Cypher gateway system
Abstract
In a first security domain (610) of a cypher gateway system (600), a computer converts a message (M) into an encyphered form that is associated with a first public key and a first private key. In a second security domain (620) of the system, the computer creates a second public key and a second private key. The computer places arguments to a channel (632) that is shared with both domains. A first argument shows knowledge of the message and shows properties of the message; a second argument shows that knowledge of the second private key implies knowledge of the message. A gateway (630) intercepts the placements, verifies the properties of the message using the first argument, and observes that the message verifiably communicated to an owner of the second private key. The gateway then enforces (636) a policy to determine at least one action.

Term
10.2 yearsto projected expiry
Projected expiry 25 November 2036, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
13 claims: 6 independent, 7 dependent
- 1A computer-implemented method for use in a cypher gateway system (600), the method comprising:within a first security domain (610), converting a message (M) into an encyphered form associated with a first public key and a first private key;within a second security domain (620), creating a second public key and a second private key;placing, on a shared channel (632) of the first security domain (610) and of the second security domain (630), a first argument (S) showing knowledge of the message and showing properties of the message;placing, on the shared channel, a second argument (T) showing that knowledge of the second private key implies knowledge of the message (M);at a gateway (630): intercepting the send that was placed on the shared channel (632);verifying the properties of the message (M) using the first argument;observing that the message (M) is verifiably communicated to an owner of the second private key;and enforcing (636) a policy to determine at least one action.
- 7Method according to any of the preceding claims, wherein in the obtaining step, the second public key identifies the recipient of the message (M) and wherein in the observing step, it is observed that the message (M) is verifiably communicated to the recipient.
- 8Method according to any of the preceding claims, wherein intercepting and verifying is performed without accessing the message.
- 9Method according to any of the preceding claims, wherein observing that the message is verifiably communicated comprises:transforming a first secret (166) including confidential data into a first public representation of the first secret;executing at least one instruction on the first secret (166) to obtain a second secret (148);transforming the second secret into a second public representation of the second secret;generating (142) an instruction statement that conveys a relation between the first public representation of the first secret and the second public representation of the second secret;generating a first gestalt statement (124, 126) characterizing a first gestalt relation between a first plurality of piece-secrets, the first gestalt relation defining a manner in which the first plurality of piece-secrets combine to provide the first secret;generating a second gestalt statement characterizing a second gestalt relation between a second plurality of piece-secrets, the second gestalt relation defining a manner in which the second plurality of piece-secret combine to provide the second secret;providing the instruction statement, the first gestalt statement, and the second gestalt statement to enable verification of application of the instruction statement and the relation between the first secret and the second secret;and performing an action in response to the verification of the application, wherein the action is related to the confidential data.
Independent claims6
280 paragraphs in 5 sections, as filed
TECHNICAL FIELD
0001This description relates to data security.
BACKGROUND
0002Conventional systems and techniques exist for securing data, whether at-rest or in-motion or otherwise. Particularly, in the realm of digital data, it is often highly likely that data can potentially be accessed or otherwise illicitly obtained by an entity who is not intended to have access or otherwise unauthorized to the data. Such data must therefore be secured, so that the unintended entity will be unable to inspect or alter the data.
0003For example, a message containing data to be sent from a transmitting entity to a receiving entity may be encoded in a manner which attempts to ensure that only the intended recipient(s) will be able to decode the message and obtain the data therein. Thus, even if the encoded message is transmitted in a manner that is accessible to unintended recipients (e.g., is sent over the public Internet), the unintended recipients will be unable to obtain or alter the data being communicated. In a similar example, stored data may be encoded in a manner which attempts to ensure that only intended entities will be able to retrieve and decode the stored data. The many known techniques for implementing public/private key cryptography provide specific examples of such scenarios, and other examples are also known.
0004In many scenarios, however, it is difficult or impossible for a third party to verify aspects of secured data, or successful communication thereof. Consequently, in scenarios in which such third-party verification would be necessary or helpful, undesirable levels of cost and effort must be expended, or the desired verification may have to be abandoned entirely, or may not be sufficiently reliable. In such scenarios, then, profits and efficiencies may be reduced, and data security may be compromised.
0005A prior art solution is disclosed in document: <patcit id="pcit0001" dnum="US2013339730A1"><text>US 2013/339730 A1</text></patcit>.
SUMMARY
0006According to one general aspect, a computer program product may include instructions recorded on a non-transitory computer readable storage medium, which, when executed by at least one process, are configured to cause at least one processor to transform a first secret including confidential data into a first public representation of the first secret, execute an instruction on the first secret to obtain a second secret, and transform the second secret into a second public representation of the second secret. The instructions, when executed, may further generate an instruction statement that conveys an instruction relation between the first public representation of the first secret and the second public representation of the second secret, generate a first gestalt statement characterizing a first gestalt relation between a first plurality of pieces secrets, the first gestalt relation defining a manner in which the first pieces secret combine to provide the first secret, and generate a second gestalt statement characterizing a second gestalt relation between a second plurality of pieces secrets, the second gestalt relation defining a manner in which the second pieces secret combine to provide the second secret. The instructions, when executed, may further provide the instruction statement, the first gestalt statement, and the second gestalt statement within a shared manifest to enable verification of application of the instruction with respect to the first secret and the second secret.
0007In the following implementations, any suitable combination(s) may be understood to be included of the various features recited herein. For example, in one or more implementations, the first public representation of the first secret may be encrypted, and the verification does not require decrypting the first public representation of the first secret.
0008The instructions, when executed, may further split the first secret into the first plurality of pieces secrets that are combinable via the first gestalt relation, wherein the splitting of the first secret may be inverted using the first gestalt relation, and split the second secret into the second plurality of pieces secrets that are combinable back via the second gestalt relation. The instructions, when executed, may further select a first subset of pieces from the first plurality of pieces secrets, and select a second subset of pieces from the second plurality of pieces secrets. The instructions, when executed, may further generate a first pieces statement that reveals the first subset of pieces secrets to enable verification of knowledge of the first secret, generate a second pieces statement that reveals the second subset of pieces secrets to enable verification of knowledge of the first secret, and include the first pieces statement and the second pieces statement within the shared manifest to enable verification of knowledge of the first secret and the second secret.
0009The first plurality of pieces secrets may have a first pieces relation to the first secret that enables the first subset of pieces secrets to be publically revealed while maintaining confidentiality of the confidential data. The first public representation of the first secret may include a first hashed value of the first secret, and the verification may involve matching the first public representation with a hashing of the first secret. The first public representation of the first secret may include a first hashed value of the first secret, and the verification may involve matching the first public representation with a hashing of the first subset of pieces.
0010The instructions, when executed, may further augment the shared manifest to be provided among a plurality of shared manifests in a manner that makes the shared manifest indistinguishable from the plurality of shared manifests to a potential attacker, and that enables a recipient of the shared manifest to detect whether the potential attacker has made a change to the plurality of shared manifests.
0011The instructions, when executed, may further provide the shared manifest in conjunction with a message associated with the confidential data and sent from a sender to a recipient with access to the confidential data, wherein the verification includes confirmation, by a verifier not having access to the confidential data, that the recipient received the message and had the access to the confidential data, and verification of a characteristic of the confidential data. The verification may include a partial verification of only a portion of the characteristic of the confidential data. The shared manifest may be one of a plurality of shared manifests, and the sender may have only partial control over which shared manifest is received by the recipient.
0012The instructions, when executed, may further receive a plurality of instructions, including the instruction, compile the plurality of instructions into executable instructions, and execute the plurality of instructions, including the executing the instruction on the first secret to obtain the second secret.
0013The confidential data may include a digital good and the verification may include confirmation of a characteristic of the digital good for which a recipient of the digital good has committed compensation to a provider of the digital good. The confidential data may include accounting information and the verification may include confirmation of a characteristic of the accounting information. The confidential data may include enciphered data and the verification may include a preview of the enciphered data without decyphering. The confidential data may include encrypted confidential data to be checked for authorization for transmission through a gateway, and the verification may include verifying the authorization without decrypting the encrypted confidential data.
0014Various corresponding methods and systems may also be implemented. Further, in additional or alternative implementations, a computer program product may instructions recorded on a non-transitory computer readable storage medium, which, when executed by at least one process, may be configured to cause at least one processor to receive a shared manifest. The shared manifest may include an instruction statement that conveys an instruction relation between a first public representation of a first secret and a second public representation of a second secret, wherein the first secret includes confidential data and the second secret was obtained by execution of an instruction on the first secret. The shared manifest may include a first gestalt statement characterizing a first gestalt relation between a first plurality of pieces secrets, the first gestalt relation defining a manner in which the first pieces secret combine to provide the first secret. The shared manifest may include a second gestalt statement characterizing a second gestalt relation between a second plurality of pieces secrets, the second gestalt relation defining a manner in which the second pieces secret combine to provide the second secret. The instructions, when executed, may further verify application of the instruction with respect to the first secret and the second secret, based on the shared manifest.
0015Any of the various implementations referenced herein, and/or associated methods or systems, may be utilized in conjunction with the preceding computer program product. Further, for example, the instructions, when executed, may access information relevant to the characteristic, and derive additional information regarding the characteristic from the relevant information.
BRIEF DESCRIPTION OF THE DRAWINGS
0016<ul id="ul0001" list-style="none" compact="compact"><li><figref idref="f0001">FIG. 1A</figref> is a block diagram of a system for selective privacy and verification.</li><li><figref idref="f0002">FIG. 1B</figref> is a schematic diagram of a system for selective privacy and verification.</li><li><figref idref="f0003">FIG. 2</figref> is a block diagram of a flowchart illustrating example operations of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0004">FIG. 3A</figref> is a block diagram of a system illustrating a first example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0005">FIG. 3B</figref> is a schematic diagram of a system illustrating a first example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0006">FIG. 4</figref> is a block diagram of a flowchart illustrating example operations of the system of <figref idref="f0004">FIG. 3A</figref>.</li><li><figref idref="f0007">FIG. 5</figref> is a block diagram of a system illustrating a second example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0008">FIG. 6</figref> is a block diagram of a system illustrating a third example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0009">FIG. 7</figref> is a schematic diagram illustrating the use of zero-knowledge hashing in an example implementation of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0010">FIG. 8</figref> is a block diagram of a relationship diagram corresponding to <figref idref="f0009">FIG. 7</figref>.</li><li><figref idref="f0011">FIG. 9</figref> is a table diagram illustrating an example construction corresponding to <figref idref="f0010">FIG. 8</figref>.</li><li><figref idref="f0012">FIG. 10</figref> is a schematic diagram of a system illustrating a fourth example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>, incorporating an example implementation of <figref idref="f0009">FIG. 7</figref>.</li><li><figref idref="f0013">FIG. 11</figref> is a schematic diagram of a system illustrating an example use of the zero-knowledge hashing.</li><li><figref idref="f0014">FIG. 12</figref> is a schematic diagram and table diagram illustrating an example of extending embodiments of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0015">FIG. 13</figref> is a schematic diagram illustrating a fifth example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0016">FIG. 14</figref> is a schematic diagram illustrating the use of verifiable communication commitments in the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0017">FIG. 15</figref> is a schematic diagram illustrating the use of partial verifiable partial communication in the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0018">FIG. 16</figref> is a block diagram of a flowchart illustrating a sender use of indistinguishability communication in the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0019">FIG. 17</figref> is a block diagram of a flowchart illustrating a receiver use of indistinguishability communication in the system of <figref idref="f0001">FIG. 1A</figref>.</li><li><figref idref="f0020">FIG. 18</figref> is a schematic diagram of a system illustrating a fifth example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>, incorporating oblivious verifiable oblivious communication.</li></ul>
DETAILED DESCRIPTION
0017<figref idref="f0001">FIG. 1A</figref> is a block diagram and <figref idref="f0002">FIG. 1B</figref> is a schematic diagram of a system 100 for selective privacy and verification. In the system 100, a manifest verifier 180 is configured to utilize a shared manifest 120 for data in order to provide de-centralized, third-party selective verification for a manifest driver 160, who is configured to utilize a manifest generator 140 in order to produce with selective privacy the shared manifest 120.
0018As will be described in more detail herein, the shared manifest 120 may describe aspects of some data but does not reveal or expose said data. Herein, the meaning of not revealing or exposing information about secrets is making it infeasible for unintended entities to learn about said secrets. Thus, said data may be kept private while selective privacy and verification with respect to said data is achieved by the inclusion of only selected aspects of said data in the shared manifest 120.
0019As described in detail herein, such selective privacy and verification provide advantages in a number of scenarios, including, e.g., restricting or eliminating an ability of parties to deny data aspects described by the shared manifest 120, facilitating commerce involving digital goods or compensations for information as described herein with respect to <figref idref="f0004">FIG. 3A</figref> and <figref idref="f0006">FIG. 4</figref>, facilitating compliance auditing as described herein with respect to <figref idref="f0007">FIG. 5</figref>, and enabling encyphered data previewing and gateway-processing as described herein with respect to <figref idref="f0012">FIG. 10</figref> and <figref idref="f0008">FIG. 6</figref>. Further, as described in detail herein, such privacy and verification may be enhanced in a number of ways including, e.g., by using zero-knowledge hashing as described herein with respect to <figref idref="f0009">FIG. 7</figref> and <figref idref="f0010">FIG. 8</figref> and <figref idref="f0011">FIG. 9</figref>, knowledge extension as described herein with respect to <figref idref="f0014">FIG. 12</figref>, compilation of manifest code as described herein with respect to <figref idref="f0015">FIG. 13</figref>, as well as various types of verifiable communication techniques, e.g. regular verifiable communication, verifiable communication commitments as described herein with respect to <figref idref="f0016">FIG. 14</figref>, verifiable partial communication as described herein with respect to <figref idref="f0017">FIG. 15</figref>, indistinguishability communication as described herein with respect to <figref idref="f0018">FIG. 16</figref> and <figref idref="f0019">FIG. 17</figref>, and verifiable oblivious communication as described herein with respect to <figref idref="f0020">FIG. 18</figref>.
0020Moreover, verification techniques described herein, as well as others that would be apparent to one skilled in the art, may be operated in a de-centralized manner, easily implementable by virtually any entity wishing to obtain verification, and without requiring the use of a trusted third party. These and various other uses and advantages of the system 100, and related systems, are described in detail herein, or would be apparent from the following description.
0021More specifically, for purposes of the example of <figref idref="f0001">FIG. 1A</figref>, the secrets storage engine 162 is used to fetch input secrets 166 to be operated on using instructions provided by the instructions provider 164. Secrets may be placed in the secrets storage engine 162 at any time. In one example, to be elaborated on with respect to <figref idref="f0007">FIG. 5</figref>, a financial entity may be interested in keeping its books private while enabling an accounting party to verify that the entitys book is in compliance with certain risk limits. In this example, the entitys book entries may be kept secret and placed in the secrets storage engine 120, while verification risk limits may be enabled by constructing an appropriate shared manifest 120 based on the secret book entries, as described in more detail herein.
0022Moreover, secrets that are generated as a result of operating the system 100 may also be placed in the secrets storage engine 120. In one example, to be elaborated on with respect to <figref idref="f0004">FIG. 3A</figref>, a person may be interested in keeping their heartrate data private while enabling a healthcare provider to verify the persons heartrate patterns are within healthy limits. In this example, the persons heartrate data may be kept secret and placed in the secrets storage engine 120 and the heartrate patterns may be obtained as output secrets 148 during the generation of a shared manifest 120 using appropriate instructions, as described in more detail herein. Thus, the secret storage engine 162 may be used to keep secrets that are obtained either internally or externally to the system 100. Furthermore, in embodiments of the system 100, secrets may be placed in the secrets storage engine 162 in sequence, incrementally, in parallel, in a distributed fashion, or other ordering.
0023Further, for the purposes of the example of FIG. IB, the instruction statement generator 142, given an instruction, operates on input secrets 166 to produce instruction statements 122 and output secrets 148. Thus, the instruction statement generator 142 may be used to establish a relation between some input secrets 166 to some output secrets 148 without revealing secrets. The relation is determined by the corresponding instruction handled by the instruction statements generator 142. In one example, to be elaborated on in with respect to <figref idref="f0008">FIG. 6</figref>, an encyphered resource gateway may be configured to allow only certain white-listed documents to pass through the gateway from one security domain to another. In this case the instruction statements 122 may indicate to the gateway that an encyphered document being sent through the gateway indeed appears on the white-list, so that the gateway may allow it through, yet without exposing the document itself to the gateway. More generally, the relation is described in a corresponding instruction statement 122 in the shared manifest 120 that a manifest verifier 180 is able to check.
0024For example, as described in more detail with respect to <figref idref="f0009">FIG. 7</figref> and <figref idref="f0010">FIG. 8</figref> and <figref idref="f0011">FIG. 9</figref>, an arithmetic instruction for adding two given numbers may be used. In this case, the corresponding relation may be between two input secrets 166 and one output secret 148 such that the latter is the result of adding the formers, while the corresponding instruction statement 122 may be a description of this relation in the shared manifest 120. As described, the output secrets 148 may be placed in the secrets storage engine 162 and may be used in future operations or instructions, e.g. as input secrets 166. In this example, the result of adding the two given numbers may be used as input for a second instruction for adding a third given number. Repeating this with additional given numbers results in output secrets 148 for sums of several given numbers.
0025More generally, different instructions may be used in repeated operation. As described in more detail with respect to <figref idref="f0015">FIG. 13</figref>, it will be appreciated that such instructions may be organized in complex structures, e.g. in programs expressed in appropriate source code.
0026Further, for the purposes of the example of FIG. IB, the pieces statements generator 144 operates on given input secrets 166 to produce output secrets 148. More specifically, each of the given input secrets 144 is split into at least two resulting output secrets 166, here referred to as pieces secrets. The split is such that each of the given input secrets 166 may be reproduced from its corresponding pieces secrets yet certain selected subsets of the pieces secrets corresponding to an input secret may be revealed without exposing information about the input secret.
0027In one example, to be elaborated on with respect to <figref idref="f0012">FIG. 10</figref>, a preview of a digital movie may be made available while keeping the document secret and while convincing a verifier that the preview is authentic, without resorting to a trusted third-party. This may be done by splitting the digital movie into pieces and exposing only some of the pieces as described herein. As will be made apparent in this description, the restriction of avoiding exposing information supports selective privacy and verification.
0028It will be appreciated that this restriction on exposing precludes simple splitting. For example, splitting a secret document into pages would not satisfy the restriction, since revealing any of the piece secrets, i.e. any of the pages of the secret document, would in fact expose information about the secret document. In accordance with the restriction, the splitting may be made using randomization, e.g. using well-known methods of secret sharing, such that the information available from revealing only certain selected subsets of the pieces secrets appears random.
0029Further, the pieces statements generator 144 may be used to produce a pieces statement 124 to be included in the shared manifest 120. The pieces statement 124 describes the relation between the given input secrets 166 and the pieces secrets. In addition, the pieces statement 124 reveals a certain selected subset of the pieces secrets such that no information on the input secrets 166 is exposed.
0030As will be described in more detail with respect to <figref idref="f0009">FIG. 7</figref> and <figref idref="f0010">FIG. 8</figref> and <figref idref="f0011">FIG. 9</figref>, the subset of secret pieces that is revealed would not feasibly be in complete control of the entity (or entities) producing the manifest, thus enabling a manifest verifier 180 to detect an attempt of said entity to cheat, e.g. by revealing secret pieces that are inconsistent with the relation described by the pieces statement 124. Thus, an honestly produced pieces statement 124 allows a manifest verifier 180 to be convinced that said relation between the revealed input secrets 166 and the pieces secrets holds yet without learning information about the given input secrets 166.
0031Further, for the purposes of the example of FIG. IB, the gestalt statement generator 146 operates on input secrets 166 and output secrets 148 to produce a gestalt statement 126. More specifically, the gestalt statement 126 describes the relation between the input secrets 166 and the above described pieces secrets yet without exposing information about any secrets.
