3

I have some questions from previous years exams, I hope you could help me with them. :)

Suppose that a protocol satisfies the properties of a $\Sigma$-protocol, except that it is only (plain) honest-verifier zero-knowledge. Show how to transform this protocol into a $\Sigma$-protocol for the same relation by assuming that the verifier generates $c \in C$ at random (with uniform distribution), where $(C,+)$ is an additive finite group.

Mikero
  • 14,908
  • 2
  • 35
  • 58

0 Answers0