【24h】

One-Out-of-Many Proofs: Or How to Leak a Secret and Spend a Coin

机译:一定的证据:或者如何泄漏秘密并花一个硬币

获取原文

摘要

We construct a 3-move public coin special honest verifier zero-knowledge proof, a so-called Sigma-protocol, for a list of commitments having at least one commitment that opens to 0. It is not required for the prover to know openings of the other commitments. The proof system is efficient, in particular in terms of communication requiring only the transmission of a logarithmic number of commitments. We use our proof system to instantiate both ring signatures and zero-coin, a novel mechanism for bitcoin privacy. We use our Sigma-protocol as a (linkable) ad-hoc group identification scheme where the users have public keys that are commitments and demonstrate knowledge of an opening for one of the commitments to unlinkably identify themselves (once) as belonging to the group. Applying the Fiat-Shamir transform on the group identification scheme gives rise to ring signatures, applying it to the linkable group identification scheme gives rise to zerocoin. Our ring signatures are very small compared to other ring signature schemes and we only assume the users' secret keys to be the discrete logarithms of single group elements so the setup is quite realistic. Similarly, compared with the original zerocoin protocol we only rely on a weak cryptographic assumption and do not require a trusted setup. A third application of our Sigma protocol is an efficient proof of membership of a secret committed value belonging to a public list of values.
机译:我们构建了一个3举行的公共硬币特殊诚实验证者零知识证明,即所谓的Σ-议定书,了解至少有一个承诺的承诺,该承诺将打开0.这是宣传件了解开放所要求的另一个承诺。证明系统是有效的,特别是在通信方面,只需要仅传输对数次数的承诺。我们使用校对系统来实例化环形签名和零硬币,这是比特币隐私的新机制。我们将Sigma-Conforfic用作(可挂联的)ad-hoc组识别方案,用户有公共键是承诺,并展示一个开放的一个开放,以便将自己(一次)属于本集团的承诺。应用FIAT-Shamir变换对组鉴定方案产生戒指签名,将其应用于可连接群体识别方案产生Zerocoin。与其他环形签名方案相比,我们的戒指签名非常小,并且我们只假设用户的密钥是单个组元素的离散对数,因此设置非常逼真。同样,与原始Zerocoin协议相比,我们只依赖于弱密加密假设,并且不需要受信任的设置。我们的SIGMA协议的第三个应用是属于公共值列表的秘密承诺价值的成员资格的有效证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号