0032As will be described in more detail with respect to <figref idref="f0009">FIG. 7</figref> and <figref idref="f0010">FIG. 8</figref> and <figref idref="f0011">FIG. 9</figref>, the gestalt statement 126 may be made using zero-knowledge hashing, such that the relation is evident from exposed hashes yet it is still infeasible for unintended entities to learn about the secrets from the hashes. As will be described in more detail with respect to <figref idref="f0013">FIG. 11</figref>, the hashes corresponding to gestalt statements 126 may be organized in a tree or other structures. In one example, to be elaborated on with respect to <figref idref="f0007">FIG. 5</figref>, a financial entity may maintain a ledger of its financial transactions. The financial entity may make hashes available for each transactions in the ledger, while a tree structure of hashes may be made available for the ledger. Thus, the financial entity may make gestalt statements 126 describing the relation between the hashes of the transactions and that of the ledger, allowing a verifier to confirm the relation without exposing the transactions or the ledger.
0033Further, for the purposes of the example of <figref idref="f0001">FIG. 1A</figref>, the output secrets 148 may further be used by the pieces statements generator 144 to produce the pieces statement 124 and by the gestalt statement generator 146 to produce the gestalt statement 126. Put another way, output secrets 148 produced in the operation of the manifest generator 140 may be reused in the making of further statements, and in particular need not first be placed in the secrets storage engine 162. For example, in case of an instruction for multiplying two numbers that are kept secret, the multiplication result, which is also kept secret, may be reused, e.g. in splitting it to pieces as described.
0034Further, for the purposes of the example of <figref idref="f0001">FIG. 1A</figref>, the manifest verifier 180 uses a statements interpreter 182 to interpret statements placed in the shared manifest 120 and a statements comparator 184 to compare said statements. More specifically, the statement interpreter 182 is configured to distinguish between types of statements, namely instruction statements 122 and pieces statements 124 and gestalt statements 126, and to interpret the information they describe. The statements comparator 184 may configured to compare the interpreted statements and perform checks for certain data aspects that may be described by the statements. The manifest verifier 180 is configured to accept the shared manifest 120 when the statements interpreter 182 successfully interprets the statements and the statements comparator 184 finds the statements pass the checks.
0035In one example, to be elaborated with respect to <figref idref="f0008">FIG. 6</figref>, an encyphered resource gateway may be configured to allow only certain white-listed documents to pass through the gateway from one security domain to another. The encyphered resource gateway may use a manifest verifier 180 to check that a shared manifest 120 describing the document indicates that it indeed appears on the white list, without exposing the document.
0036Thus, as described herein with respect to <figref idref="f0001">FIG. 1A</figref>, the gestalt statement 124 describes a splitting into pieces of the input secrets 166 and/or output secrets 148 into pieces without revealing them, the pieces statement 124 describes a revealing of some but not all of the pieces, and the instruction statement 122 describes a relation between said secrets, as well as between their pieces, corresponding to an instruction. The instruction statement 122, pieces statement 124, and gestalt statement 126 are configured such that together they enable verifying said instruction has been applied. The instruction statement 122, pieces statement 124, and gestalt statement 126 are interpreted by the statements interpreter 182 and then compared by the statements comparator 184 to determine validity.
0037In some embodiments, the relationship between the input secrets 166 and the output secrets 148 is determined by an instruction that is described not only by a type of operation but also by additional information, e.g. random values. In some embodiments, a multiplicity of instruction statements 122, pieces statement 124, and gestalt statement 126 may be used in the operation of one instruction, which may be viewed as a complex instruction, e.g. as described herein for modular exponentiation. Various embodiments of the system of <figref idref="f0001">FIG. 1A</figref> are described in detail herein.
0038In many embodiments of the system of <figref idref="f0001">FIG. 1A</figref>, one entity may operate the manifest driver 160 and the manifest generator while another entity may operate the manifest verifier 180. The motivations for this may vary. For example, the first entity may hold secrets it is incentivized to enable the second entity to verify some aspects of said secrets, while the second entity is incentivized to provide value in return for this enablement. Example systems involving these and similar motivations are described herein. In other embodiments, one entity may operate all of the manifest driver 160, the manifest generator, and the manifest verifier 180. Again, the motivation for this may vary. For example, one entity may be interacting with a second entity such that each entity enables the other to verify certain aspects of the formers secrets. Of course, it will be appreciated that such example divisions of operation are not exhaustive or limiting, and many other known or future techniques for divisions of operation may be used, as would be apparent from the present description.
0039Further in the example of <figref idref="f0001">FIG. 1A</figref>, the shared manifest 120 may be made available via virtually any medium that is accessible to the entities/modules 140, 160, 180. For example, the shared manifest 120 may be made available via a direct physical connection to a storage device. In further examples, it may be made available via a storage interface, e.g. shared memory or a storage service accessible via the public Internet, and presented in various standard ways, e.g. via file sharing, distributed storage, and email. In other examples, the shared manifest 120 may be made available via a channel, e.g. a private local area network (LAN), a private wide area network (WAN), or a virtual private network (VPN). The medium for accessing the shared manifest 120 may include various connectivity techniques, such as wireless, wired, electromagnetic, and optical.
0040In will be appreciated that, with respect to the system 100 and its various embodiments, the system operations may be augmented with auxiliary information such as timestamps, digital signatures, and authentication data, e.g. in order to enhance security of said embodiments.
0041<figref idref="f0003">FIG. 2</figref> is a block diagram of a flowchart illustrating example operations of the system of <figref idref="f0001">FIG. 1A</figref>. In the example of <figref idref="f0003">FIG. 2</figref>, operations 220-260 are illustrated as separate, sequential operations. However, in various implementations, additional or alternative operations may be included, and/or one or more operations may be omitted. In the various implementations, two or more operations or sub-operations may be executed in a partially or completely overlapping or parallel manner, or in a nested, iterative, looped, or branched fashion.
0042In <figref idref="f0003">FIG. 2</figref>, an instruction may be made available. If so, the operation continues to fetch input secrets 230, to make instruction statement (IS) 240, to store output secrets 250 as may have been produced, and to make piece and gestalt statements 260, and returns to check for more instructions 220. If no more instructions are available, the operation may stop 270.
0043Of course, <figref idref="f0003">FIG. 2</figref> represents a high-level view of example operations of the system 100 of <figref idref="f0001">FIG. 1A</figref>, and should not be considered limiting of additional or alternative embodiments. For example, as described above, it may occur that the various statements may be made together or individually, and, in the latter case(s), any of the statements may be made before the other.
0044Example embodiments of the system of <figref idref="f0004">FIG. 3A</figref>, an information compensation system that may be built using the system of <figref idref="f0001">FIG. 1A</figref> and verifiable communication techniques, are described herein. The system allows a first entity in possession of private data and a second entity in possession of resources to exchange selected information relating to the data with selected compensations from the resources. In addition, the exchange may be verified by a third-party that is not exposed to private data.
0045An example embodiment of the system of <figref idref="f0005">FIG. 3B</figref> involves an entity operating a resource committer 350, referred to as provider, and an entity operating an encyphered data committer 360, referred to as owner. The owner puts data into an encyphered data storage engine 330 (in the form of an encyphered data commitment 332, in accordance with <figref idref="f0004">FIG. 3A</figref>) such that information relating to the data initially inaccessible to the provider may be extracted later. The provider puts resources into a resources storage engine 320 (in the form of a resources commitment 322, in accordance with <figref idref="f0004">FIG. 3A</figref>) such that compensations that are initially inaccessible to the owner can be extracted later by the commitment extractor 340.
0046Thus, the owner and the provider commit to an extraction of information and compensations. An enabler for the extraction may optionally be included, so that the extraction is at first disabled, or otherwise it is enabled by default. The extraction is committed to by both sides and when enabled it may be affected. Once the extraction is affected, both the information and the compensations are extracted from the information storage engine and the value storage engine to the provider and the owner, respectively.
0047As will be appreciated from the description with respect to <figref idref="f0001">FIG. 1A</figref>, the system of <figref idref="f0004">FIG. 3A</figref> may utilize the system 100 to implement some of its operations. For example, the commitment generator 362 may use the manifest driver 160 and the manifest generator 140 to produce a shared manifest 120 describing the encyphered data commitment, the secret storage engine 356 and 364 may correspond to the secret storage engine 162, and the commitments verifier 370 may correspond to the manifest verifier 180.
0048As described above, with respect to <figref idref="f0004">FIG. 3A</figref>, the exchange may be delayed until the resources commitment 312, the encyphered data commitment 314 and the extract enablement 316 are all available on the shared channel 310. Example methods for making these commitments and enablement are described in more detail with respect to <figref idref="f0016">FIG. 14</figref>.
0049The described example information compensation system distinguishes between the data of the owner and the information to be delivered to the provider. Thus, the owner can keep the data private. Further, this system distinguishes between the resources of the provider and the compensations for the owner. Thus, the provider may condition the compensations on ex-post results related to the information. For example, using this system it is possible to set up an extraction whereby a discount from an insurance company is conditioned on the result of a formula accounting for the owners car data, without exposing this data to the insurance company.
0050The described example information compensation system of <figref idref="f0004">FIG. 3A</figref> should be understood to apply widely. For example, it may be applied to contexts of medical information, e.g. where medical data may be used to derive medical results such as statistical ones, of quantified-self, e.g. where personal data may be used to derive market segmentation results, or of (personal or entity) credit information, e.g. where financial data may be used to derive credit results such as creditworthiness or a credit score.
0051In the described example information compensation system, verifiable communication techniques may be employed as follows. Each piece of data is collected on behalf of its owner by a device protecting the pieces integrity. For example, a device may include trusted computing hardware that can sign the data using a private key accessible only to the device. The integrity of a piece of data may also be supported by cryptographic hashes as described herein. Each piece of data is put in a message <i>M</i> and into the encyphered data storage engine 330.
0052Further in the described example information compensation system, the provider makes a commitment as an argument <i>S</i> to enable delivery to him/her. The provider puts resources into the resources storage engine 320, such as payments or coupons, whose compensations to the owner are conditioned on delivery of certain derivations to the provider by the owner, e.g. by a payment processor or a smart contract enforcing the condition. The owner makes a commitment as an argument <i>T</i> referencing encyphered data in the information storage engine with a manifest suitable to the derivations, as an argument <i>T</i> to permit their delivery to the provider. An extract enabler 342 for the extraction, to introduce a delay or an approval process before the extraction may be affected, using verifiable communication commitments as described herein, e.g. with respect to <figref idref="f0016">FIG. 14</figref>.
0053Further in the described example information compensation system, the opening of said commitments may be done by a third-party, such as a creditor who could delay opening until a positive credit decision would have been made, or by an automatic process, such as a time delay or a smart contract. Using verifiable communication commitments ensures the enabler does not gain access to messages. The extraction is affected once enabled and arguments <i>S, T</i> are verified. This extracts derivations for the provider and compensations for the owner. One may use temporal arguments, which have previously been described for verifiable communication, as a way to timestamp system operations.
0054Example embodiments of the system of <figref idref="f0004">FIG. 3A</figref>, for a digital goods system that enables publicly confirming an exchange of a payment for a digital good without exposing the digital good to the public, are described. The system allows a seller of a digital good sold to make it accessible to a buyer conditioned on payment. The seller, operating as the encyphered data committer 360, places an inaccessible encyphered form of a digital good, as an encyphered data commitment 314, in an encyphered goods store, operating as the encyphered data storage engine 330. The buyer, operating as the value committer 350, pays the amount asked by the seller to a payment store, operating as the value storage engine 320. Both the buyer and the seller commit to a transaction involving the stored digital good and the stored payment. An enabler for the transaction, operating as the commitment extractor 340, may optionally be included, so that the transaction is at first disabled, or otherwise it is enabled by default.
0055Further in the example embodiments for a digital goods system, the transaction may be committed to by both sides and may be enabled, by means of an extract enablement 316, so that the transaction may be affected. Its effect is to release both the (decyphered) digital good, via the information extractor 346, and the payment, via the compensations extractor 344, from their corresponding stores 330 and 320, so that the former is delivered only to the buyer and the latter is remitted only to the seller and the transaction can be verified by any observer.
0056The example digital goods system should be understood to apply widely. For example, by taking the digital good to be a notarized document, one may obtain a system for payment against a notary service that is privacy preserving. Similarly, one may apply the system to trade finance contexts such as letters of credit (LoC) or documentary collections (D/C), by taking the digital good to be documents required by a bank, or other financial institution, to release payment such as a bill-of-lading, a transport document, or an invoice. The same applies to other financial and legal contexts where official documents are required to affect a transaction. An advantage of the digital goods system in these cases is that the documents remain private while the transaction is confirmed. Further, many forms of payments such as debit, credit, cryptocurrencies and non-monetary payments such as a transfer of title or another digital good may be taken.
0057In some embodiments of the example digital goods system, verifiable communication may be employed as follows. A digital good is set as a message M. A seller places an encyphered form of <i>M</i> in the encyphered good store described above. Depending on the method of verifiable communication, this form may be <i>g<sup>M</sup></i> for example. The seller can publish an offer to deliver the message behind the encyphered form using a traditional system, such as an online market place. The seller may also publish a cryptographic hash of <i>M</i> that can be used to validate <i>M</i> in a delivery. A buyer makes a commitment as an argument <i>S</i> to permit delivery to him/her. The buyer makes a payment to the payment store described above in the amount of the offer price against the verification of delivery of <i>M,</i> e.g. by a payment processor or a smart contract system. A seller makes a commitment as an argument <i>T</i> to permit delivery of <i>M</i> to the buyer. One may include an enabler for the transaction, to introduce a delay or an approval process before the transaction may be affected, using verifiable communication commitments.
0058Further in the examples of a digital goods system, the opening of said commitments may be done by a third-party, such as a creditor who could delay opening until a positive credit decision would have been made, or by an automatic process, such as a time delay or a smart contract. Using verifiable communication commitments ensures the enabler does not gain access to M. The transaction is affected once enabled and arguments <i>S, T</i> are verified. The affecting of the transaction releases the digital good for delivery to the buyer, by the digital good store, and the payment for remitting to the seller, by the payment store. One may use temporal arguments, which have previously been described for verifiable communication, as a way to timestamp system operations.
0059<figref idref="f0006">FIG.4</figref> is a block diagram of a flowchart illustrating example operations of the system of <figref idref="f0004">FIG. 3A</figref>. In particular, <figref idref="f0006">FIG. 4</figref> shows an example operation of a commitments verifier 370. Following the start 410 of operation, the resources commitment well-formedness is checked. For example, for the purposes of the above described digital goods system using verifiable communication, the commitment message corresponding to the resources commitment 312 is checked for whether it indeed described the commitment. If the answer is no, the operation proceeds to fail 470. Otherwise, the encyphered data commitment well-formedness is checked. For example, for the purposes of the above described digital goods system using verifiable communication, the commitment message corresponding to the encyphered data commitment 314 is checked for whether it indeed described the commitment. If the answer is no, the operation proceeds to fail 470. Otherwise, the matching of the two forms is checked. For example, for the purposes of the above described digital goods system using verifiable communication, the two commitment messages are compared for whether they are both relate to the same verifiable communication. If the answer is no, the operation proceeds to fail 470. Otherwise, the extraction enabled 450 status is checked. For example, for the purposes of the above described digital goods system using verifiable communication, the enablement for the opening of the commitments is checked. If the answer is no, the operation proceeds to fail 470. Otherwise, the operation proceeds to pass 460.
0060Example embodiments of the system of <figref idref="f0007">FIG. 5</figref>, a transactions compliance system 500 which may be built as an example embodiment of the system of <figref idref="f0001">FIG. 1A</figref>, are described. The system allows an entity, e.g. a financial company, to convince an auditor that its transaction books are in compliance, e.g. according to known regulations, without exposing the book entries to the auditor.
0061In the example transaction compliance system 500, book entries 512 and compliance instructions 532 for an entity, such as a financial company, are given. The book entries 512 describe transactions, e.g. buying or selling of specific financial securities. The book entries 512 may be processed by the book processor 510 to produce, or update, book state 514. For example, the book processor 510 may maintain the positions, or amounts, of each financial security and update them after each transaction. The book state 514 may be produced, or updated, as a result of this maintenance and may reflect information pertaining to compliance status of the entity. The book entries 512 and the book state 514 may be provided to the manifest generator 520 as inputs. Further, the manifest generator 520 is configured with the compliance instructions 532, which allow determining the compliance status from the given inputs, using methods described for the system 100. Then, the manifest generator 520 may generate statements 522, in accordance with the compliance instructions 532, that describe the compliance status based on the given inputs. The statement 522 do not expose the book entries 512 or the book state 514, as described with respect to the system 100, and may be included in a manifest. Next, the manifest verifier 530 is provided with the statement 522. Further, the manifest verifier 530 is configured with the compliance instructions 532. Thus, the manifest verifier 532 may check, using methods described for the system 100, that the statements 522 are consistent in accordance with the compliance instructions 532.
0062Embodiments of the system of <figref idref="f0007">FIG. 5</figref> may utilize the system of <figref idref="f0001 f0002">FIG. 1</figref> as described here. The book entries 512 may be implemented using secret inputs 166 generated by the manifest driver 160. The book state may be implemented using secret outputs 148 deriveed by the manifest generator 140. The manifest generator 520 may be implemented using the manifest generator 140. The compliance instructions 532 may be implemented using the instruction provider 164 by the manifest driver 160. The statements 522 may be implemented using the shared manifest 120, with instruction statements 122, pieces statements 124, and gestalt statements 126. The manifest verifier 530 may be implemented using the manifest verifier 180.
0063Example embodiments of the system of <figref idref="f0008">FIG. 6</figref>, a cypher gateway system 600 that may be built as an embodiment of the system of <figref idref="f0001">FIG. 1A</figref> and using verifiable communication techniques, are described. The system allows setting up security domains and encyphered resource gateways in between. An encyphered resource gateway may enforce policies on encyphered resources being transferred through it, between the security domains it stands between, without decyphering or otherwise accessing the resources and without relying on key services such as key escrow.
0064Embodiments of the system of <figref idref="f0008">FIG. 6</figref> may utilize the system of <figref idref="f0001 f0002">FIG. 1</figref> as described here. The manifest generators 614 and 624 may be implemented using the manifest generator 140. The manifest drivers 616 and 626 may be implemented using the manifest driver 160. The manifest verifier 634 may be implemented sing the manifest verifier 180. The shared manifest 120 may be placed on the shared channel 632.
0065In the example cypher gateway system 600, policies may be set up for taking certain actions in response to specific transfers, e.g. blocking a transfer or raising an alert. The encyphered resource gateway 630 may apply policies by intercepting messages placed on the shared channel 632, which is under its control. The encyphered resource gateway 630 may use the manifest verifier 634 to determine selected aspects of said messages, even if encyphered and their content remains inaccessible to the encyphered resource gateway 630.
0066Further in the example cypher gateway system 600, to enforce a policy, a rule enforcer 636 is used to determine the actions. The rules may be defined e.g. in terms of senders, recipients, and properties of resources. In the example, the enforcer applies rules consulting traces that are placed in the traces storage engine 638. These traces capture information about grants and revocations orders, and more generally about authorization operations, for resources. A grant or revocation order may involve resources being granted or revoked, sender (grantor or revoker) keys, and receiver (grantee or revokee) keys. When allowed by the enforcer given the policies, the effect of an order may be to grant or revoke rights to access resources, or to administering such rights for them, to recipients possibly in other security domains. Orders may originate from owners of resources, administrators, or other users. The traces of these orders, fetched from the traces storage engine 638, are consulted by the policies rule enforcer 636, allowing the gateway to control a send that goes through it. A send may be allowed through as determined by applying these policies.
0067Using the described a cypher gateway system 600, certain restricted resources, even in encyphered form, may be prevented from leaving their security domain through the gateway. For example, the transfer of encyphered resource 612 from security domain 610 to security domain 620 may be blocked, and similarly the transfer of encyphered resource 622 from security domain 620 to security domain 610 may be blocked. Encyphered resources may be identified in policies, e.g. by their public keys or by their cryptographic hashes as described herein. This way, a violating sender would not convince the gateway that the (encyphered) resource is not restricted when in fact it is. One may use a cypher gateway system to ensure that certain restricted resources in one security domain may be sent only to certain allowed recipients, who may be identified by their public keys, in other security domains.
0068Further in the example cypher gateway system 600, a cypher gateway system may be used to monitor or report unauthorized sends. Hence honeypots, canary traps, and other detection schemes, are enabled for encyphered resources by enabling the detection of aspects of encyphered resources being sent. Since all policy required information exists in the sends, they may be directly stored for auditing purposes, with no need for a separate audit system that would need to be kept in sync and secured separately.
