraction. This property is a serious problem in practice, e.g. the mafia fraud attack on identification scheme and the multi-verifier attack against undeniable signatures.This paper proposes a new concept,security against divertibility, and proves that Naor’s bit commitment function based on pseudo-random generators is secure against divertibility under the reasonable assumption. Usage of this bit commitment inZKIPcan convert adivertible ZKIPto adivertible-free-ZKIPwhich is secure against the mafia fraud attack and the multi-verifier attack.