applied cryptography - protocols, algorithms, and source code in c

# She can pick different problems hence different

Noninteractive Zero-Knowledge Proofs Carol can't be convinced because the protocol is interactive, and she is not involved in the interaction. To convince Carol, and anyone else who may be interested, we need a noninteractive protocol. Protocols have been invented for noninteractive zero-knowledge proofs [477,198,478,197]. These protocols do not require any interaction; Peggy could publish them and thereby prove to anyone who takes the time to check that the proof is valid. The basic protocol is similar to the parallel zero-knowledge proof, but a one-way hash function takes the place of Victor: (1) Peggy uses her information and n random numbers to transform the hard problem into n different isomorphic problems. She then uses her information and the random numbers to solve the n new hard problems. (2) Peggy commits to the solution of the n new hard problems. (3) Peggy uses all of these commitments together as a single input to a one-way hash function. (After all, the commitments are nothing more than bit strings.) She then saves the first n bits of the output of this one-way hash function. (4) Peggy takes the n bits generated in step (3). For each ith new hard problem in turn, she takes the ith bit of those n bits and: (a) if it is a 0, she proves that the old and new problems are isomorphic, or (b) if it i...