0069The example cypher gateway system 600 should be understood to apply widely. In one example, it may be applied to trusted computing contexts. A CPU, or any other unit with processing capabilities, may have an embedded private key that never leaves the unit. This gives the unit the capacity to secretly authenticate and transfer encrypted data without the owner of the device having a feasible way to know it, which is often considered a serious security threat. Using a cypher gateway system and placing the unit in a separate security domain, one may restrict the unit to transmitting allowed data without exposing the data.
0070In another example of the cypher gateway system 600, it may be applied to intranets and the Internet, wired or wireless networks, static or dynamic or ad-hoc networks, and so on. Traditionally, there is a conflict between the desire of a network operator to understand traffic flowing through its network and the desire of network users to privacy. Using a cypher gateway system and placing users in security domains, the network operator may require aspects of the traffic be conveyed without needing the full traffic details to be exposed.
0071In an example embodiment of the cypher gateway system, verifiable communication may be employed as follows. Resource 1 is represented as a message <i>M</i> and converted into encyphered form within security domain 1. Depending on the method of verifiable communication used, this form may be <i>g<sup>M</sup></i> for example. Encyphered resource 1 is associated with key pair 1 (public and private keys), which are controlled by user 1. A gateway policy is set up to allow key pair 1 to grant and revoke access to resources it is associated with to any user in security domain 2. User 1 makes an argument <i>S</i> showing knowledge of <i>M</i> for encyphered resource 1 and any desirable properties of <i>M</i> using the manifest of the message. Meanwhile in security domain 2, key pair 2 is created and controlled by users 2. User 1 issues an order to grant private key 2 access to encyphered resource 1. The order includes a reference to public key 2 and is signed with private key 1. The order is traced by keeping detailed information about it, such as issuer, sequence number, time, etc. User 1 sends resource 1 to user 2 by constructing an argument <i>T</i>, showing that knowledge of private key 2 implies knowledge of <i>M</i>, and communicating <i>T</i> and encyphered resource 1 to security domain 2. The gateway intercepts the send, verifies arguments <i>S, T</i> and observes that <i>M</i> is verifiably communicated to an owner of private key 2. The gateway does not have or need access to <i>M</i> to do so. The gateway consults the traces which show that user 1 has granted private key 2 access to resource 1, and that this grant has not been revoked. The gateway applies the policy, which allows this grant, and permits the send to go through. The sent argument <i>T</i> and encyphered resource 1 are received at security domain 2, which are labeled here as encyphered resource 2, allowing user 2 to access M.
0072Further in the example, since orders refer to public keys, not private keys, there is no need to have access to private keys for constructing orders. In this example, policies determine if an order is allowed. If user 1, or anyone allowed to do so such as an administrator, had issued an order to revoke the grant after it was given, the gateway would have blocked the send. An attempt to send a different resource, for which the traces showed there was no grant, would have been blocked as well. The gateway could be configured, instead of or in addition to blocking sends, to monitor or report policy violations, i.e. orders or sends that are not allowed by the policies, or to perform other actions. Temporal arguments, which have previously been described for verifiable communication, may be used to timestamp system operations.
0073Example embodiments of the system of <figref idref="f0004">FIG. 3A</figref> for a system for previewing digital goods are described. In the non-limiting examples, the system enables a preview in encyphered form to be extracted from an original digital good in encyphered form, which is committed to the encyphered data storage engine 330 by the encyphered data committer 360. Further, it enables a verifier, corresponding to a specific commitments verifier 370, to check that the preview is consistent with the original without exposing them. Further, the system enables a preview recoverer, corresponding to a specific commitments extractor 340, to recover the preview from its encyphered form.
0074The system for previewing digital goods operates as follows. A preview extractor obtains a digital good in encyphered form and extracts from it a preview in an encyphered form that enables verification. A preview verifier observes the encyphered preview and checks that it indeed matches the encyphered digital good, without decyphering it, and that a preview recoverer can recover the preview. The preview recoverer recovers the preview from its encyphered form and matches with the encyphered digital good.
0075The described system for previewing digital goods improves on traditional previewing, which, without verification, requires a higher level of trust, for example in view of the risk the preview does not faithfully represent the good as may be claimed by the extractor. In traditional previewing, this trust often manifests in reputation of the extractor, which takes effort to build, while extractors that have not built this reputation (yet) often need to pay for services of a third party, such as a distributor that already established a reputation of its own.
0076In more detail, with respect to <figref idref="f0012">FIG. 10</figref>, the components of the example system for previewing digital goods may interact as follows. The encyphered digital good is given in a form that enables extraction of an encyphered preview from it. As elaborated on later, the encyphered digital good may be split into encyphered parts 1010, corresponding to parts 1020 of the digital good. Further, a preview extractor may extract from the parts 1020 selected preview parts 1030 and form the encyphered preview parts 1040 from them. The extraction is consistent, meaning that the preview parts 1030 in decyphered form are consistent with the parts 1020 in decyphered form of the digital good. In addition, the extraction enables verification and recovery using the same encyphered forms, which are available on a shared manifest. Next, a verifier observes on the shared manifest the encyphered preview parts 1040 and matches them to the encyphered parts 1010 of the digital good, without decyphering. If the parts are indeed in the expected form and a match is found, the verifier accepts; otherwise, it rejects. Meanwhile, a preview recoverer, that also accesses the same encyphered preview parts 1040 on the shared manifest, may recover the preview parts 1030 from the encyphered preview parts 1030 and match the parts of the recovered preview with the encyphered parts 1010 of the digital good similarly. The preview recoverer may succeed in performing this recovery only when the verifier has accepted but fails when the verifier has rejected. This correspondence between successful verification and recovery is a desirable property of the system.
0077The example system for previewing digital goods may be used with other systems involving digital goods. In one example, it may be used in the context of a digital goods system in the implementation of an encyphered good committer, e.g. a cryptogaphic device on a SIM card in a smartphone, and an encyphered good store, e.g. a network file storage appliance hosting content in encyphered form. This may be done in order to provide said preview of said digital good to potential buyers that make it easier for them to proceed to transacting to buy said digital good using said digital goods system.
0078Example embodiments of the example system for previewing digital goods are described. The encyphered parts 1020 and the encyphered preview parts 1030 may be implemented as digital files stored in digital storage devices. An advantage of the system described here is that, due to encyphering, such digital storage devices need not be trusted to limit the risk of leaking the content of the good or preview. The described preview extractor, preview recoverer, and preview verifier may be implemented as separate hardware modules that are communicating over a network or interconnect.
0079For example, in the context of a previewing digital images, the preview extractor may be implemented using a module connected to image memory in a digital camera, the preview recoverer may be implemented using a module connected to a display in a handheld device, and the preview verifier may be implemented using a module connected to a storage device in an auditing system. An advantage of the system described here is that such modules need not operate all at the same time or be located all physically close to each other, and may be operated by independent entities.
0080In some implementations of the example system for previewing digital goods, verifiable communication may be employed as follows. The digital good, represented as a string of bits, is split into n parts such that each part may be interpreted independently of other parts. The parts need not be disjoint though in many cases it may be a convenient choice. For example, a digital video may be split into 1-minute video parts and a digital book may be split into 1-page parts. A zero-knowledge hash <i>h</i>(·) may be applied to each part and an incremental hashing scheme may be applied to the hashes. A Merkle-tree, or some other authenticated data structure, of the hashes in the scheme may be used for verification of some of these hashes by authenticating them against the structure, often involving the checking of fewer than all hashes. Let <i>H</i>(·) be a cryptographic hash function on bit strings. Zero-knowledge hashes of the parts may be input to <i>H</i>(·) to obtain a bit string that is used to select a subset of the parts, to ensure that the selected subset is unpredictable and enhance security. In one example, to get a subset of size k with (nearly) uniform probability, <maths id="math0001"><math display="inline"><mo>⌈</mo><mrow><msub><mi>log</mi><mn>2</mn></msub><mfenced><mtable><mtr><mtd><mi>n</mi></mtd></mtr><mtr><mtd><mi>k</mi></mtd></mtr></mtable></mfenced></mrow><mo>⌉</mo></math><img file="EP4040713A1_D0001.tif" /></maths> bits from the output of <i>H</i>(·) may be used to select such a subset. In a second example, a stream of bits from the output of <i>H</i>(·) may be used to select such a subset via sampling parts from a streaming digital good. The selected parts may be taken together to form a (sample) preview digital good that is consistent with the original digital good. A verifier can check that the hashes of preview parts match those of selected original parts to confirm this consistency. An arguer may verifiably communicate the preview digital good using one of the known methods.
0081In a second example of the system for previewing digital goods, it may be incorporated in an information compensation system in the implementation of an encyphered information storage engine, e.g. a cryptographic device for encyphering prior to storing in a storage device, and preview derivations from digital good data, e.g. previews of video clips. In this system, a digital good may be used as the data and a preview of the digital good may be used as the derivation of the data, thus allowing getting compensation for a preview of a digital good. This may be done in order to facilitate the settlement of a sale of the preview to a buyer without exposing the preview to settlement agents.
0082In a third example of the system for previewing digital goods, it may be incorporated in a cypher gateway system in the implementation of encyphered resources for digital goods and their previews, e.g. cryptographic devices for safekeeping sensitive data, and that of key pairs, e.g. security tokens. This may be done in order to prevent unauthorized extraction of restricted information from security domains. By considering the encyphered forms of the preview and digital good, a cypher gateway is able to consider them in its decision whether to allow through communication of said digital good.
0083The cypher gateway may also be configured to modify the communication in a controlled way, e.g. using proxy re-encryption. In these examples, one may reduce the hardware and networking resources needed in operation, e.g. the use of encyphered forms for the digital goods and the previews allows them to be securely stored in a shared storage, such as cloud storage, thus avoiding the need to store copies at several end-user devices and the need to communicate them from afar when they are available from proximate shared storage.
0084Indistinguishability communication, a technique applicable to verifiable communication in the context of an at least partially unreliable or untrusted shared channel, is described. Such a channel may erase, modify, insert, reorder or delay communications which could lead to inconsistencies such as a party successfully verifying communication that was not (yet or at all) received by another party or vice versa. Examples for such channels are erasure channels and untrusted centralized storage channels. The technique is useful in mitigating risks of such inconsistencies.
0085Indistinguishability communication may be used with the above described system for verifiable, possibly in the context of a digital goods system or an information compensation system, as discussed above. This results in observers gaining access to previews of digital goods that are communicated on the channel, while verifying that recipients gain access to these digital goods, even via an unreliable or untrusted channel.
0086Indistinguishability communication may also be used with channels providing only temporary access to communications, such as an unreliable storage channel or a broadcasting channel with limited retransmissions. Due to indistinguishability of verification and decyphering, verifiers may be convinced that during the time a particular communication is (possibly repeatedly) observed on the channel and passes verification, the recipients of the communication have access to its message. Hence, verification and decyphering may be viewed as co-occurring.
0087Indistinguishability communication may be implemented in a module in networking and communication systems, e.g. in a channel access device. It may be used to reduce the hardware and networking resources needed by allowing communications to be multi-casted or broadcasted, as described below, so that the volume of communication and the need for retransmissions and for storing-and-forwarding are reduced without exposing encyphered content.
0088Example uses of indistinguishability communication in the system of <figref idref="f0001">FIG. 1A</figref> are described. <figref idref="f0018">FIG. 16</figref> is a block diagram of a flowchart illustrating a sender use of indistinguishability communication in the system of <figref idref="f0001">FIG. 1A</figref>. Following the start 1610, the sender proceeds to inputs manifest statements 1620, then to add order information 1630 to them, next to add authentication to these, and finally to send the resulting communication. <figref idref="f0019">FIG. 17</figref> is a block diagram of a flowchart illustrating a receiver use of indistinguishability communication in the system of <figref idref="f0001">FIG. 1A</figref>. Following the start 1710, the receiver first checks that the channel is well-timed 1720. If the answer is no, the receiver proceeds to reject 1760. Otherwise, the receiver checks whether the communication authenticates 1730. If the answer is no, the receiver proceeds to reject 1760. Otherwise, the receiver checks whether the communication is well-ordered 1740, i.e. with respect to other received communication. If the answer is no, the receiver proceeds to reject 1760. Otherwise, the receiver proceeds to verify/receive the manifest statements 1750.
0089Techniques of indistinguishability communication may build on a number of other techniques, for example, as follows. A communication sender uses anonymous access to the channel, ensures a communication occurs on the channel periodically, includes order information in each communication, and uses randomized encyphering with, and authenticates, each communication. A communication receiver uses anonymous access to the channel, checks for periodic occurrence of communication on the channel, checks for correct authentication of communications, checks well-ordering of communications from each party, and checks for correct form of communications: a communication receiver that is a verifier follows with verifying the communication, whereas one that is a decypherer follows with decyphering the communication. The technique ensures that attacks cannot result in an inconsistent view of the channel by different communication receivers, as described below.
0090In more detail, the indistinguishability communication technique operates as follows. First, anonymous access to the channel ensures that receiving, i.e. decyphering, and verification are indistingiushable. For example, anonymous access to a broadcast or multicast channel may be used. Anonymity makes parties indistinguishable from one another from the point of view of an attacker of the channel. Since in verifiable communication the same arguments <i>S, T</i> are used in both verification and decyphering, anonymous access ensures that decyphering and verification are indistinguishable outside of the party performing them.
0091Further using of randomized encyphering ensures all communications are different and indistinguishable too. With this, an attacker is reduced to attacking a random subset of communications, so e.g. attacks cannot single out a specific party or isolate verifiers.
0092Further using of authenticated communications, prior to passing the communications to the channel, limits these attacks to erasure and reordering and delays, since modifications and insertions may be detected and dropped, rather than passed, from the channel by communicating parties when their communication fails to authenticate.
0093Assuming erasures occur with some probability <i>p</i> < 1, retransmitting directly or effectively, e.g. using codes, each communication a sufficient number of times, each time with randomization as described above, ensures that eventually all communications are accessible to all parties despite the erasures, and that eventually all parties obtain a consistent view of the channel. For example, a fountain code may be used to reach a sufficient number of effective retransmissions. For <i>p</i> = 1, communicating parties obtain an empty yet still consistent view of the channel. Hence, these attacks cannot result in an inconsistent view among parties.
0094Further inclusion of ordering information, such as a serial number, may be made by a party in each of its (input) communications prior to authenticating them, so that reordering (possibly after failed attempts to correct) and erasures may be detected by other parties as a communication not in a well order, e.g. having a non-consecutive serial number.
0095Finally, keeping communication alive periodically, e.g. once per second by any party even carrying no payload, ensures that delays are detected by other parties as a missing communication within the expected period, i.e. as a channel that is not well-timed.
0096Techniques for selectivity in privacy and verification techniques in devising various device instructions are described. Zero-knowledge hashing arguments are described herein as a means to make gestalt statements, pieces statements, and instruction statements. A set of general-purpose instructions is described. The described instructions include arithmetic, comparison, hashing, and permuting ones involving elements, numbers, and/or constants. These make extensive use of linear algebra, such as in matrix/vector multiplications, for computation of zero-knowledge hash values. Because of this use of linear algebra, these instructions are a good fit for enhancing widely available hardware - such as general-purpose CPUs and GPUs, vectorized and embedded processors, secure processors as such SIM cards, programmable hardware such as FGPAs, dedicated hardware such as ASICs, and other processing architectures - with privacy and verification capabilities, e.g. based on their support for linear algebra operations. These operations may be efficiently (possibly incrementally) parallelized and distributed across many computing threads, e.g. cores or co-processors or circuits, and/or across many nodes, e.g. machines or virtual machines or containers, for enhancing various applications, e.g. cluster computing such as streaming or Map/Reduce or lambda architecture. Moreover, device instructions may apply the same operation to multiple items and hence are a good fit for enhancing hardware supporting SIMD. Further, the device enables a wide range of hardware enhanced with privacy and verification capabilities in a manner not available in conventional hardware. In contrast, existing solutions for verifiable computation often involve operations that are more expensive computationally than linear algebra operations and are often harder to efficiently parallelize or distribute. Further, these solutions often support directly only a limited set of instructions and may only support some other instructions indirectly, e.g. via a software implementation using a (relatively large) program that utilizes the directly-supported instructions. Finally, these solutions often do not have a good fit to enhancing widely available hardware as described here for the device.
0097Example embodiments of the system of <figref idref="f0001">FIG. 1A</figref> using zero-knowledge hashing as in <figref idref="f0009">FIG. 7</figref> are described. In a well-known paper dated 1995, Ajtai described constructions of one-way functions based on some well-known lattice problems. In another well-known paper dated 1996 Goldreich, Goldwasser and Halevi described constructions based on Ajtais that provided for collision-free hash functions as well as collision-free universal hash functions. Shown here is a zero-knowledge argument of knowledge of a pre-image of such collision-free hash functions, in particular one that is simple and fast for both the prover and the verifier. Some zero-knowledge argument systems may employ collision-free hashing as a building block and may use zero-knowledge hashing described herein as a building block.
0098The GGH's construction for collision-free hashing is recalled. Let <i>n,m,q</i> ∈<img file="EP4040713A1_D0002.tif" /> be parameters such that <i>n</i> log <i>q</i> < <i>m</i> < <maths id="math0002"><math display="inline"><mfrac><mi>q</mi><mrow><mn>2</mn><msup><mi>n</mi><mn>4</mn></msup></mrow></mfrac></math><img file="EP4040713A1_D0003.tif" /></maths>, <i>q</i> = <i>O</i>(<i>n<sup>c</sup></i>) for some constant <i>c</i> > 0. Let <maths id="math0003"><math display="inline"><msub><mi>M</mi><mrow><mi>n</mi><mo>×</mo><mi>m</mi></mrow></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>q</mi><mrow><mi>n</mi><mo>×</mo><mi>m</mi></mrow></msubsup></math><img file="EP4040713A1_D0004.tif" /></maths> be a random matrix. The hash function <i>h<sub>M</sub></i> : <maths id="math0004"><math display="inline"><msup><mfenced open="{" close="}"><mn>0,1</mn></mfenced><mi>m</mi></msup><mo>→</mo><msubsup><mi>ℤ</mi><mi>q</mi><mi>n</mi></msubsup></math><img file="EP4040713A1_D0005.tif" /></maths> is then defined for <i>s</i> := <i>s</i><sub>1</sub><i>s</i><sub>2</sub>...<i>s<sub>m</sub></i> ∈ {0,1}<i><sup>m</sup></i> as <i>h<sub>M</sub></i>(<i>s</i>) := <i>Ms</i> mod <i>q.</i> GGH show that it is infeasible to find collisions for <i>h<sub>M</sub></i> unless the well-known lattice problems have good approximations in the worst case. GGH also show a slight modification to get universal and collision-free hash functions. To this end, <i>q</i> is chosen as a prime, <maths id="math0005"><math display="inline"><mi>r</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mi>q</mi><mi>n</mi></msubsup></math><img file="EP4040713A1_D0006.tif" /></maths> is chosen at random, and the hash function is defined as <i>h</i><sub><i>r</i>,<i>M</i></sub>(<i>s</i>) := <i>r</i> + <i>Ms</i> mod <i>q.</i> With respect to <figref idref="f0009">FIG. 7</figref>, setup 710 may be used to select a hash function as described. GGH's construction uses a modified Ajtai theorem stating that a well-known lattice problem can be solved in the worst case if the following problem can be solved in the average case: for parameters <i>n</i>,<i>m</i>,<i>q</i> ∈ <img file="EP4040713A1_D0007.tif" /> such that <maths id="math0006"><math display="inline"><mi>n</mi><mspace width="1ex" /><mi>log</mi><mspace width="1ex" /><mi>q</mi><mo><</mo><mi>m</mi><mo><</mo><mfrac><mi>q</mi><mrow><mn>2</mn><msup><mi>n</mi><mn>4</mn></msup></mrow></mfrac></math><img file="EP4040713A1_D0008.tif" /></maths>, <i>q</i> = <i>O</i>(<i>n<sup>c</sup></i>) for some constant <i>c</i> > 0, given input <maths id="math0007"><math display="inline"><mi>M</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mi>q</mi><mrow><mi>n</mi><mo>×</mo><mi>m</mi></mrow></msubsup></math><img file="EP4040713A1_D0009.tif" /></maths>, find output <i>x</i> ∈ {-1,0,1}<i><sup>m</sup></i> \ {0}<i><sup>m</sup></i> such that <i>Mx</i> = 0 (mod <i>q</i>) and ll<i>x</i>ll ≤ <i>m.</i> This problem is labeled (A2) in GGH, and this labeling is adopted here. GGH go on to show that finding a collision <i>h<sub>M</sub></i>(<i>s</i><sub>1</sub>) = <i>h<sub>M</sub></i>(<i>s<sub>2</sub></i>) for <i>s</i><sub>1</sub> ≠ <i>s</i><sub>2</sub> ∈ {0,1}<i><sup>m</sup></i> yields a solution <i>x</i> := <i>s</i><sub>1</sub> - <i>s</i><sub>2</sub> ∈ {-1,0,1}<i><sup>m</sup></i> to (A2).
