Concurrent zero-knowledge
… Concurrent executions of a zero-knowledge protocol by a single prover (with one or more …
be zero-knowledge in toto. In this article, we study the problem of maintaining zero-knowledge …
be zero-knowledge in toto. In this article, we study the problem of maintaining zero-knowledge …
[PDF][PDF] Resettable zero-knowledge
… of zero-knowledge. In essence, an rZK protocol is one that remains zero knowledge even if
an … In this paper we extend the classical notion of zero-knowledge by introducing the notion of …
an … In this paper we extend the classical notion of zero-knowledge by introducing the notion of …
Noninteractive zero-knowledge
M Blum, A De Santis, S Micali, G Persiano - SIAM Journal on Computing, 1991 - SIAM
… prover and verifier ina zero-knowledge proof if they share beforehand a short random
string. Without any assumption, it is proven that noninteractive zero-knowledge proofs exist for …
string. Without any assumption, it is proven that noninteractive zero-knowledge proofs exist for …
Zero knowledge proofs of identity
U Fiege, A Fiat, A Shamir - Proceedings of the nineteenth annual ACM …, 1987 - dl.acm.org
… bit of information) to zero knowledge proofs of knowledge (which … parallel executions of zero
knowledge protocols, define a … (which is not known to be zero knowledge) is secure since it …
knowledge protocols, define a … (which is not known to be zero knowledge) is secure since it …
Zero-knowledge proofs of knowledge without interaction
A De Santis, G Persiano - … 33rd Annual Symposium on Foundations of …, 1992 - computer.org
… A zero-knowledge proof system of … a zero-knowledge proof system of membership where
the prover convinces the verifier only of the veridicity of the statement. Zero-knowledge proofs …
the prover convinces the verifier only of the veridicity of the statement. Zero-knowledge proofs …
Zero-knowledge undeniable signatures
D Chaum - Advances in Cryptology—EUROCRYPT'90: Workshop …, 1991 - Springer
… The present article contains new undeniable signature protocols, and these are the first
that are zero-knowledge. … Again two things are proved: Theorem 3: The protocol of Figure …
that are zero-knowledge. … Again two things are proved: Theorem 3: The protocol of Figure …
Zero-knowledge sets
S Micali, M Rabin, J Kilian - 44th Annual IEEE Symposium on …, 2003 - ieeexplore.ieee.org
… Our new primitive immediately extends to providing zero-knowledge “databases.” … Since
the notion of a zero-knowledge set is essentially a special case of that of a zero-knowledge EDB…
the notion of a zero-knowledge set is essentially a special case of that of a zero-knowledge EDB…
Unifying zero-knowledge proofs of knowledge
U Maurer - International Conference on Cryptology in Africa, 2009 - Springer
… We present a simple zero-knowledge proof of knowledge protocol of which many protocols
in the literature are instantiations. These include Schnorr’s protocol for proving knowledge of …
in the literature are instantiations. These include Schnorr’s protocol for proving knowledge of …
Zero knowledge proofs of knowledge in two rounds
U Feige, A Shamir - Conference on the Theory and Application of …, 1989 - Springer
… The next assumption is used only for our perfect zero knowledge protocols. The same
assumption is used in [6] in the construction of their perfect zero knowledge protocols. …
assumption is used in [6] in the construction of their perfect zero knowledge protocols. …
A survey of noninteractive zero knowledge proof system and its applications
H Wu, F Wang - The scientific world journal, 2014 - Wiley Online Library
… will be correspondingly defined as statistical zero knowledge and perfect zero knowledge.
On the other hand, if soundness holds for any probabilistic polynomial time prover, that is, …
On the other hand, if soundness holds for any probabilistic polynomial time prover, that is, …