On the 'composition of Zero-knowledge Proof Systems on the Composition of Z~ro· Knowledge Proof Systems

نویسندگان

  • Oded Goldreich
  • Hugo Krawczyk
چکیده

A basic question concerning zero-knowledge proof systems is whether their (sequential and/or parallel) composition is zero-knowledge too. This question is not only of natural theoretical interest, but is also of great practical importance as it concerns the use of zero-knowledge proofs as subroutines in cryptographic protocols. We prove that the original formulation of zero-knowledge as appearing in the pioneering work of Goldwasser, Micali and Rackoff is not closed under sequential composition. This fact was conjuctered by many researchers (leading to the introduction of more robust fonnulations of zero-knowledge (e.g. ~lack-box simulation», but no full proof has been given yet. We prove that the general statement that the parallel composition of any two zeroknowledge protocols constitutes a zero-knowledge protocol, is wrong. Namely, we present two protocols, both being zero-Knowledge in a strong sense (e.g. black-box simulation) yet their parallel composition is not zero-knowledge (not even in a weak sense). We re~olve an open problem concerning the "parallel versions" of the interactive proofs systems known for quadratic residuosity, graph isomorphism and any language in NP. We show that these proof systems (which are constant-round Arthur-Merlin games) cannot be proven zero-knowledge using black-box simulation, unless the corresponding languages are in BPP. This is a corollary of our result that a constant-round ArthurMerlin interactive. proof for a language L, cannot be proven zero-knowledge using black-box simulation, unless L is in BPP. It should be noted that all known zeroknowledge interactive proofs are proven zero-knowledge using black-box simulation and that it is hard to conceive an alternative way for demonstrating the zero-knowledgeness of an interactive proof. The result concerning Arthur-Merlin zero-knowledge proofs can be viewed as a support to the conjecture that "secret coins" help in' the zero-knowledge setting. Research was partially supported by the Fund for Basic Research Administered by the Israeli Academy of Sciences and Humanities. T ec hn io n C om pu te r Sc ie nc e D ep ar tm en t T eh ni ca l R ep or t C S0 57 0 19 89

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

On the Composition of Zero-Knowledge Proof Systems

The wide applicability of zero-knowledge interactive proofs comes from the possibility of using these proofs as subroutines in cryptographic protocols. A basic question concerning this use is whether the (sequential and/or parallel) composition of zero-knowledge protocols is zero-knowledge too. We demonstrate the limitations of the composition of zeroknowledge protocols by proving that the orig...

متن کامل

Analyzing the tradition, hadith, of self-knowledge with regard to the knowledge of God

  Deep thinking on the tradition and analyzing other tradition dealing with knowledge of human soul distinguish this proof from those of philosophers and theologians. Availability, unity of the path and the follower and, most particularly, its being intuitive enter the follower to an objective state and, contrary to conceptual proofs, leads him/her to the presence of God. Again, this traditio...

متن کامل

Karlin’s Basic Composition Theorems and Stochastic Orderings

Suppose λ,x,ζ traverse the ordered sets Λ, X and Z, respectively and consider the functions f(λ,x,ζ) and g(λ,ζ) satisfying the following conditions, (a) f(λ,x,ζ) > 0 and f is TP2 in each pairs of variables when the third variable is held fixed and (b) g(λ,ζ) is TP2. Then the function h(λ,x) =∫Z f(λ,x,ζ)g(λ,ζ)dµ(ζ), defined on Λ×X is TP2 in (λ,x). The aim of this note is to use a new stochast...

متن کامل

Concurrent Zero-Knowledge in Poly-logarithmic Rounds

The subject of these notes is concurrent zero knowledge , in particular the construction given in [KP01]. Zero knowledgeness property of zero knowledge proof systems is defined with respect to an adversarial verifier that does not attempt to run multiple instances of a protocol concurrently. It is possible to prove that such protocols can be composed serially without substantial loss of securit...

متن کامل

Super-Perfect Zero-Knowledge Proofs

We initiate a study of super-perfect zero-knowledge proof systems. Loosely speaking, these are proof systems for which the interaction can be perfectly simulated in strict probabilistic polynomial-time. In contrast, the standard definition of perfect zero-knowledge only requires that the interaction can be perfectly simulated by a strict probabilistic polynomial-time that is allowed to fail wit...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014