0099An example construction of zero-knowledge hashing built on Ajtais and GGHs results is described. By using this construction, provers may convince that with some probability they know a secret preimage of a public hash vector and that this preimage lies in a small domain, in which finding preimages is hard. The construction does not leak any information about the secret preimage beyond this. Involving mostly linear operations, the construction is relatively simple and efficient.
0100An overview of the example construction of zero-knowledge hashing with respect to <figref idref="f0009">FIG. 7</figref> is described. First, a secret in some domain is set up using the setup 710. Then, the secret is transformed using the transformer 720 to a transformed secret that is in a domain equal to the sum of at least two sub-domains. This lets the secret be split using the splitter 732 to at least two secret pieces, one in each of the sub-domains that linearly combine back to it. The description below refers to two sub-domains and to summation as the linear combination; this should not be interpreted to limit the number of sub-domains or the linear combination that may be used. For convenience of reference, herein the two sub-domains are called the positive and negative domain; this should not be interpreted to mean that an element of the positive (resp. negative) domain is a positive (resp. negative) number.
0101In the example, the transformed secret is split into two secret pieces, one in the positive domain and the other in the negative domain, that sum to the transformed secret and that each separately leaks no information about the transformed secret or the secret. For example, given any one piece as a fixed value, drawing the other piece with uniform probability leads to a uniform distribution of their sum, which describes the transformed secret. For example with <i>d</i> > 2 sub-domains and a linear combination, for some <i>k < d</i> of pieces to be revealed, given k pieces as fixed values, drawing remaining <i>d</i> - <i>k</i> pieces with uniform probability leads to a uniform distribution of the linear combination of all pieces, which describes the transformed secret. One may use linear all-or-nothing-transforms to get pieces with such properties.
0102Then, a hash value of the transformed secret is computed using hashes 742 and posted as a commitment by the committer 740. Next, hash values for the secret pieces, computed using the hasher 734, are posted. Both types of hash values are computed with a linear hash function that is hard to invert over the union of the domains, for example the one described above with respect to GGH. Finally, one of the secret pieces is revealed using the revealer 736. Finally, the verifier 750 checks that this piece hashes to its corresponding posted hash value and that the posted hash values of the pieces sum to that of the transformed secret.
0103<figref idref="f0010">FIG. 8</figref> shows a block diagram of a relationships diagram corresponding to <figref idref="f0009">FIG. 7</figref>. The secret 820 is transformed into the transformed secret 850 which is hashed to the hash 880. The transformed secret 850 is split into the secret pieces 830-840, such that the secret pieces 830-840 may be combined back to the transformed secret 850. The secret pieces are hashed to the piece hashes 860-870 and may be combined back to the hash 880. Finally, the revealer 810 reveals only some of the secret pieces 830-840.
0104An example construction for zero-knowledge hashing is described with respect to <figref idref="f0011">FIG. 9</figref>. In <figref idref="f0011">FIG. 9</figref>, an example table is shown where each row described possibilities for a j-th element of a type of secret, to be described here, and where each column corresponds to one possibility across the types. Given are <i>m</i> ∈ <i>N</i> and a secret 910. In the example, characters are Peter the prover and Victor the verifier. Both are computationally bounded, preventing Peter from changing his commitments and Victor from discovering secrets by inverting <i>h<sub>M</sub>.</i> Victor knows only the domain of <i>s</i>, so that Victor views <i>s</i> ∈<i><sub>R</sub></i> {0,1}<i><sup>m</sup></i>. Peter begins with setting up secrets. Let <i>S</i> := {0,1} so that <i>s</i> ∈ <i>S<sup>m</sup>.</i> Let <i>α<sub>i</sub></i> := {<i>ix</i>|<i>x</i> ∈ <i>S</i>} for <i>i</i> ∈ {1, 1}. First, peter chooses the auxiliary secret <maths id="math0008"><math display="inline"><mn>920</mn><mspace width="1ex" /><mi>k</mi><mo>:</mo><mo>=</mo><msubsup><mfenced open="{" close="}"><msub><mi>k</mi><mi>j</mi></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><msub><mo>∈</mo><mi>R</mi></msub><msup><mfenced open="{" close="}"><mo>−</mo><mn>1,1</mn></mfenced><mi>m</mi></msup></math><img file="EP4040713A1_D0010.tif" /></maths> and sets <maths id="math0009"><math display="inline"><mi>σ</mi><mo>±</mo><mi>k</mi><mo>:</mo><mo>=</mo><msubsup><mo>×</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mi>α</mi><mo>±</mo><msub><mi>k</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0011.tif" /></maths>. Next, Peter sets the transformed secret <maths id="math0010"><math display="inline"><mn>930</mn><mspace width="1ex" /><mi>t</mi><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>t</mi><mi>j</mi></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>s</mi><mi>j</mi></msub><msub><mi>k</mi><mi>j</mi></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mo>≡</mo></math><img file="EP4040713A1_D0012.tif" /></maths><i>s</i> ⊙ <i>k</i>. Finally, Peter chooses the secret piece <maths id="math0011"><math display="inline"><mn>940</mn><mspace width="1ex" /><msub><mi>r</mi><mn>0</mn></msub><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>r</mi><mrow><mn>0</mn><mo>,</mo><mi>j</mi></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><msub><mo>∈</mo><mi>R</mi></msub><mi>σ</mi><mo>+</mo><mi>k</mi></math><img file="EP4040713A1_D0013.tif" /></maths> and sets the secret piece <maths id="math0012"><math display="inline"><mn>950</mn><mspace width="1ex" /><msub><mi>r</mi><mn>1</mn></msub><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>r</mi><mrow><mn>1</mn><mo>,</mo><mi>j</mi></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mo>:</mo><mo>=</mo><mi>t</mi><mo>−</mo><msub><mi>r</mi><mn>0</mn></msub></math><img file="EP4040713A1_D0014.tif" /></maths>.
0105By construction <i>r</i><sub>1</sub> ∈ <i>σ</i><sub>-<i>k</i></sub> and <i>t</i> ∈ <i>σ</i><sub>+</sub><i><sub>k</sub>.</i> Peter keeps <i>s</i>,<i>t</i>,<i>r</i><sub>0</sub>,<i>r</i><sub>1</sub>,<i>k</i> secret. These have the property that <i>s<sub>j</sub></i> can be recovered from <i>t<sub>j</sub></i>, so this (random) map is invertible, or from (<i>r</i><sub>0,<i>j</i></sub>,<i>r</i><sub>1,<i>j</i></sub>) but no information about <i>s<sub>j</sub></i> is revealed from <i>r</i><sub>0,<i>j</i></sub> alone or <i>r</i><sub>1,<i>j</i></sub> alone, for any given <i>j</i> ∈ [<i>m</i>]. Indeed <i>s<sub>j</sub></i> = abs(<i>t<sub>j</sub></i>) = abs(<i>r</i><sub>0,<i>j</i></sub> + <i>r</i><sub>1,<i>j</i></sub>) whereas Victor views Pr(<i>s<sub>j</sub></i>|<i>r</i><sub><i>i</i>,<i>j</i></sub>) = 1/2 for any given <i>i</i> ∈ {0, 1}, <i>j</i> ∈ [<i>m</i>] as can be seen in the table of possibilities in <figref idref="f0011">FIG. 9</figref>.
0106Peter uses the construction. Let <i>D</i> := <i>σ</i><sub>+<i>k</i></sub> ∪ <i>σ</i><sub>-<i>k</i></sub>. Extend the domain of <i>h<sub>M</sub></i>(<i>·</i>) to <i>D</i> as <i>h<sub>M</sub></i> : <maths id="math0013"><math display="inline"><mi>D</mi><mo>→</mo><msubsup><mi>ℤ</mi><mi>q</mi><mi>n</mi></msubsup></math><img file="EP4040713A1_D0015.tif" /></maths> so that <i>t</i>, <i>r</i><sub>0</sub>, <i>r</i><sub>1</sub> ∈ <i>D</i> can be input to <i>h<sub>M</sub></i>(·). Peter commits to <i>t</i>, and hence also <i>s</i>, by posting <i>T</i> where <i>T</i> := <i>h<sub>M</sub></i>(<i>t</i>). Peter posts <i>R</i><sub>0</sub>, <i>R</i><sub>1</sub> where <i>R<sub>i</sub></i> := <i>h<sub>M</sub></i>(<i>r<sub>i</sub></i>) for <i>i</i> ∈ {0,1} and Victor checks that <i>T</i> = <i>R</i><sub>0</sub> + <i>R</i><sub>1</sub> (mod <i>q</i>); this step may be improved by Peter posting <i>R</i><sub>0</sub> and Victor recovering <i>R</i><sub>1</sub> as <i>T</i> - <i>R</i><sub>0</sub>. Victor chooses <i>c</i> ∈<i><sub>R</sub></i> {0,1}. Peter posts <i>v</i> where <i>v</i> := <i>r<sub>c</sub>.</i> Victor checks that <i>v</i> ∈ <i>D</i> and that <i>h<sub>M</sub></i>(<i>v</i>) = <i>R<sub>c</sub>.</i> If the checks pass, Victor is convinced that with probability 1/2 Peter also knows <i>v'</i> where <i>v'</i> ∈ <i>D</i> and <i>h<sub>M</sub></i>(<i>v'</i>) = <i>R</i><sub>1-<i>c</i></sub> and hence also <i>u</i> such that <i>u</i> ∈ <i>D</i>, <i>u</i> = <i>v</i> + <i>v'</i>, and <i>h<sub>M</sub></i>(<i>u</i>) = <i>T.</i> Because of the hardness of finding collisions for <i>h<sub>M</sub></i> due to the hardness result for (A2) described above, Victor is also convinced that <i>v</i> = <i>r<sub>c</sub></i>,<i>v'</i> = <i>r</i><sub>1-<i>c</i></sub>, <i>u</i> = <i>t.</i> Yet Victor does not learn anything new about <i>s</i> from <i>v</i> due to the property described above. A simulator that gets to select <i>c</i> can set <maths id="math0014"><math display="inline"><msub><mi>r</mi><mrow><mn>1</mn><mo>−</mo><mi>c</mi></mrow></msub><mo>:</mo><mo>=</mo><msubsup><mi>h</mi><mi>M</mi><mrow><mo>−</mo><mn>1</mn></mrow></msubsup><mfenced><mi>T</mi><mo>−</mo><msub><mi>R</mi><mi>c</mi></msub></mfenced></math><img file="EP4040713A1_D0016.tif" /></maths>, which is generally in <maths id="math0015"><math display="inline"><msubsup><mi>ℤ</mi><mi>q</mi><mi>m</mi></msubsup></math><img file="EP4040713A1_D0017.tif" /></maths> and not <i>D</i>, and hide it since <i>r</i><sub>1-<i>c</i></sub> is not revealed.
0107To make a zero-knowledge argument based on the above construction, Peter may convince Victor with probability much higher than 1/2, approaching 1. Increasing the probability requires new technique. Standard round-repeating does not work securely, since by observing multiple draws of <i>r</i><sub>0,<i>j</i></sub>, <i>r</i><sub>1,<i>j</i></sub> Victor learns about <i>t<sub>j</sub></i>, and hence about <i>s<sub>j</sub></i>. Specifically, Victor may infer <i>t<sub>j</sub></i> = 0 or <i>t<sub>j</sub></i> = -1 or <i>t<sub>j</sub></i> = 1 when observations follow draws with replacement from the multisets {-1,0,0,1} or {0, -1} or {0,1} respectively; these are easy to statistically distinguish with high confidence after a small number of draws.
0108To increase the probability, a partly-cheating protocol with a pair of rounds for each bit of security may be used instead. Let <i>w</i> be the security parameter in bits, so that 2<i>w</i> rounds are used. For each pair of rounds <i>k</i> ∈ <i>W</i> := {1,...,<i>w</i>}, peter chooses <i>a<sub>k</sub></i>, <i>b<sub>k</sub></i> ∈<i><sub>R</sub></i> {0,1}. Let <maths id="math0016"><math display="inline"><mi>T</mi><mo>′</mo><mo>:</mo><mo>=</mo><msubsup><mi>T</mi><mi>k</mi><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><mo>−</mo><mi>T</mi></math><img file="EP4040713A1_D0018.tif" /></maths> if <i>a<sub>k</sub></i> = 1 or <i>T'</i> := <i>T</i> otherwise. Peter posts <i>T'</i>, in place of <i>T</i> in the above described construction, once per an argument. Peter commits to <i>r</i><sub><i>i</i>,<i>j</i>,2<i>k</i>+1-<i>a<sub>k</sub></i></sub> corresponding to <i>t<sub>j</sub></i> as usual for <i>i</i> ∈ {0,1}, <i>j</i> ∈ [<i>m</i>] and to <i>r</i><sub><i>b<sub>k</sub></i>,<i>j</i>,2<i>k</i>+<i>a<sub>k</sub></i></sub> ∈<i><sub>R</sub> U</i><sub><i>j</i>,<i>k</i></sub> where <i>U<sub>j,k</sub></i> ∈<i><sub>R</sub></i><maths id="math0017"><math display="inline"><mfenced open="{" close="}"><msubsup><mi>r</mi><mrow><mn>0</mn><mo>,</mo><mi>j</mi></mrow><mo>′</mo></msubsup><mo>,</mo><msubsup><mi>r</mi><mrow><mn>1</mn><mo>,</mo><mi>j</mi></mrow><mo>′</mo></msubsup><mrow><mo>|</mo><mrow><msubsup><mi>t</mi><mi>j</mi><mo>′</mo></msubsup><mo>=</mo><mo>−</mo><msub><mi>t</mi><mi>j</mi></msub></mrow></mrow></mfenced></math><img file="EP4040713A1_D0019.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] is the multiset of <maths id="math0018"><math display="inline"><msubsup><mi>r</mi><mrow><mn>0</mn><mo>,</mo><mi>j</mi></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0020.tif" /></maths>, <maths id="math0019"><math display="inline"><msubsup><mi>r</mi><mrow><mn>1</mn><mo>,</mo><mi>j</mi></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0021.tif" /></maths> values from a column having <maths id="math0020"><math display="inline"><msubsup><mi>t</mi><mi>j</mi><mo>′</mo></msubsup><mo>=</mo><mo>−</mo><msub><mi>t</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0022.tif" /></maths> chosen randomly from the table of possibilities. These result in <i>R</i><sub><i>i</i>,<i>j</i>,2<i>k</i>+1-<i>a<sub>k</sub></i></sub> for <i>i</i> ∈ {0,1}, <i>j</i> ∈ [<i>m</i>] and <i>R</i><sub><i>b<sub>k</sub></i>,<i>j,</i>2<i>k</i>+<i>a<sub>k</sub></i></sub> for <i>j</i> ∈ [<i>m</i>] being posted. Peter posts <maths id="math0021"><math display="inline"><msubsup><mfenced><msub><mi>R</mi><mrow><mn>1</mn><mo>−</mo><msub><mi>b</mi><mrow><mi>k</mi><mo>,</mo><mi>j</mi><mo>,</mo><mn>2</mn><mi>k</mi><mo>+</mo><msub><mi>a</mi><mi>k</mi></msub></mrow></msub></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mo>:</mo><mo>=</mo></math><img file="EP4040713A1_D0023.tif" /></maths><maths id="math0022"><math display="inline"><mi>T</mi><mo>′</mo><mo>−</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mfenced><msub><mi>r</mi><mrow><msub><mi>b</mi><mi>k</mi></msub><mo>,</mo><mi>j</mi><mo>,</mo><mn>2</mn><mi>k</mi><mo>+</mo><msub><mi>a</mi><mi>k</mi></msub></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></mfenced></math><img file="EP4040713A1_D0024.tif" /></maths> which is a cheat-vector generally having a <i>h<sub>M</sub></i>(<i>·</i>) preimage in <maths id="math0023"><math display="inline"><msubsup><mi>ℤ</mi><mi>q</mi><mi>m</mi></msubsup></math><img file="EP4040713A1_D0025.tif" /></maths>, not <i>D</i>. The protocol ensures Victor never sees this preimage. Victor posts a challenge <i>c</i> of length <i>w</i> bits. Peter posts <i>c</i><sub>0</sub>, <i>c</i><sub>1</sub> of length <i>w</i> bits each having <i>c</i> = <i>c</i><sub>0</sub> ⊕ <i>c</i><sub>1</sub> and <i>c<sub>a<sub2>k</sub2></sub></i>[<i>k</i>] = <i>b<sub>k</sub></i> for <i>k</i> ∈ <i>W</i>, which can be solved for <i>c<sub>a<sub2>k</sub2></sub></i>[<i>k</i>] and then for <i>c</i><sub>1-<i>a<sub>k</sub></i></sub>[<i>k</i>]<i>.</i> Next, Peter posts <i>c</i><sub>0</sub>,<i>c</i><sub>1</sub> and reveals <i>r</i><sub><i>c<sub>i</sub></i>[<i>k</i>],<i>j</i>,2<i>k</i>+<i>i</i></sub> for <i>i</i> ∈ {0,1}, <i>j</i> ∈ [<i>m</i>], <i>k</i> ∈ <i>W.</i> Finally, Victor verifies the argument by checking that <i>c</i>,<i>r</i>,<i>R</i>,<i>T'</i> posts match, namely that <i>c</i> = <i>c</i><sub>0</sub> ⊕ <i>c</i><sub>1</sub>, that <maths id="math0024"><math display="inline"><mi>T</mi><mo>′</mo><mo>=</mo><msubsup><mfenced><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>0</mn></mrow><mn>1</mn></msubsup><msub><mi>R</mi><mrow><mi>i</mi><mo>,</mo><mi>j</mi><mo>,</mo><mn>2</mn><mi>k</mi></mrow></msub></mstyle></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0026.tif" /></maths> and <maths id="math0025"><math display="inline"><mo>−</mo><mi>T</mi><mo>′</mo><mo>=</mo><msubsup><mfenced><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>0</mn></mrow><mn>1</mn></msubsup><msub><mi>R</mi><mrow><mi>i</mi><mo>,</mo><mi>j</mi><mo>,</mo><mn>2</mn><mi>k</mi><mo>+</mo><mn>1</mn></mrow></msub></mstyle></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0027.tif" /></maths> for <i>k</i> ∈ <i>W</i>, and that <maths id="math0026"><math display="inline"><msubsup><mfenced><msub><mi>R</mi><mrow><msub><mi>c</mi><mi>i</mi></msub><mfenced open="[" close="]"><mi>k</mi></mfenced><mo>,</mo><mi>j</mi><mo>,</mo><mn>2</mn><mi>k</mi><mo>+</mo><mi>i</mi></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mfenced><msub><mi>r</mi><mrow><msub><mi>c</mi><mi>i</mi></msub><mfenced open="[" close="]"><mi>k</mi></mfenced><mo>,</mo><mi>j</mi><mo>,</mo><mn>2</mn><mi>k</mi><mo>+</mo><mi>i</mi></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></mfenced></math><img file="EP4040713A1_D0028.tif" /></maths> for <i>i</i> ∈ {0,1}, <i>k</i> ∈ <i>W</i>. The inclusion of the rounds (2<i>k</i> + <i>a<sub>k</sub></i>)<sub><i>k</i>∈<i>W</i></sub>, in which Peter uses -<i>t</i> and -<i>T</i>, has a balancing effect on observed distribution of <i>r</i><sub><i>i</i>,<i>j</i>,<i>k</i></sub> values: Victor's observations follow draws with replacement from the multiset {-1,0,0,1} <i>for j</i> ∈ [<i>m</i>], <i>k</i> ∈ <i>W</i>. Hence the same <i>t</i>, <i>T</i> can be securely used in all pairs of rounds.
