On the 'composition of Zero-knowledge Proof Systems on the Composition of Z~ro· Knowledge Proof Systems
نویسندگان
چکیده
A basic question concerning zero-knowledge proof systems is whether their (sequential and/or parallel) composition is zero-knowledge too. This question is not only of natural theoretical interest, but is also of great practical importance as it concerns the use of zero-knowledge proofs as subroutines in cryptographic protocols. We prove that the original formulation of zero-knowledge as appearing in the pioneering work of Goldwasser, Micali and Rackoff is not closed under sequential composition. This fact was conjuctered by many researchers (leading to the introduction of more robust fonnulations of zero-knowledge (e.g. ~lack-box simulation», but no full proof has been given yet. We prove that the general statement that the parallel composition of any two zeroknowledge protocols constitutes a zero-knowledge protocol, is wrong. Namely, we present two protocols, both being zero-Knowledge in a strong sense (e.g. black-box simulation) yet their parallel composition is not zero-knowledge (not even in a weak sense). We re~olve an open problem concerning the "parallel versions" of the interactive proofs systems known for quadratic residuosity, graph isomorphism and any language in NP. We show that these proof systems (which are constant-round Arthur-Merlin games) cannot be proven zero-knowledge using black-box simulation, unless the corresponding languages are in BPP. This is a corollary of our result that a constant-round ArthurMerlin interactive. proof for a language L, cannot be proven zero-knowledge using black-box simulation, unless L is in BPP. It should be noted that all known zeroknowledge interactive proofs are proven zero-knowledge using black-box simulation and that it is hard to conceive an alternative way for demonstrating the zero-knowledgeness of an interactive proof. The result concerning Arthur-Merlin zero-knowledge proofs can be viewed as a support to the conjecture that "secret coins" help in' the zero-knowledge setting. Research was partially supported by the Fund for Basic Research Administered by the Israeli Academy of Sciences and Humanities. T ec hn io n C om pu te r Sc ie nc e D ep ar tm en t T eh ni ca l R ep or t C S0 57 0 19 89
منابع مشابه
On the Composition of Zero-Knowledge Proof Systems
The wide applicability of zero-knowledge interactive proofs comes from the possibility of using these proofs as subroutines in cryptographic protocols. A basic question concerning this use is whether the (sequential and/or parallel) composition of zero-knowledge protocols is zero-knowledge too. We demonstrate the limitations of the composition of zeroknowledge protocols by proving that the orig...
متن کاملAnalyzing the tradition, hadith, of self-knowledge with regard to the knowledge of God
Deep thinking on the tradition and analyzing other tradition dealing with knowledge of human soul distinguish this proof from those of philosophers and theologians. Availability, unity of the path and the follower and, most particularly, its being intuitive enter the follower to an objective state and, contrary to conceptual proofs, leads him/her to the presence of God. Again, this traditio...
متن کاملKarlin’s Basic Composition Theorems and Stochastic Orderings
Suppose λ,x,ζ traverse the ordered sets Λ, X and Z, respectively and consider the functions f(λ,x,ζ) and g(λ,ζ) satisfying the following conditions, (a) f(λ,x,ζ) > 0 and f is TP2 in each pairs of variables when the third variable is held fixed and (b) g(λ,ζ) is TP2. Then the function h(λ,x) =∫Z f(λ,x,ζ)g(λ,ζ)dµ(ζ), defined on Λ×X is TP2 in (λ,x). The aim of this note is to use a new stochast...
متن کاملConcurrent Zero-Knowledge in Poly-logarithmic Rounds
The subject of these notes is concurrent zero knowledge , in particular the construction given in [KP01]. Zero knowledgeness property of zero knowledge proof systems is defined with respect to an adversarial verifier that does not attempt to run multiple instances of a protocol concurrently. It is possible to prove that such protocols can be composed serially without substantial loss of securit...
متن کاملSuper-Perfect Zero-Knowledge Proofs
We initiate a study of super-perfect zero-knowledge proof systems. Loosely speaking, these are proof systems for which the interaction can be perfectly simulated in strict probabilistic polynomial-time. In contrast, the standard definition of perfect zero-knowledge only requires that the interaction can be perfectly simulated by a strict probabilistic polynomial-time that is allowed to fail wit...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014