0109As one round in each pair is effectively a response to a challenge, passing verification convinces Victor with probability 1 - 2<sup>-<i>w</i></sup> that Peter knows corresponding <i>s</i>,<i>t</i> where <i>h<sub>M</sub></i>(<i>t</i>) = <i>T.</i> As for the construction, Victor does not learn anything new about <i>s</i>. A simulator that gets to select <i>c</i> can hide two cheat values, one for each round of a pair, in a 2 × 2 matrix with a row for each of <maths id="math0027"><math display="inline"><msubsup><mi>r</mi><mn>0</mn><mo>′</mo></msubsup></math><img file="EP4040713A1_D0029.tif" /></maths>, <img file="EP4040713A1_D0030.tif" /> and a columns for each round of the pair, along a row or diagonal that is not revealed. The structure of the argument for a pair of rounds is such that effectively Victor gets to choose whether Peter would expose <i>r'</i> values along a diagonal or a row of the 2 × 2 matrix, whereas Peter gets to choose which diagonal or row respectively.
0110The described zero-knowledge hashing arguments may be made non-interactive using standard techniques. A use of one known method for converting interactive arguments to non-interactive ones is described. Using the technique of signatures of knowledge, the non-interactive argument proceeds as follows. Let <i>H<sub>w</sub></i> be a cryptographic hash function (not <i>h<sub>M</sub></i>) from arbitrary bit strings to bit strings of length <i>w</i>, that is <i>H<sub>w</sub></i> : {0,1}<sup>∗</sup> → {0,1}<i><sup>w</sup></i>, and let || be the bit string concatenation operator. A parameter appearing under <i>H<sub>w</sub></i>(·) is understood as its bit string representation. Let <i>P</i><sub>∗</sub> be a tuple of all public parameters, and let <i>R</i><sub>∗</sub> be a tuple of all <i>R</i>-values posted by Peter in the interactive argument. Instead of Victor's challenge and Peter's response, Peter posts (<i>c</i>,<i>r</i>) where <maths id="math0028"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><msub><mi>H</mi><mi>w</mi></msub><mfenced><msub><mi>P</mi><mo>*</mo></msub><mrow><mo>‖</mo><msub><mi>R</mi><mo>*</mo></msub><mo>‖</mo></mrow><mi>T</mi><mo>′</mo></mfenced></math><img file="EP4040713A1_D0031.tif" /></maths>, <maths id="math0029"><math display="inline"><mi>r</mi><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>r</mi><mrow><msub><mi>c</mi><mi>k</mi></msub><mo>,</mo><mi>j</mi><mo>,</mo><mi>k</mi></mrow></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn><mo>,</mo><mi>k</mi><mo>=</mo><mn>1</mn></mrow><mrow><mi>m</mi><mo>,</mo><mi>w</mi></mrow></msubsup></math><img file="EP4040713A1_D0032.tif" /></maths> and Victor checks that <i>H<sub>w</sub></i>(<i>P</i><sub>∗</sub>||<i>R</i><sub>∗</sub>||<i>T"</i>) = <i>c</i> where <maths id="math0030"><math display="inline"><mi>T</mi><mo>"</mo><mo>:</mo><mo>=</mo><msubsup><mfenced><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>k</mi><mo>=</mo><mn>1</mn></mrow><mi>w</mi></msubsup><mfenced><msub><mi>h</mi><mi>M</mi></msub><mfenced><msub><mi>r</mi><mrow><msub><mi>c</mi><mi>k</mi></msub><mo>,</mo><mi>j</mi><mo>,</mo><mi>k</mi></mrow></msub></mfenced><mo>+</mo><msub><mi>R</mi><mrow><mn>1</mn><mo>−</mo><msub><mi>c</mi><mi>k</mi></msub><mo>,</mo><mi>j</mi><mo>,</mo><mi>k</mi></mrow></msub></mfenced></mstyle></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0033.tif" /></maths>.
0111The described zero-knowledge hashing arguments of knowledge may be converted to one of communication as follows. In addition to the posts <i>R</i><sub>0</sub>, <i>R</i><sub>1</sub>, Peter verifiably communicates <i>r</i><sub>0</sub>,<i>r</i><sub>1</sub> as opaque messages <i>M</i><sub>0</sub>,<i>M</i><sub>1</sub> with secret keys <i>K</i><sub>0</sub>,<i>K</i><sub>1</sub> respectively to Robert, the receiver. When Victor chooses <i>c</i> and Peter posts <i>v</i> := <i>r<sub>c</sub></i>, observers may verify whether <i>r<sub>c</sub></i> matches <i>M<sub>c</sub></i> in the corresponding communication, and/or Peter posts <i>K<sub>c</sub></i> to allow observers to infer <i>M<sub>c</sub></i>. Following this, Victor is convinced that with same probability Robert also received <i>r</i><sub>1-<i>c</i></sub>, so Victor views Robert and Peter the same, and the argument conclusions apply to both Peter and Robert.
0112A verifiable commitment to a message may be made using a zero-knowledge argument, as described, for its hash. This is a commitment because of the hardness of finding a preimage for a collision resistant hash function, like the uses in the present examples, and is verifiable because the argument is verifiable as described above. Different commitments, based on the same zero-knowledge hashing, may be made to the same message by using any of a number of well-known techniques, including padding and HMAC (hash-based message authentication codes). Multiple commitments may be organized in a chain, a tree, or similar structures.
0113The described zero-knowledge hashing may be extended to streams. So far the zero-knowledge hash applied to messages of length <i>m</i> bits. <i>m</i> can be increased to fit a message of any size; doing so would require more memory to accommodate larger <i>r</i><sub><i>i</i>,<i>j</i></sub>, <i>M</i> as well as processing the entire stream even if validation would fail on the first few bits. Alternatively, zero-knowledge hashing may be used in well-known incremental hashing schemes. Thus, zero-knowledge hashing is applied to each block of the stream separately, and an incremental hashing is used to combine the hashes of the blocks. The size of the block may be chosen based on various considerations including resulting level of security, streaming latency, and required computational resources. One may also use message padding to ensure hash values for two blocks differ even if their non-padded messages do not. The structure of an incremental hashing scheme allows this combination to be done in parallel or in a distributed fashion.
0114Incremental hashing may be applied with the described zero-knowledge hashing as follows. Let <i>b</i> be the block size in bits, <i>N</i> be the number of blocks in the stream, and <i>s</i> ∈ <img file="EP4040713A1_D0034.tif" /> where <i>N</i> ≤ 2<i><sup>s</sup></i>. A zero-knowlegde hash <i>h</i> is applied to a string <maths id="math0031"><math display="inline"><msubsup><mi>x</mi><mi>i</mi><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><mrow><mo>〈</mo><mrow><mi>i</mi><mo>,</mo><msub><mi>x</mi><mi>i</mi></msub></mrow><mo>〉</mo></mrow></math><img file="EP4040713A1_D0035.tif" /></maths> of length <i>m</i> := <i>s</i> + <i>b</i> bits where <i>x<sub>i</sub></i> is the content of block <i>i</i> (zero-based) and where <i>m</i> is the same as in our zero-knowledge hashing. The hashes are then combined using an incremental hash <i>H</i>. Bellare and Micciancio described a few options in a well-known paper dated 1997. One option is AdHash, with a parameter <i>M'</i> of <i>k</i> bits, defined by <maths id="math0032"><math display="inline"><mi>H</mi><mfenced><msub><mi>x</mi><mn>1</mn></msub><mo>,</mo><mo>…</mo><mo>,</mo><msub><mi>x</mi><mi>N</mi></msub></mfenced><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></msubsup><mrow><mi>h</mi><mfenced><msubsup><mi>x</mi><mi>i</mi><mo>′</mo></msubsup></mfenced></mrow></mstyle></math><img file="EP4040713A1_D0036.tif" /></maths> mod <i>M'</i>. An example choice is <i>s</i> = 64, <i>k</i> = <i>s</i><sup>3/2</sup> = 512. Another option is LtHash, which has a parameter <i>p</i> of <i>l</i> bits, works with <i>h</i> : <maths id="math0033"><math display="inline"><msup><mfenced open="{" close="}"><mn>0,1</mn></mfenced><mi>m</mi></msup><mo>→</mo><msubsup><mi>ℤ</mi><mi>p</mi><mi>k</mi></msubsup></math><img file="EP4040713A1_D0037.tif" /></maths>, and is defined by <maths id="math0034"><math display="inline"><mi>H</mi><mfenced><msub><mi>x</mi><mn>1</mn></msub><mo>,</mo><mo>…</mo><mo>,</mo><msub><mi>x</mi><mi>N</mi></msub></mfenced><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></msubsup><mrow><mi>h</mi><mfenced><msubsup><mi>x</mi><mi>i</mi><mo>′</mo></msubsup></mfenced></mrow></mstyle></math><img file="EP4040713A1_D0038.tif" /></maths> mod <i>p</i> over <maths id="math0035"><math display="inline"><msubsup><mi>ℤ</mi><mi>p</mi><mi>k</mi></msubsup></math><img file="EP4040713A1_D0039.tif" /></maths>. Bellare and Micciancio paper noted in their paper that the choice <i>k</i> = 500, <i>l</i> = 110 is sufficient in practice.
0115The described construction may be generalized in multiple ways, including the following examples. A numeric base <i>a</i> > 2 may be used. In this case, <i>S</i> := {0,1,...,<i>a</i>-1}<i><sup>m</sup></i> and the rest of the construction for <i>α</i><sub>±1</sub>, <i>k</i>, <i>σ</i><sub>±<i>k</i></sub>, <i>t</i>, <i>r</i><sub>0</sub>, <i>r</i><sub>1</sub>, <i>D</i> remains the same. The construction will work when a is small enough that (A2) remains hard for <i>x</i> ∈ <i>D</i> \ {0}<i><sup>m</sup></i>. Similarly, one may also use a varying base <maths id="math0036"><math display="inline"><msubsup><mfenced><msub><mi>a</mi><mi>j</mi></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0040.tif" /></maths> with <i>S<sub>j</sub></i> := {0,1,...,<i>a<sub>j</sub></i> - 1}, <maths id="math0037"><math display="inline"><mi>S</mi><mo>:</mo><mo>=</mo><msubsup><mo>×</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><msub><mi>S</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0041.tif" /></maths>, <i>α</i><sub><i>i</i>,<i>j</i></sub> := {<i>ix</i>|<i>x</i> ∈ <i>S<sub>j</sub></i>} for <i>i</i> ∈ {-1,1}, <maths id="math0038"><math display="inline"><mi>σ</mi><mo>±</mo><mi>k</mi><mo>:</mo><mo>=</mo><msubsup><mo>×</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mi>α</mi><mo>±</mo><msub><mi>k</mi><mi>j</mi></msub><mo>,</mo><mi>j</mi></math><img file="EP4040713A1_D0042.tif" /></maths>, <i>D<sub>j</sub></i> := <i>α</i><sub><i>-</i>1,<i>j</i></sub> ∪ <i>α</i><sub>1,<i>j</i></sub>, and <maths id="math0039"><math display="inline"><mi>D</mi><mo>:</mo><mo>=</mo><msubsup><mo>×</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><msub><mi>D</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0043.tif" /></maths>. The above described techniques for making a zero-knowledge argument, a non-interactive argument, verifiable communication of the argument, zero-knowledge hash commitments, and verifying a stream apply similarly.
0116A different structure for the challenge <i>c</i> may be used. In this case, a formula where <i>c</i> is a bijective function of <i>c<sub>i</sub></i> given <i>c</i><sub>1-<i>j</i></sub> for <i>i</i> ∈ {0,1} can be used in place of ⊕, such as splitting the binary form of <i>c</i> into components of <i>b</i> bits each and using addition modulo 2<i><sup>b</sup></i> per component. These options apply in this construction as well as in other sigma-protocols.
0117Both the zero-knowledge construction and argument may be applied to a universal hash function <i>h</i><sub><i>r</i>,<i>M</i></sub>(<i>·</i>). Let <i>h<sub>M</sub></i>(<i>r</i>,<i>s</i>) := <i>h</i><sub><i>r</i>,<i>M</i></sub>(<i>s</i>). The difference between <i>h<sub>M</sub></i>(<i>·</i>) and <i>h<sub>M</sub></i>(·, ·) is that the former is linear in one variable, satisfying <i>h<sub>M</sub></i>(<i>s</i><sub>1</sub>) + <i>h<sub>M</sub></i>(<i>s</i><sub>2</sub>) = <i>h<sub>M</sub></i>(<i>s</i><sub>1</sub> + <i>s</i><sub>2</sub>), whereas the latter in two, satisfying <i>h<sub>M</sub></i>(<i>r</i><sub>1</sub>, <i>s</i><sub>1</sub>) + <i>h<sub>M</sub></i>(<i>r</i><sub>2</sub>, <i>s</i><sub>2</sub>) = <i>h<sub>M</sub></i>(<i>r</i><sub>1</sub> + <i>r</i><sub>2</sub>, <i>s</i><sub>1</sub> + <i>s</i><sub>2</sub>). Hence, the universal hash function may be substituted for the non-universal one in the construction and argument by considering its two variables in linear operations.
0118Zero-knowledge hashing argument methods described herein may be built on secure linear/affine hashing. One example scheme is that described herein due to GGH with parameters <i>n</i>, <i>m</i>, <i>q.</i> A second scheme involves hash functions <i>h<sub>M</sub></i>, <i>h</i><sub><i>r</i>,<i>M</i></sub> that are extended to <maths id="math0040"><math display="inline"><msup><mfenced open="{" close="}"><mn>0</mn><mo>,</mo><mo>…</mo><mo>,</mo><mi>d</mi><mo>−</mo><mn>1</mn></mfenced><mi>m</mi></msup><mo>→</mo><msubsup><mi>ℤ</mi><mi>q</mi><mi>n</mi></msubsup></math><img file="EP4040713A1_D0044.tif" /></maths> with <i>d</i> ∈ <img file="EP4040713A1_D0045.tif" /> and <maths id="math0041"><math display="inline"><mi>n</mi><mfrac><mrow><mi>log</mi><mspace width="1ex" /><mi>q</mi></mrow><mrow><mi>log</mi><mspace width="1ex" /><mi>d</mi></mrow></mfrac><mo><</mo><mi>m</mi></math><img file="EP4040713A1_D0046.tif" /></maths>. A third scheme, whose security was analyzed by Micciancio, involves using a block-circulant matrix <i>M</i> where <i>n</i> divides <i>m</i>, allowing reducing the storage size of <i>M</i> from <i>m</i> × <i>n</i> to <i>m</i> as well as speeding up the hashing using the number-theoretic transform (NTT), a modular-arithmetic version of the discrete Fourier transform (DFT), which may be efficently implemented using the fast Fourier transform (FFT). A fourth scheme, due to Lyubashevsky and Micciancio, involves using a block-matrix <i>M</i> where each block is chosen at random as a linear transformation to which ideal lattices are invariant. A similar scheme is due to Peikert and Rosen. A fifth scheme called SWIFFT, due to Lyubashevsky and Micciancio and Peikert and Rosen, is a highly optimized version of the previous scheme. A standard assumption of hardness applies to the problem of finding collisions as well as to the problem of finding a pre-image for the hash function in these settings. Moreover, these schemes are considered secure against quantum computational attacks. Finally, a secure additively-homomorphic hash function <i>h</i>(·) may be used in place of <i>h<sub>M</sub></i>(<i>·</i>) in zero-knowledge hashing arguments described herein.
0119Various zero-knowledge arguments are described herein. In zero-knowledge arguments described herein, one round is detailed and the generalization to multiple rounds is understood to follow using described techniques unless said otherwise in context. Herein, in zero-knowledge hashing arguments, pre-images (<i>t</i> values) and their parts (<i>r</i><sub>±</sub> values) are verified to be in their domain (<i>D<sup>m</sup></i>), unless said otherwise in context. Herein, notations such as <i>s</i><sup>[<i>a</i>]</sup>, <i>t</i><sup>[<i>a</i>]</sup>, <i>k</i><sup>[<i>a</i>]</sup>, <i>σ</i><sup>[<i>a</i>]</sup>, <i>r</i><sup>[<i>a</i>]</sup> are used to denote values with an additional index <i>a.</i> A signed-modulus notation <i>a</i> smod <i>n</i> := sgn(<i>a</i>)(|<i>a</i>| mod <i>n</i>), defined for <i>a</i> ∈ <img file="EP4040713A1_D0047.tif" /> , <i>n</i> ∈ <img file="EP4040713A1_D0048.tif" /> , is used as well. Mathematical relations with free indexes apply to each combination of indexes in their domain. Unless said otherwise in context, a free index <i>i</i> ranges over [<i>n</i>] and a free index <i>j</i> ranges over [<i>m</i>]. Operations such as absolute value | · | or floor └·┘ of a vector as well as operations such as multiplication ⊙ or division / of vectors are each taken element-wise. The operation ÷, /, +, - used to denote division without remainder, quotient, addition, and subtraction; when these operations are used on vectors, they apply to numbers corresponding to the vectors, unless said otherwise in context. Unless said otherwise, parameters are set such that pre-image problems are hard per said standard assumption.
0120Herein, a challenge refers to means of affecting what secrets that their holder committed to would need to be revealed for verification to pass, such that the choice of secrets to reveal is unpredictable to and not controlled by the holder at the time of commitment to the secrets. One example for a challenge is a random value used to select which secrets would be revealed. A second example is the value of a secure hash function in a Fiat-Shamir transform of a given protocol. A third example is an extension of the first or second example using a pseudo-random number generator seeded with their value, resulting in a longer sequence of challenges. A fourth example is using oblivious-transfer (OT) or <i>k</i>-out-of-<i>n</i> OT for selecting to reveal some of the secrets possibly with some probability. A fifth example is an extension of the fourth example by extending OT, resulting in a longer sequence of OT.
0121Zero-knowledge hashing argument described herein may be composed in a manner similar to connecting circuit gates. A secret for which one zero-knowledge hashing argument is made may be viewed as the output of the argument, and this output may be used as input to other such arguments. For example, zero-knowledge hashing arguments for two secrets may be followed by a zero-knowledge hashing argument for modular addition and then by a zero-knowledge hashing argument for modular multiplication of numbers composed by elements, both described herein. In composing arguments, some elements of some of the arguments may be permuted to align their position with that of elements of other arguments, in order to align outputs of some arguments with inputs of others, effectively wiring them as circuit gates. This may be done using arguments for permutation of elements, described herein.
0122A first example zero-knowledge hashing argument for binary elements, in the ring Z2, is described. A splitting of a secret in <maths id="math0042"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0049.tif" /></maths> into two pieces in <maths id="math0043"><math display="inline"><mo>±</mo><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0050.tif" /></maths>, such that the pieces are embedded in <maths id="math0044"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0051.tif" /></maths> via an appropriate mapping and only one piece is revealed, may be used in a zero-knowledge argument that the secret is in <maths id="math0045"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0052.tif" /></maths>. Methods for using zero-knowledge hashing to obtain a zero-knowledge embedding of <maths id="math0046"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0053.tif" /></maths> in <maths id="math0047"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0054.tif" /></maths> are described here. Let <maths id="math0048"><math display="inline"><mi>S</mi><mo>:</mo><mo>=</mo><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0055.tif" /></maths>. Let <i>α<sub>i</sub></i> := {<i>ix</i>|<i>x</i> ∈ <i>S</i>} for <i>i</i> ∈ {-1,1}. Let <i>D</i> := <i>α</i><sub>1</sub> ∪ <i>α</i><sub>-1</sub>. Let <i>s</i> := (<i>s</i><sub>1</sub>,...,<i>s<sub>m</sub></i>) ∈ <i>S<sup>m</sup>.</i> Let <i>k</i> := (<i>k</i><sub>1</sub>,...,<i>k<sub>m</sub></i>) ∈<i><sub>R</sub></i> {-1,1}<i><sup>m</sup></i>. Let <maths id="math0049"><math display="inline"><mi>σ</mi><mo>±</mo><mi>k</mi><mo>:</mo><mo>=</mo><msubsup><mo>×</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mi>α</mi><mo>±</mo><msub><mi>k</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0056.tif" /></maths>. Let <i>t</i> := (<i>t</i><sub>1</sub>,...,<i>t<sub>m</sub></i>) where <i>t<sub>j</sub></i> := <i>s<sub>j</sub>k<sub>j</sub></i> for <i>j</i> ∈ [<i>m</i>]. Let <i>r</i><sub>+</sub> := (<i>r</i><sub>+,1</sub>,...,<i>r</i><sub>+,<i>m</i></sub>) ∈ <i>σ</i><sub>+<i>k</i></sub>, <i>r</i><sub>-</sub> := (<i>r</i><sub>-,1</sub>,...,<i>r</i><sub>-,<i>m</i></sub>) ∈ <i>σ</i><sub>-<i>k</i></sub> be pieces randomly chosen with <i>r</i><sub>+,<i>j</i></sub> + <i>r</i><sub>-,<i>j</i></sub> = <i>t<sub>j</sub></i> for <i>j</i> ∈ [<i>m</i>], i.e. from the set {(<i>r</i><sub>+</sub>, <i>r</i><sub>-</sub>)|<i>r</i><sub>+</sub> ∈ <i>σ</i><sub>+<i>k</i></sub>, <i>r</i><sub>-</sub> ∈ <i>σ</i><sub>-<i>k</i></sub>, <i>r</i><sub>+</sub> + <i>r</i><sub>-</sub> = <i>t</i>}. Let <i>r</i><sub>0</sub>, <i>r</i><sub>1</sub> be a random permutation of <i>r</i><sub>+</sub>, <i>r</i><sub>-</sub> of which one is revealed by Peter to Victor. This results in the following table of possibilities appearing in <figref idref="f0011">FIG. 9</figref>. Then <i>s</i> is determined by <i>t</i> while Victor learns nothing about <i>s</i> from one of <i>r</i><sub>0</sub>, <i>r</i><sub>1</sub>.
0123Moreover, a partially cheating protocol for a pair of rounds, each with its own choices of <i>r</i><sub>±</sub>, may be used in a zero-knowledge argument of knowledge of a pre-image of <i>h<sub>M</sub></i>(<i>t</i>). It may also be used in an argument of knowledge of a pre-image of <i>h</i><sub><i>r</i>,<i>M</i></sub>(<i>t</i>) by accounting for the linearity of <i>h</i><sub><i>r</i>,<i>M</i></sub> in <i>r</i>, which here is distinct from <i>r</i><sub>+</sub>, <i>r</i><sub>-</sub>. For example, for <i>s<sub>j</sub></i> = 0 (resp. <i>s<sub>j</sub></i> = 1), Peter may set either <i>r</i><sub>±,<i>j</i></sub> ∈<i><sub>R</sub></i> {(0, 0), (<i>k<sub>j</sub></i>, -<i>k<sub>j</sub></i>)} or <i>r</i><sub>±,<i>j</i></sub> = (0,0) as a random choice in each round (resp. set <i>r</i><sub>±,<i>j</i></sub> ∈<i><sub>R</sub></i> {(0,<i>k<sub>j</sub></i>), (<i>k<sub>j</sub></i>,0)} in each round), and use said protocol on the pair of rounds to reveal <maths id="math0050"><math display="inline"><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0057.tif" /></maths>, <maths id="math0051"><math display="inline"><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0058.tif" /></maths> with a multiset-drawn distribution <maths id="math0052"><math display="inline"><mfenced><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><msub><mo>∈</mo><mi>R</mi></msub><mfenced open="{" close="}"><mfenced><mn>0,0</mn></mfenced><mfenced><mn>0,0</mn></mfenced><mfenced><mn>0</mn><msub><mi>k</mi><mi>j</mi></msub></mfenced><mfenced><msub><mi>k</mi><mi>j</mi></msub><mn>0</mn></mfenced></mfenced></math><img file="EP4040713A1_D0059.tif" /></maths> viewed by Victor. Other balanced distributions for <maths id="math0053"><math display="inline"><mfenced><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0060.tif" /></maths> may be used as well, e.g. one with a non-uniform probability of drawing from the multiset shown. Here, <maths id="math0054"><math display="inline"><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0061.tif" /></maths> (resp. <maths id="math0055"><math display="inline"><msubsup><mi>r</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0062.tif" /></maths>) is a revealing of one of <i>r</i><sub>±,<i>j</i></sub> of the first (resp. second) round in the pair. Effectively, the protocol lets Peter avoid revealing -<i>k<sub>j</sub></i> and present a balanced, i.e. independent of <i>s<sub>j</sub></i>, distribution to Victor. Thus, Peter only reveals <i>k<sub>j</sub></i> and teaches Victor nothing about <i>s<sub>j</sub></i> even in many pairs of rounds.
0124The structure of statements for this construction is described. The GS includes the hash values <i>h<sub>M</sub></i>(<i>t</i>), <i>h<sub>M</sub></i>(<i>r</i><sub>+</sub>), <i>h<sub>M</sub></i>(<i>r</i><sub>-</sub>) of <i>t</i>,<i>r</i><sub>+</sub>,<i>r</i><sub>-</sub> for each round; their connection may be verified by checking that <i>h<sub>M</sub></i>(<i>t</i>) = <i>h<sub>M</sub></i>(<i>r</i><sub>+</sub>) + <i>h<sub>M</sub></i>(<i>r</i><sub>-</sub>). The PS includes the revealings in the protocol described; the revealing of <i>r</i><sub>0</sub> or <i>r</i><sub>1</sub> in each round provides the pieces evidence, which is verified by checking that each revealed vector is in the described expected domain and that the distribution of vector elements follows the described expected distribution. The IS includes a description of the instruction, namely one declaring that the secret vector is composed of binary elements and referencing the GS and the PS; it is verified by checking that the GS and the IS are ones for binary elements as described.
0125A second example zero-knowledge hashing for o-ary elements, in the ring <maths id="math0056"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0063.tif" /></maths>, is described. A zero-knowledge embedding of <maths id="math0057"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0064.tif" /></maths> in <maths id="math0058"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0065.tif" /></maths>, as described herein, may be extened to a zero-knowledge embedding of <maths id="math0059"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0066.tif" /></maths> in <maths id="math0060"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0067.tif" /></maths>. Methods for using zero-knowledge hashing to obtain a zero-knowledge embedding of <maths id="math0061"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0068.tif" /></maths> in <maths id="math0062"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0069.tif" /></maths> are described here. Peter makes a zero-knowledge hashing argument for <i>o</i>-ary elements as follows. Let <maths id="math0063"><math display="inline"><mi>S</mi><mo>:</mo><mo>=</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0070.tif" /></maths> for <i>o</i> « <i>q</i>, let <i>α<sub>i</sub></i>, <i>D</i>, <i>s</i>, <i>k</i>, <i>σ</i><sub>±</sub>, <i>r</i><sub>±</sub> be defined for this <i>S</i> as was defined in the first example zero-knowledge hashing argument, and consider the case <i>k<sub>j</sub></i> = 1 for which <i>t<sub>j</sub></i> = <i>s<sub>j</sub></i>. For each round, where round indexes are dropped, Peter sets <maths id="math0064"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>c</mi><mi>j</mi></msub></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mo>∈</mo><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0071.tif" /></maths> where <i>c<sub>j</sub></i> = 1 if <i>r</i><sub>+,<i>j</i></sub> + <i>r</i><sub>-,<i>j</i></sub> < 0 and otherwise <i>c<sub>j</sub></i> = 0, and argues knowledge of a pre-image in <maths id="math0065"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0072.tif" /></maths> of <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>) as described in the first example zero-knowledge hashing argument, thus posting <i>y</i>. Now, <i>r</i><sub>+</sub> + <i>r</i><sub>-</sub> + <i>oc</i> = <i>t</i> holds, while revealing one of <i>r</i><sub>±</sub> teaches nothing about <i>t</i>, for each round. For each pair of rounds, Peter follows the partially cheating protocol described in the first example zero-knowledge hashing argument to argue knowledge of a pre-image of <i>h<sub>M</sub></i>(<i>t</i>), thus posting <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>r</i><sub>+</sub>), <i>h</i><sup>[3]</sup> := <i>h<sub>M</sub></i>(<i>r</i><sub>-</sub>) for each round. In response to a challenge for each pairs of rounds, Peter reveals one of <i>r</i><sub>±</sub> for each round as described in the protocol in the first example zero-knowledge hashing argument. Victor verifies this argument for o-ary elements by checking said arguments of knowledge and that <i>h</i><sup>[1]</sup> = <i>h</i><sup>[2]</sup> + <i>h</i><sup>[<i>3</i>]</sup> + <i>oy</i> mod <i>q</i>. In more detail, where such details should be understood when not elaborated in arguments, Victor checks the argument for <i>y</i> for each round, that <i>h</i><sup>[1]</sup> is common to all rounds, that revealings correspond to challenges, that each revealed <i>r</i><sub>+</sub> (resp. <i>r</i><sub>-</sub>) is in <i>D</i> and hashes to <i>h</i><sup>[2]</sup> (resp. <i>h</i><sup>[3]</sup>), and that <i>h</i><sup>[1]</sup> = <i>h</i><sup>[2]</sup> + <i>h</i><sup>[3]</sup> + <i>oy</i> mod <i>q</i> holds for each round. Since <i>h</i><sup>[1]</sup> is common to all rounds, Peter need only post it once for the argument. Since <i>h</i><sup>[1]</sup> = <i>h</i><sup>[2]</sup> + <i>h</i><sup>[3]</sup> + <i>oy</i> mod <i>q</i> must hold for verification to pass, Peter may skip posting <i>h</i><sup>[<i>3</i>]</sup> and Victor may recover <i>h</i><sup>[3]</sup> as <i>h</i><sup>[1]</sup> - <i>h</i><sup>[2]</sup> - <i>oy</i> mod <i>q</i>, thus reducing communication demands of the argument.
0126This method may be modified as follows. The argument may be made similarly in the case <i>k<sub>j</sub></i> = -1 for which <i>t<sub>j</sub></i> = -<i>s<sub>j</sub></i>, with <i>c<sub>j</sub></i> = 1 if <i>r</i><sub>+,<i>j</i></sub> + <i>r</i><sub>-,<i>j</i></sub> > 0 and otherwise <i>c<sub>j</sub></i> = 0, with <i>r</i><sub>+</sub> + <i>r</i><sub>-</sub> - <i>oc</i> = <i>t</i> mod <i>o</i> and <i>h</i><sup>[1]</sup> = <i>h</i><sup>[2]</sup> + <i>h</i><sup>[3]</sup> - <i>oy</i> mod <i>q</i> holding, and with <i>h</i><sup>[3]</sup> recovered as <i>h</i><sup>[1]</sup> - <i>h</i><sup>[2]</sup> + <i>oy</i> mod <i>q</i> instead.
0127The structure of statements for this construction is described. The GS includes the hash values <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup>, <i>h</i><sup>[3]</sup> of <i>t</i>, <i>r</i><sub>+</sub>, <i>r</i><sub>-</sub>, <i>c</i> for each round; their connection may be verified e.g. by checking that <i>h</i><sup>[1]</sup> = <i>h</i><sup>[2]</sup> + <i>h</i><sup>[3]</sup> + <i>oy</i> mod <i>q</i> as described in one case. The PS includes the revealings described; the revealing of <i>r</i><sub>0</sub> or <i>r</i><sub>1</sub> in each round provides the pieces evidence, which is verified by checking that each revealed vector is in the described expected domain and that the distribution of vector elements follows the described expected distribution. The IS includes a description of the instruction, namely one declaring that the secret vector is composed of <i>o</i>-ary elements and referencing the GS and the PS, as well as the hash value <i>y</i> of <i>c</i>; it is verified by checking that the GS and the IS are ones for <i>o</i>-ary elements as described. The structure of statements for other instructions described herein arises similarly.
0128An example method of extending this construction to more pieces is described. A construction with <i>n</i> + 1 pieces <maths id="math0066"><math display="inline"><mi>R</mi><mo>′</mo><mo>:</mo><mo>=</mo><msubsup><mfenced><msubsup><mi>r</mi><mi>i</mi><mo>′</mo></msubsup></mfenced><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mrow><mi>n</mi><mo>+</mo><mn>1</mn></mrow></msubsup></math><img file="EP4040713A1_D0073.tif" /></maths> starting from one with <i>n</i> pieces <maths id="math0067"><math display="inline"><mi>R</mi><mo>:</mo><mo>=</mo><msubsup><mfenced><msub><mi>r</mi><mi>i</mi></msub></mfenced><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>n</mi></msubsup></math><img file="EP4040713A1_D0074.tif" /></maths> may be obtained as follows. First, a random <i>u</i> ∈ [<i>n</i>] may be chosen, and e.g. a choice such that sgn(<i>r<sub>u</sub></i>) is not a majority among <maths id="math0068"><math display="inline"><msubsup><mfenced><mi>sgn</mi><mfenced><msub><mi>r</mi><mi>i</mi></msub></mfenced></mfenced><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>n</mi></msubsup></math><img file="EP4040713A1_D0075.tif" /></maths> may be used to ensure a (near) balance between positive and negative signs of items in <i>R'</i>, e.g. to obtain a smaller carry domain. Initially for <i>n</i> = 2 and thereafter for <i>n</i> > 2, it holds that <maths id="math0069"><math display="inline"><msub><mi>r</mi><mi>u</mi></msub><mo>∈</mo><mo>±</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0076.tif" /></maths>. Hence, <i>r<sub>u</sub></i> may be split into <maths id="math0070"><math display="inline"><msub><mi>r</mi><mrow><mo>+</mo><mo>,</mo><mi>u</mi></mrow></msub><mo>,</mo><msub><mi>r</mi><mrow><mo>−</mo><mo>,</mo><mi>u</mi></mrow></msub><mo>∈</mo><mo>±</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0077.tif" /></maths> using the method described above for <i>t</i>. Next, <i>R'</i> may be constructed as the items <maths id="math0071"><math display="inline"><msubsup><mfenced><msub><mi>r</mi><mi>i</mi></msub></mfenced><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mrow><mi>u</mi><mo>−</mo><mn>1</mn></mrow></msubsup></math><img file="EP4040713A1_D0078.tif" /></maths>, <i>r</i><sub>+,<i>u</i></sub>, <i>r</i><sub>-,<i>u</i></sub>, <maths id="math0072"><math display="inline"><msubsup><mfenced><msub><mi>r</mi><mi>i</mi></msub></mfenced><mrow><mi>i</mi><mo>=</mo><mi>u</mi><mo>+</mo><mn>1</mn></mrow><mi>n</mi></msubsup></math><img file="EP4040713A1_D0079.tif" /></maths>. A reordering of these items may be used as well. A relation over <maths id="math0073"><math display="inline"><msubsup><mfenced><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mi>r</mi><mi>i</mi><mo>′</mo></msubsup></mfenced></mfenced><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mrow><mi>n</mi><mo>+</mo><mn>1</mn></mrow></msubsup></math><img file="EP4040713A1_D0080.tif" /></maths> in a zero-knowledge argument is obtained from one over <maths id="math0074"><math display="inline"><msubsup><mfenced><msub><mi>h</mi><mi>M</mi></msub><mfenced><msub><mi>r</mi><mi>i</mi></msub></mfenced></mfenced><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>n</mi></msubsup></math><img file="EP4040713A1_D0081.tif" /></maths> by replacing <i>h<sub>M</sub></i>(<i>r<sub>u</sub></i>) in the latter with <i>h<sub>M</sub></i>(<i>r</i><sub>+,<i>u</i></sub>) + <i>h<sub>M</sub></i>(<i>r</i><sub>-,<i>u</i></sub>) in the former, and by extending the domain of the carry to account for the split. For example, <i>h<sub>M</sub></i>(<i>t</i>) = <i>h<sub>M</sub></i>(<i>r</i><sub>1</sub>) + <i>h<sub>M</sub></i>(<i>r<sub>2</sub></i>) + <i>oy</i> mod <i>q</i> where <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>), <maths id="math0075"><math display="inline"><mi>c</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mn>2</mn><mi>m</mi></msubsup></math><img file="EP4040713A1_D0082.tif" /></maths> may be replaced with <maths id="math0076"><math display="inline"><msub><mi>h</mi><mi>M</mi></msub><mfenced><mi>t</mi></mfenced><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mi>r</mi><mn>1</mn><mo>′</mo></msubsup></mfenced><mo>+</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mi>r</mi><mn>2</mn><mo>′</mo></msubsup></mfenced><mo>+</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mi>r</mi><mn>3</mn><mo>′</mo></msubsup></mfenced><mo>+</mo><mi mathvariant="italic">oy</mi></math><img file="EP4040713A1_D0083.tif" /></maths><i>oy</i> mod <i>q</i> where <i>r</i><sub>2</sub> was split to <maths id="math0077"><math display="inline"><msubsup><mi>r</mi><mn>2</mn><mo>′</mo></msubsup><mo>+</mo><msubsup><mi>r</mi><mn>3</mn><mo>′</mo></msubsup></math><img file="EP4040713A1_D0084.tif" /></maths> and where <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>), <maths id="math0078"><math display="inline"><mi>c</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mn>3</mn><mi>m</mi></msubsup></math><img file="EP4040713A1_D0085.tif" /></maths>.
0129A third example zero-knowledge hashing argument for zero elements is described. Let <i>J</i> ⊆ [<i>m</i>] be a set of elements where <i>s<sub>j</sub></i> = 0 for <i>j</i> ∈ <i>J</i> that Peter wishes to argue for. To this end, Peter may make a zero-knowledge hashing argument for <i>o</i>-ary elements, as described herein, modified as follows: in all rounds, for each <i>j</i> ∈ <i>J</i> Peter sets <i>r</i><sub>+,<i>j</i></sub> = <i>r</i><sub>-,<i>j</i></sub> = 0. Victor verifies this argument for zero-elements by checking said arguments of knowledge and that in each round the revealed <i>r</i><sub>0</sub> or <i>r</i><sub>1</sub> (one of <i>r</i><sub>±</sub>) has <i>r.</i><sub>,<i>j</i></sub> = 0 for <i>j</i> ∈ <i>J</i>.
0130A fourth example zero-knowledge hashing argument for partial equality of elements is described. Peter makes a zero-knowledge hashing argument for partial equality of elements as follows. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> be secrets and <i>J</i> ⊆ [<i>m</i>] be a set of elements such that <maths id="math0079"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0086.tif" /></maths> for <i>j</i> ∈ <i>J</i>. First, Peter makes a zero-knowledge hashing argument for modular subtraction of elements, described herein, showing that <i>s</i><sup>[3]</sup> = <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup>. Then, Peter makes a partial zero-knowledge argument for zero elements, described herein, showing that <maths id="math0080"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0087.tif" /></maths> for <i>j</i> ∈ <i>J</i>.
0131A fifth example zero-knowledge hashing argument for permutation of elements is described. Peter makes a zero-knowledge hashing argument for permutation of elements as follows. Let <i>P</i> be the public <i>m</i> × <i>m</i> permutation matrix for the argument. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> ∈ <i>S<sup>m</sup></i> be secrets where <i>s</i><sup>[2]</sup> := <i>P<sub>S</sub></i><sup>[1]</sup><i>.</i> Peter argues knowledge of pre-images of <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>) using a method as described above modified as follows: sets <maths id="math0081"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0088.tif" /></maths> to <maths id="math0082"><math display="inline"><mfenced><mi>P</mi><mfenced><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⊙</mo><msup><mi>k</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msup></mfenced></mfenced><mo>⊙</mo><msup><mi>k</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msup></math><img file="EP4040713A1_D0089.tif" /></maths> and reveals either <maths id="math0083"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0090.tif" /></maths>, <maths id="math0084"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0091.tif" /></maths> or <maths id="math0085"><math display="inline"><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0092.tif" /></maths>, <maths id="math0086"><math display="inline"><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0093.tif" /></maths>, e.g. using a common challenge for both in the method. Herein, <maths id="math0087"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0094.tif" /></maths>, <maths id="math0088"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0095.tif" /></maths> and similar notations are understood to mean only either <maths id="math0089"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0096.tif" /></maths>, <maths id="math0090"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0097.tif" /></maths> or <maths id="math0091"><math display="inline"><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0098.tif" /></maths>, <maths id="math0092"><math display="inline"><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0099.tif" /></maths> are revealed, e.g. using a common challenge. Thus, Peter posts <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup><i>.</i> Victor verifies this argument for permutation of elements by checking the described arguments of knowledge and that each revealed pair <maths id="math0093"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0100.tif" /></maths>, <maths id="math0094"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0101.tif" /></maths> satisfies <maths id="math0095"><math display="inline"><mfenced open="|" close="|"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mo>=</mo><mfenced open="|" close="|"><msubsup><mi mathvariant="italic">Pr</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0102.tif" /></maths>.
0132The argument may be characterized as follows. For a rotation matrix <i>P</i>, the permutation of elements is equivalent to rotation of elements. Given an argument of knowledge for a pre-image of <i>h</i><sup>[1]</sup> (as input to this argument) has already been made, the computational resources demanded by this argument are dominated by 1 argument of knowledge of a pre-image. In case <i>k</i><sup>[2]</sup> is constrained to be chosen equal to <i>Pk</i><sup>[1]</sup>, the communication resources demanded by the argument can be reduced by having Victor recover <maths id="math0096"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0103.tif" /></maths> as <maths id="math0097"><math display="inline"><msubsup><mi mathvariant="italic">Pr</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0104.tif" /></maths> and Peter skip posting <maths id="math0098"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0105.tif" /></maths>. In this case, the argument of knowledge of a pre-image for <i>h</i><sup>[2]</sup> may be skipped, though hash values are still posted.
0133The argument may be enhanced as follows. For a set <i>J</i> ⊂ [<i>m</i>], let <i>I<sub>J</sub></i> be an <i>m</i> × <i>m</i> matrix where entries <i>I</i><sub><i>j</i>,<i>j</i></sub> for <i>j</i> ∈ <i>J</i> are set to 1 and all other entries are set to 0. Provided problems of finding a pre-image remain hard, the argument may be modified to a partial permutation argument by having Peter constrain only elements <i>j</i> ∈ <i>J</i> of <i>r</i><sup>[2]</sup>, so that <maths id="math0099"><math display="inline"><msub><mi>I</mi><mi>J</mi></msub><msup><mi>r</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msup><mo>=</mo></math><img file="EP4040713A1_D0106.tif" /></maths><maths id="math0100"><math display="inline"><msub><mi>I</mi><mi>J</mi></msub><mfenced><mi>P</mi><mfenced><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⊙</mo><msup><mi>k</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msup></mfenced></mfenced><mo>⊙</mo><msup><mi>k</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msup></math><img file="EP4040713A1_D0107.tif" /></maths>, and set remaining elements (in a described way for an argument of knowledge of a pre-image), and having Victor verify that <maths id="math0101"><math display="inline"><mfenced open="|" close="|"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mo>=</mo><mfenced open="|" close="|"><msubsup><mi mathvariant="italic">Pr</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0108.tif" /></maths> only for elements <i>j</i> ∈ <i>J</i>, i.e. that <maths id="math0102"><math display="inline"><msub><mi>I</mi><mi>J</mi></msub><mfenced open="|" close="|"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mo>=</mo><msub><mi>I</mi><mi>J</mi></msub><mfenced open="|" close="|"><msubsup><mi mathvariant="italic">Pr</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0109.tif" /></maths>. When the first (resp. last) element is free in a 1-right (resp. 1-left) rotation, the resulting argument is a 1-right-shift (resp. 1-left-shift) argument and the corresponding partial permutation matrix is a 1-right-shift (resp. 1-left-shift) matrix. When |<i>S</i>| = 2, the argument is a (possibly partial) bit permutation argument. Moreover, a varying base <maths id="math0103"><math display="inline"><msub><mi>S</mi><mi>j</mi></msub><mo>:</mo><mo>=</mo><msub><mi>ℤ</mi><msub><mi>o</mi><mi>j</mi></msub></msub></math><img file="EP4040713A1_D0110.tif" /></maths> for corresponding varying moduli <i>o<sub>j</sub></i> may replace <i>S</i>, <i>o</i> as well, by using a varying base in said arguments of knowledge of a pre-image. Provided problems of finding a pre-image remain hard, the argument may be made for a subset <i>J</i> ⊂ [<i>m</i>] of the elements by modifying the included arguments of knowledge of a pre-image to set <i>r<sub>j</sub></i> values in <maths id="math0104"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0111.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ <i>J</i>, while continuing to set <i>r<sub>j</sub></i> values in <maths id="math0105"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0112.tif" /></maths> for <i>j</i> ∈ <i>J</i>; the resulting argument is a partial argument for permutation of elements. If the verification relation is additive, this may be done e.g. by choosing <maths id="math0106"><math display="inline"><msub><mi>ν</mi><mi>j</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0113.tif" /></maths>, and setting element <i>j</i> of <i>r</i><sub>+</sub> (resp. <i>r</i><sub>-</sub>) to a modified (blinded) version that is incremented (resp. decremented) by <i>v<sub>j</sub></i>, for <i>j</i> ∈ <i>J</i>. Furthermore, an extended argument may be made for permutation of elements of <i>v</i> vectors, each of length <i>m</i>, using a matrix <i>P<sub>ξ</sub></i> of size <i>vm</i> × <i>vm</i> acting on a block-concatenation of <i>v</i> vectors of size <i>m</i>, and using an extended block-diagnoal hash matrix <i>M<sub>ξ</sub></i> of size <i>vn</i> × <i>vm</i>, with <i>v</i> copies of <i>M</i> along its diagonal and zeros elsewhere, in an extended hash function <i>h<sub>M<sub2>ξ</sub2></sub></i> for the arguments of knowledge of a pre-image. In this case, said variables <i>M</i>, <maths id="math0107"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0114.tif" /></maths>, <maths id="math0108"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0115.tif" /></maths>, <maths id="math0109"><math display="inline"><msubsup><mi>k</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0116.tif" /></maths>, <maths id="math0110"><math display="inline"><msubsup><mi>k</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0117.tif" /></maths> are replaced with <i>M<sub>ξ</sub></i> := diag(<i>M</i><sub>1</sub>,...,<i>M<sub>v</sub></i>), <maths id="math0111"><math display="inline"><msubsup><mi>r</mi><mrow><mi>ξ</mi><mo>,</mo><mo>±</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><mfenced><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1,1</mn></mfenced></msubsup><mo>,</mo><mo>…</mo><mo>,</mo><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn><mi>ν</mi></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0118.tif" /></maths>, <maths id="math0112"><math display="inline"><msubsup><mi>r</mi><mrow><mi>ξ</mi><mo>,</mo><mo>±</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><mfenced><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2,1</mn></mfenced></msubsup><mo>,</mo><mo>…</mo><mo>,</mo><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn><mi>ν</mi></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0119.tif" /></maths>, <maths id="math0113"><math display="inline"><msubsup><mi>k</mi><mrow><mi>ξ</mi><mo>,</mo><mo>±</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>:</mo><mo>=</mo></math><img file="EP4040713A1_D0120.tif" /></maths><maths id="math0114"><math display="inline"><mfenced><msubsup><mi>k</mi><mo>±</mo><mfenced open="[" close="]"><mn>1,1</mn></mfenced></msubsup><mo>,</mo><mo>…</mo><mo>,</mo><msubsup><mi>k</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn><mi>ν</mi></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0121.tif" /></maths>, <maths id="math0115"><math display="inline"><msubsup><mi>k</mi><mrow><mi>ξ</mi><mo>,</mo><mo>±</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><mfenced><msubsup><mi>k</mi><mo>±</mo><mfenced open="[" close="]"><mn>2,1</mn></mfenced></msubsup><mo>,</mo><mo>…</mo><mo>,</mo><msubsup><mi>k</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn><mi>ν</mi></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0122.tif" /></maths> where <i>M<sub>a</sub></i> = <i>M</i> for <i>a</i> ∈ [<i>v</i>]. Here, the second bracketed index ranges over [<i>v</i>] and corresponds to a block. Varying <i>M<sub>a</sub></i> for <i>a</i> ∈ [<i>v</i>] may also be used, provided pre-image problems remain hard. The length (resp. size) of each block in these defined vectors (resp. matrix) may be varied, provided pre-image problems remains hard, to obtain a varying-length extended argument.
0134As described herein for modular addition of elements, hash values of the form <i>h</i><sub><i>r</i>,<i>M</i></sub> and a varying base <maths id="math0116"><math display="inline"><msub><mi>S</mi><mi>j</mi></msub><mo>:</mo><mo>=</mo><msub><mi>ℤ</mi><msub><mi>o</mi><mi>j</mi></msub></msub></math><img file="EP4040713A1_D0123.tif" /></maths> for corresponding varying moduli <i>o<sub>j</sub></i>, so that <i>o<sup>k</sup></i> for <i>k</i> ∈ [<i>m</i>] is replaced with <maths id="math0117"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∏</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>k</mi></msubsup><msubsup><mi>o</mi><mi>j</mi><mi>k</mi></msubsup></mstyle></math><img file="EP4040713A1_D0124.tif" /></maths> (defined as 1 for <i>k</i> = 0), may be used in similar ways, and an extended argument may be made in similar ways as well. Provided problems of finding a pre-image remain hard, a set <i>J</i> ⊂ [<i>m</i>] of elements of <i>c'</i> and of corresponding elements of <i>r</i><sub>±</sub> may be chosen as 0. Arguments for zero elements are described herein. In this case, an argument for multiple numbers, each interpreted over a disjoint subset of elements, may be made by choosing as 0 the most significant element of each number and by setting (and verifying) <i>r</i><sub>±</sub> = 0 for these elements in all rounds. For example, for the choices <i>m</i> := 4096 and <i>J</i> := {<i>j</i>|<i>j</i> ∈ [<i>m</i>], <i>j</i> = 0 mod 64}, an argument may be made for 64 numbers, where the <i>i</i>th number for <i>i</i> ∈ [64] is interpreted over 64 elements with indexes 64<i>i</i> - 63,...,64<i>i</i> (listed from least significant to most significant). Thus, in this example, the argument may be viewed as one of single-instruction multiple-data (SIMD), as may be other arguments herein such as for permutation and addition of elements, for an ADD instruction and 64 numbers as data. When <i>o</i> = 2, this example may be characterized as one for 64 numbers of 64 bits each. Moreover, said permutation argument for <i>c</i>, <i>c'</i> may be modified to become a partial permutation argument. A partial set <i>J</i> may be defined to include only some of the numbers, e.g. the 64-element numbers in said example, resulting in a partial argument for modular addition of numbers, provided pre-image problems remain hard.
0135An argument for subtraction of numbers may be made using an argument for addition of numbers with repositioned operands. For example, to argue that <i>s</i><sup>[3]</sup> = <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup> mod <i>o<sup>m</sup></i>, an argument that <i>s</i><sup>[1]</sup> = <i>s</i><sup>[2]</sup> + <i>s</i><sup>[3]</sup> mod <i>o<sup>m</sup></i> may be made.
0136An example with 3 pieces is described. Here, free indexes <i>i</i>,<i>a</i>,<i>b</i> are ranging over [2], [3], [3] respectively. Require <i>k</i><sup>[<i>i</i>]</sup> be all equal, and for simplicity assume all are equal to 1. Let <i>a'</i> := <i>a</i> + 1 mod 3. Peter sets <maths id="math0118"><math display="inline"><msup><mi>w</mi><mfenced open="[" close="]"><mi>a</mi></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0125.tif" /></maths> mod <i>o</i>, so that each is a sum of two corresponding pieces. Therefore, <i>w</i><sup>[<i>a</i>]</sup> are random in <maths id="math0119"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mi>m</mi></msubsup></math><img file="EP4040713A1_D0126.tif" /></maths> subject to <maths id="math0120"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><msup><mi>w</mi><mfenced open="[" close="]"><mi>a</mi></mfenced></msup><mo>=</mo></mrow></mstyle></math><img file="EP4040713A1_D0127.tif" /></maths><maths id="math0121"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mrow></mstyle></math><img file="EP4040713A1_D0128.tif" /></maths> (mod <i>o</i>). Peter sets <maths id="math0122"><math display="inline"><msup><mi>r</mi><mfenced open="[" close="]"><mi>a</mi><mi>b</mi></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0129.tif" /></maths>, r<i>'</i><sup>[<i>a</i>,<i>b</i>]</sup> := <i>r</i><sup>[<i>a</i>,<i>b</i>]</sup> mod <i>o</i>, and computes a carry vector (or vectors) <i>c</i> for <maths id="math0123"><math display="inline"><mi>ƒ</mi><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><mi>r</mi><msup><mo>′</mo><mfenced open="[" close="]"><mi>a</mi><mi>b</mi></mfenced></msup></mrow></mstyle></math><img file="EP4040713A1_D0130.tif" /></maths>, i.e. such that <i>oc</i>+<i>f</i> = (<i>f</i> mod <i>o</i>). Peter computes <i>h</i><sup>[<i>a</i>,<i>b</i>]</sup> := <i>h<sub>M</sub></i>(<i>r'</i><sup>[<i>a</i>,<i>b</i>]</sup>), <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>). Peter posts <i>h</i><sup>[<i>a</i>,<i>b</i>]</sup>,<i>y</i> as commitments. Victor verifies that <maths id="math0124"><math display="inline"><msup><mi>h</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>:</mo><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msup><mi>t</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup></mfenced><mo>=</mo><mi mathvariant="italic">oy</mi><mo>+</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><msup><mi>h</mi><mfenced open="[" close="]"><mi>a</mi><mi>b</mi></mfenced></msup></mstyle></math><img file="EP4040713A1_D0131.tif" /></maths> mod <i>q</i>. Victor chooses a challenge <i>u</i> ∈ [3]. Let <i>u'</i> := <i>u</i> + 1 mod 3. Peter reveals the carry and secret pieces corresponding to 2 indices determined by Victor for <i>u</i>, namely <i>c</i>, <maths id="math0125"><math display="inline"><msubsup><mi>r</mi><mi>u</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0132.tif" /></maths>, <maths id="math0126"><math display="inline"><msubsup><mi>r</mi><mrow><mi>u</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0133.tif" /></maths>, <maths id="math0127"><math display="inline"><msubsup><mi>r</mi><mi>u</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0134.tif" /></maths>, <maths id="math0128"><math display="inline"><msubsup><mi>r</mi><mrow><mi>u</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0135.tif" /></maths>, thus allowing Victor to learn <i>w</i><sup>[<i>u</i>]</sup>, <i>w</i><sup>[<i>u'</i>]</sup> but not about any <i>t</i><sup>[<i>i</i>]</sup>. Victor verifies the argument by reconstructing <i>r'</i><sup>[<i>u</i>,<i>u</i>]</sup>, <i>r'</i><sup>[<i>u'</i>,u]</sup>, <i>r'</i><sup>[u,u<i>'</i>]</sup> and checking that they respectively hash to <i>h</i><sup>[<i>u</i>,<i>u</i>]</sup>, <i>h</i><sup>[<i>u'</i>,<i>u</i>]</sup>, <i>h</i><sup>[<i>u</i>,<i>u'</i>]</sup>, and by checking that <i>h<sub>M</sub></i>(<i>c</i>) = <i>y.</i>
0137A sixth example zero-knowledge hashing argument for modular addition or subtraction of elements is described. Peter makes a zero-knowledge hashing argument for modular addition of elements as follows. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> ∈ <i>S<sup>m</sup></i>, <maths id="math0129"><math display="inline"><msup><mi>s</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mfenced><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0136.tif" /></maths> be secrets. Peter argues knowledge of pre-images of <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>), with <i>k</i><sup>[1]</sup> = <i>k</i><sup>[2]</sup>, using a method as described above, thus posting <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup>. Next, Peter sets <maths id="math0130"><math display="inline"><msup><mi>t</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mfenced><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>smod</mi><mspace width="1ex" /><mi>o</mi></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0137.tif" /></maths>, <i>h</i><sup>[3]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>) and <maths id="math0131"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><msubsup><mfenced><mi>sgn</mi><mfenced><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0138.tif" /></maths> so that the relation <maths id="math0132"><math display="inline"><msub><mi mathvariant="italic">oc</mi><mi>j</mi></msub><mo>=</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0139.tif" /></maths> holds, and posts <i>h</i><sup>[3]</sup>. Now, <i>s</i><sup>[3]</sup> is determined by <i>t</i><sup>[3]</sup>, where <maths id="math0133"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mfenced open="|" close="|"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0140.tif" /></maths> and <maths id="math0134"><math display="inline"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0141.tif" /></maths>, with <i>k</i><sup>[3]</sup> = <i>k</i><sup>[1]</sup>. Hence, <i>h</i><sup>[3]</sup> is a hash value for <i>s</i><sup>[3]</sup>. Here <i>c</i> has the role of a signed carry vector for the modular addition. Finally, Peter argues knowledge of a pre-image in {-1, 0, 1}<i><sup>m</sup></i> of <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>), thus posting <i>y</i>, using an available argument making method for secrets in <maths id="math0135"><math display="inline"><msubsup><mi>ℤ</mi><mn>2</mn><mi>m</mi></msubsup></math><img file="EP4040713A1_D0142.tif" /></maths>. Victor verifies this argument for modular addition of elements by checking said arguments of knowledge of a pre-image and that <maths id="math0136"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msub><mi mathvariant="italic">oy</mi><mi>i</mi></msub><mo>=</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0143.tif" /></maths> mod <i>q</i>.
0138This argument may be characterized as follows. For <i>o</i> = 2, modular addition of elements is equivalent to a bitwise XOR operation on bit elements. Given arguments of knowledge of pre-images for <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup> (as inputs to this argument) have already been made, the computational resources demanded by this argument for modular addition of elements are dominated by 2 arguments of knowledge of a pre-image.
0139This argument may be enhanced as follows. Hashes of the form <i>h</i><sub><i>r</i>,<i>M</i></sub> may be used, where herein <i>r</i> in <i>h</i><sub><i>r</i>,<i>M</i></sub> forms is unrelated to <i>r</i>± values, in place of <i>h<sub>M</sub></i> by accounting for linearity for <i>r</i>, so that e.g. a linear relation with a sum of hash values of the form ∑<i><sub>k</sub> h<sub>r<sub2>k</sub2>,M</sub></i> on one hand results in a hash value of the form <i>h</i><sub>(∑<i>k<sup>r</sup>k</i>),<i>M</i></sub> on the other hand. This applies to similar linear relations described herein. Moreover, as described herein, hash values of the form <i>h</i><sub><i>r</i>,<i>M</i></sub> and a varying base <maths id="math0137"><math display="inline"><msub><mi>S</mi><mi>j</mi></msub><mo>:</mo><mo>=</mo><msub><mi>ℤ</mi><msub><mi>o</mi><mi>j</mi></msub></msub></math><img file="EP4040713A1_D0144.tif" /></maths> for corresponding varying moduli <i>o<sub>j</sub></i> may be used with a separate carry vector <i>c</i><sup>[<i>a</i>]</sup> for each distinct modulo <i>o</i><sup>[<i>a</i>]</sup> and a corresponding hash <i>y</i><sup>[<i>a</i>]</sup>, resulting in a relation of the form <i>h</i><sup>[1]</sup> + <i>h</i><sup>[2]</sup> + ∑<sub>a</sub><i>o</i><sup>[<i>a</i>]</sup><i>y</i><sup>[<i>a</i>]</sup> = <i>h</i><sup>[3]</sup> mod <i>q</i> where <i>a</i> enumerates distinct modulo, and with an argument as described herein that each carry vector <i>c</i><sup>[<i>a</i>]</sup> has zero elements for all <i>j</i> except where <i>S<sub>j</sub></i> = <i>o</i><sup>[<i>a</i>]</sup>. Finally, an extended argument may be made in similar ways as described for permutation of elements.
0140An argument for subtraction of elements may be made using an argument for addition of elements with repositioned operands. For example, to argue that <maths id="math0138"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0145.tif" /></maths> mod <i>o</i> for <i>j</i> ∈ [<i>m</i>], an argument that <maths id="math0139"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0146.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] may be made.
0141A similar argument for modular addition or subtraction of numbers is described. Peter makes a zero-knowledge hashing argument for modular addition of numbers as follows. Here secrets are interpreted as radix-o numbers. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> ∈ <i>S<sup>m</sup></i>, <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup> + <i>s</i><sup>[2]</sup> mod <maths id="math0140"><math display="inline"><mi>mod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mrow><msup><mi>o</mi><mrow><mi>j</mi><mo>−</mo><mn>1</mn></mrow></msup><mfenced><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup></mrow></mstyle></math><img file="EP4040713A1_D0147.tif" /></maths> be secrets. Let <i>P</i> be an <i>m</i> × <i>m</i> 1-right-shift matrix, for which <i>P</i>(<i>x</i><sub>1</sub>,<i>...</i>,<i>x<sub>m</sub></i>) = (<i>x<sub>m</sub></i>,<i>x</i><sub>1</sub>,...,<i>x</i><sub><i>m</i>-1</sub>). Peter argues knowledge of pre-images of <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>),<i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>), with <i>k</i><sup>[1]</sup> = <i>k</i><sup>[2]</sup>, using a method as described above, thus posting <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup><i>.</i> Peter sets <maths id="math0141"><math display="inline"><msup><mi>t</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>:</mo><mo>=</mo><msup><mi>t</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msup><mo>+</mo><msup><mi>t</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msup><mspace width="1ex" /><mi>smod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mrow><msup><mi>o</mi><mrow><mi>j</mi><mo>−</mo><mn>1</mn></mrow></msup><mfenced><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mi>smod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup></mrow></mstyle></math><img file="EP4040713A1_D0148.tif" /></maths>, <i>h</i><sup>[<i>3</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>), <maths id="math0142"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><msubsup><mfenced><mi>sgn</mi><mfenced><mfenced><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mi>smod</mi><mspace width="1ex" /><mi>o</mi></mfenced><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0149.tif" /></maths>, <i>c'</i> := <i>k</i><sup>[1]</sup>(<i>P</i>(<i>k</i><sup>[1]</sup> ⊙ <i>c</i>)) so that the relation <maths id="math0143"><math display="inline"><msub><mi mathvariant="italic">oc</mi><mi>j</mi></msub><mo>+</mo><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup><mo>=</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0150.tif" /></maths> holds, and posts <i>h</i><sup>[3]</sup>. Now, <i>s</i><sup>[3]</sup> is determined by <i>t</i><sup>[3]</sup>, where <maths id="math0144"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mfenced open="|" close="|"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0151.tif" /></maths> and <maths id="math0145"><math display="inline"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0152.tif" /></maths>, with <i>k</i><sup>[3]</sup> = <i>k</i><sup>[1]</sup>. Hence, <i>h</i><sup>[3]</sup> is a hash value for <i>s</i><sup>[3]</sup>. Here c and c' have the role of a signed carry vector for modular addition of numbers, and the above relation between them is argued using a permutation argument. Finally, Peter argues knowledge of pre-images in {-1, 0, 1}<i><sup>m</sup></i> of <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>), <i>y'</i> := <i>h<sub>M</sub></i>(<i>c'</i>) using a method as described above for secrets in <maths id="math0146"><math display="inline"><msubsup><mi>ℤ</mi><mn>2</mn><mi>m</mi></msubsup></math><img file="EP4040713A1_D0153.tif" /></maths>, thus posting <i>y</i>, <i>y'</i>. Victor verifies this argument for modular addition of numbers by checking said arguments of knowledge and that <maths id="math0147"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msub><mi mathvariant="italic">oy</mi><mi>i</mi></msub><mo>+</mo><msubsup><mi>y</mi><mi>i</mi><mo>′</mo></msubsup><mo>=</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0154.tif" /></maths> mod <i>q.</i>
0142A seventh example zero-knowledge hashing argument for modular multiplication of elements or numbers is described. Peter makes a zero-knowledge hashing argument for modular multiplication of elements as follows. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> ∈ <i>S<sup>m</sup></i>, <maths id="math0148"><math display="inline"><msup><mi>s</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>:</mo><mo>=</mo><mrow><mo>(</mo><mrow><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mrow></mrow></math><img file="EP4040713A1_D0155.tif" /></maths><maths id="math0149"><math display="inline"><msubsup><mrow><mrow><mi>mod</mi><mspace width="1ex" /><mi>o</mi></mrow><mo>)</mo></mrow><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0156.tif" /></maths> be secrets. In the case of multiplication, <maths id="math0150"><math display="inline"><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>≠</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0157.tif" /></maths> may be used. Peter argues knowledge of pre-images in <maths id="math0151"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0158.tif" /></maths> of <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>), using a method as described above, thus posting <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup><i>.</i> Next, Peter sets <maths id="math0152"><math display="inline"><msup><mi>t</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mfenced><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mi>smod</mi><mspace width="1ex" /><mi>o</mi></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0159.tif" /></maths>, <i>h</i><sup>[<i>3</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>) and posts <i>h</i><sup>[3]</sup>. Now, <i>s</i><sup>[3]</sup> is determined by <i>t</i><sup>[3]</sup>, where <maths id="math0153"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mfenced open="|" close="|"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0160.tif" /></maths> and <maths id="math0154"><math display="inline"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0161.tif" /></maths>, with <maths id="math0155"><math display="inline"><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0162.tif" /></maths>. Hence, <i>h</i><sup>[3]</sup> is a hash value for <i>s</i><sup>[3]</sup> Finally, Peter sets <maths id="math0156"><math display="inline"><msubsup><mi>h</mi><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⊙</mo><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0163.tif" /></maths> and posts <maths id="math0157"><math display="inline"><msubsup><mi>h</mi><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0164.tif" /></maths> for <i>a, b</i> ∈ <i>v</i> where <i>v</i> := {+, -}. The relation <maths id="math0158"><math display="inline"><mfenced><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></mfenced><mo>⊙</mo><mfenced><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mo>=</mo><msup><mi>t</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mfenced><mi>smod</mi><mspace width="1ex" /><mi>o</mi></mfenced></math><img file="EP4040713A1_D0165.tif" /></maths> holds and using hashing <maths id="math0159"><math display="inline"><mstyle displaystyle="true"><msub><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>∈</mo><mi>ν</mi></mrow></msub><msubsup><mi>h</mi><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></mstyle><mo>=</mo><msup><mi>h</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup></math><img file="EP4040713A1_D0166.tif" /></maths> holds. Let <i>a', b'</i> ∈ <i>v</i> be those for which <maths id="math0160"><math display="inline"><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0167.tif" /></maths>, <maths id="math0161"><math display="inline"><msubsup><mi>r</mi><mrow><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0168.tif" /></maths> are revealed in said arguments for <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup><i>.</i> Victor verifies this argument for modular multiplication of elements by checking said arguments of knowledge of a pre-image and that <maths id="math0162"><math display="inline"><mi>h</mi><mfenced><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⊙</mo><msubsup><mi>r</mi><mrow><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mo>=</mo><msubsup><mi>h</mi><mrow><mi>a</mi><mo>′</mo><mo>,</mo><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0169.tif" /></maths>.
0143A setup where <maths id="math0163"><math display="inline"><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>smod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0170.tif" /></maths> provides no information about neither <maths id="math0164"><math display="inline"><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0171.tif" /></maths> nor <maths id="math0165"><math display="inline"><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0172.tif" /></maths> for <i>a, b</i> ∈ <i>v</i> may be used. For example, a setup with <maths id="math0166"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0173.tif" /></maths>, <maths id="math0167"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>∈</mo><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0174.tif" /></maths> with <i>o</i> prime may be used, e.g. by modifying the definition of <i>α<sub>i</sub></i> to {<i>ix</i>|<i>x</i> ∈ <i>S</i> \ {0}}. A prime <i>o</i> close yet less than 2<i><sup>w</sup></i> << <i>q</i> for <i>w</i> ∈ <img file="EP4040713A1_D0175.tif" /> may be used to maximize the use of a w-bit representation of values in <maths id="math0168"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0176.tif" /></maths><i>.</i> A Mersenne prime <i>o</i> = 2<i><sup>w</sup></i> - 1 may be used with values of <i>w</i> it exists for. Fast modular arithmetic methods for such primes may be used as well. In this example setup, the argument for modular multiplication of elements may be modified as follows. Let <i>a"</i>, <i>b"</i> negate <i>a', b'</i> so that <i>v</i> = {<i>a'</i>, <i>a"</i>} = {<i>b'</i>, <i>b"</i>}<i>.</i> Peter sets <maths id="math0169"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><msubsup><mi>r</mi><mrow><mi>a</mi><mo>"</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⊙</mo><msubsup><mi>r</mi><mrow><mi>b</mi><mo>"</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>smod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0177.tif" /></maths> and posts c in addition to his posts for <maths id="math0170"><math display="inline"><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0178.tif" /></maths>, <maths id="math0171"><math display="inline"><msubsup><mi>r</mi><mrow><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0179.tif" /></maths> in the argument for modular multiplication of elements. Victor verifies this modified argument for modular multiplication of elements by checking in addition that <maths id="math0172"><math display="inline"><msub><mi>h</mi><mi>M</mi></msub><mfenced><mi>c</mi></mfenced><mo>=</mo><msubsup><mi>h</mi><mrow><mi>a</mi><mo>"</mo><mo>,</mo><mi>b</mi><mo>"</mo></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0180.tif" /></maths>. This added check provides a higher level of security to the modified argument compared to that of the unmodified argument.
0144An argument for modular division-without-remainder of elements may be made using an argument for modular multiplication of elements with repositioned operands. For example, to argue that. <maths id="math0173"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>÷</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0181.tif" /></maths> for <i>j</i> ∈ [<i>m</i>]<i>,</i> an argument that <maths id="math0174"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0182.tif" /></maths> mod <i>o</i> for <i>j</i> ∈ [<i>m</i>] may be made. Herein, ÷ denotes division without remainder.
0145An argument for modular division-with-remainder of elements may be made by using an argument for modular multiplication of elements, an argument for quotient of elements, and an argument for remainder of elements. Let <i>u</i> := (<i>u</i><sub>1</sub>,...,<i>u<sub>m</sub></i>) ∈ <i>S<sup>m</sup></i> be the quotient vector and let <i>d</i> := (<i>d</i><sub>1</sub><i>,...,d<sub>m</sub></i>) ∈ <i>S<sup>m</sup></i> be the remainder vector. For example, to argue that <maths id="math0175"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mrow><mo>⌊</mo><mrow><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>/</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mrow><mo>⌋</mo></mrow><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0183.tif" /></maths> for <i>j</i> ∈ [<i>m</i>], arguments that <maths id="math0176"><math display="inline"><msub><mi>u</mi><mi>j</mi></msub><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0184.tif" /></maths> mod <maths id="math0177"><math display="inline"><mi>o</mi><mo>,</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msub><mi>u</mi><mi>j</mi></msub><mo>+</mo><msub><mi>d</mi><mi>j</mi></msub><mo>,</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>></mo><msub><mi>d</mi><mi>j</mi></msub><mo>∈</mo><mi>S</mi></math><img file="EP4040713A1_D0185.tif" /></maths> may be made, as described herein for comparison of elements.
0146An argument for modulus (resp. integer-division) of elements may be made using an argument for division-with-remainder and taking the remainder <i>d</i> (resp. quotient <i>q</i>) as the output of the argument.
0147Peter makes a zero-knowledge hashing argument for modular multiplication of numbers as follows. Here vectors are interpreted with elements in <maths id="math0178"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0186.tif" /></maths> as radix-<i>o</i> numbers and use the operation · to denote their multiplication. Similarly, radix-<i>o</i> numbers are interpreted as vectors with elements in <maths id="math0179"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0187.tif" /></maths> where appropriate, e.g. as arguments to hash functions. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> ∈ <i>S<sup>m</sup></i>, <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup> · <i>s</i><sup>[2]</sup> mod <i>o<sup>m</sup></i> be secrets, so that <maths id="math0180"><math display="inline"><msup><mi>s</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∏</mo><mrow><mi>k</mi><mo>=</mo><mn>1</mn></mrow><mn>2</mn></msubsup><mfenced><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><msup><mi>o</mi><mrow><mi>j</mi><mo>−</mo><mn>1</mn></mrow></msup></mstyle><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mi>k</mi></mfenced></msubsup></mfenced></mstyle></math><img file="EP4040713A1_D0188.tif" /></maths> mod <i>o<sup>m</sup></i> holds. Peter argues knowledge of pre-images of <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>), with <maths id="math0181"><math display="inline"><msubsup><mi>k</mi><mn>1</mn><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0189.tif" /></maths> and <maths id="math0182"><math display="inline"><msubsup><mi>k</mi><mn>1</mn><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0190.tif" /></maths> for <i>j</i> ∈ [<i>m</i>], using a method as described above, thus posting <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup><i>.</i> Next, Peter sets <i>t</i><sup>[3]</sup> := t<sup>[1]</sup> · <i>t</i><sup>[2]</sup> smod <i>o<sup>m</sup></i>, <i>h</i><sup>[<i>3</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>) and posts <i>h</i><sup>[3]</sup>. Now, <i>s</i><sup>[3]</sup> is determined by <i>t</i><sup>[3]</sup>, where <maths id="math0183"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mfenced open="|" close="|"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0191.tif" /></maths> and <maths id="math0184"><math display="inline"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0192.tif" /></maths>, with <maths id="math0185"><math display="inline"><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0193.tif" /></maths>. Hence, <i>h</i><sup>[<i>3</i>]</sup> is a hash value for <i>s</i><sup>[3]</sup>. Finally, Peter sets <maths id="math0186"><math display="inline"><msubsup><mi>h</mi><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⋅</mo><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup></mfenced></math><img file="EP4040713A1_D0194.tif" /></maths> and posts <maths id="math0187"><math display="inline"><msubsup><mi>h</mi><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0195.tif" /></maths> for <i>a, b</i> ∈ <i>v</i> where <i>v</i> := {+, -}. The relation <maths id="math0188"><math display="inline"><mfenced><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></mfenced><mo>⋅</mo><mfenced><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mfenced><mo>=</mo></math><img file="EP4040713A1_D0196.tif" /></maths><i>t</i><sup>[3]</sup>(smod <i>o<sup>m</sup></i>) holds and using hashing <maths id="math0189"><math display="inline"><mstyle displaystyle="true"><msub><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>∈</mo><mi>ν</mi></mrow></msub><msubsup><mi>h</mi><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></mstyle><mo>=</mo><msup><mi>h</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup></math><img file="EP4040713A1_D0197.tif" /></maths><i>h</i><sup>[3]</sup> holds. Let <i>a', b'</i> ∈ <i>v</i> be those for which <maths id="math0190"><math display="inline"><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0198.tif" /></maths>, <maths id="math0191"><math display="inline"><msubsup><mi>r</mi><mrow><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0199.tif" /></maths> are revealed in said arguments for <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup><i>.</i> Victor verifies this argument for modular multiplication of numbers by checking said arguments of knowledge of a pre-image and that <maths id="math0192"><math display="inline"><mi>h</mi><mfenced><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⋅</mo><msubsup><mi>r</mi><mrow><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mi>smod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup></mfenced><mo>=</mo><msubsup><mi>h</mi><mrow><mi>a</mi><mo>′</mo><mo>,</mo><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0200.tif" /></maths>.
0148A setup where <maths id="math0193"><math display="inline"><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>smod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0201.tif" /></maths> provides no information about neither <maths id="math0194"><math display="inline"><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0202.tif" /></maths> nor <maths id="math0195"><math display="inline"><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0203.tif" /></maths> for <i>a, b</i> ∈ <i>v</i> may be used. For example, a setup with <maths id="math0196"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0204.tif" /></maths>, <maths id="math0197"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>∈</mo><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0205.tif" /></maths> and <i>o</i> prime may be used, e.g. by modifying the definition of <i>α</i><sub>0</sub> to {<i>ix</i>|<i>x</i> ∈ <i>S</i> \ {0}} (here index 0 corresponds to the least significant <i>o</i>-radix digit of the numbers), so that <maths id="math0198"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0206.tif" /></maths>, <maths id="math0199"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0207.tif" /></maths> are taken from the subgroup in <maths id="math0200"><math display="inline"><msubsup><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup><mo>*</mo></msubsup></math><img file="EP4040713A1_D0208.tif" /></maths> of numbers that are co-primes to <i>o</i>, having a single multiplicative inverse in that group. A prime <i>o</i> close yet less than 2<i><sup>w</sup></i> << <i>q</i> for <i>w</i> ∈ <img file="EP4040713A1_D0209.tif" /> may be used to maximize the use of a w-bit representation of values in <maths id="math0201"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0210.tif" /></maths><i>.</i> A Mersenne prime <i>o</i> = 2<i><sup>w</sup></i> - 1 may be used with values of <i>w</i> it exists for. Fast modular arithmetic methods for such primes may be used as well. Then, in this example setup, the argument for modular multiplication of elements may be modified as follows. Let <i>a"</i>, <i>b"</i> negate <i>a', b'</i> so that <i>v</i> = {<i>a</i>', <i>a"</i>} = {<i>b'</i>, <i>b"</i>}<i>.</i> Peter sets <maths id="math0202"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><msubsup><mi>r</mi><mrow><mi>a</mi><mo>"</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⋅</mo><msubsup><mi>r</mi><mrow><mi>b</mi><mo>"</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mi>smod</mi><mspace width="1ex" /><msup><mi>o</mi><mi>m</mi></msup></math><img file="EP4040713A1_D0211.tif" /></maths> and posts c in addition to posting <maths id="math0203"><math display="inline"><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0212.tif" /></maths>, <maths id="math0204"><math display="inline"><msubsup><mi>r</mi><mrow><mi>b</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0213.tif" /></maths> in the argument for modular multiplication of numbers. Victor verifies this modified argument for modular multiplication of numbers by checking in addition that <maths id="math0205"><math display="inline"><msub><mi>h</mi><mi>M</mi></msub><mfenced><mi>c</mi></mfenced><mo>=</mo><msubsup><mi>h</mi><mrow><mi>a</mi><mo>"</mo><mo>,</mo><mi>b</mi><mo>"</mo></mrow><mfenced open="[" close="]"><mn>1,2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0214.tif" /></maths>. This added check provides a higher level of security to the modified argument compared to that of the unmodified argument.
0149An argument for modular division-without-remainder of numbers may be made using an argument for modular multiplication of numbers with repositioned operands. For example, to argue that <i>s</i><sup>[3]</sup> = <i>s</i><sup>[1]</sup> ÷ <i>s</i><sup>[2]</sup> mod <i>o<sup>m</sup></i>, where here ÷ applies to numbers, an argument that <i>s</i><sup>[1]</sup> = <i>s</i><sup>[2]</sup> · <i>s</i><sup>[3]</sup> mod <i>o<sup>m</sup></i> may be made.
0150An argument for modular division-with-remainder of numbers may be made by using an argument for modular multiplication of numbers, an argument for quotient of numbers, and an argument for remainder of numbers. Let <i>u</i> := (<i>u</i><sub>1</sub>,...,<i>u<sub>m</sub></i>) ∈ <i>S<sup>m</sup></i> be the quotient vector and let <i>d</i> := (<i>d</i><sub>1</sub>,...,<i>d<sub>m</sub></i>) ∈ <i>S<sup>m</sup></i> be the remainder vector. For example, to argue that <i>s</i><sup>[3]</sup> = <sub>└</sub><i>s</i><sup>[1]</sup> / <i>s</i><sup>[2]</sup><sub>┘</sub> mod <i>o<sup>m</sup></i>, arguments (for numbers) that <i>u</i> = <i>s</i><sup>[2]</sup> · <i>s</i><sup>[3]</sup> mod <i>o<sup>m</sup></i>, <i>s</i><sup>[1]</sup> = <i>u</i> + <i>d</i> mod <i>o<sup>m</sup></i>, <i>s</i><sup>[2]</sup> > <i>d</i> ∈ <i>S</i> may be made using arguments for comparison of numbers, as described herein.
0151An argument for modulus (resp. integer-division) of numbers may be made using an argument for division-with-remainder of numbers and taking the remainder <i>d</i> (resp. quotient <i>q</i>) as the output of the argument.
0152These arguments may be modified to partial ones as follows. For a given argument and <i>J</i> ⊆ <i>[m</i>], <i>w</i> := |<i>J</i>|, Peter makes a modified argument that constrains only elements <i>j</i> ∈ <i>J</i> using techniques described herein for arguments for permutation of elements. For convenience of notation, element indexes may be permuted such that they are mapped to [<i>w</i>] and the given argument is made with <i>m</i> replaced by <i>w,</i> so that index 0 corresponds to the least significant o-radix digit. Thus, vectors of <i>w</i> elements are interpreted as numbers in <maths id="math0206"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>w</mi></msup></msub></math><img file="EP4040713A1_D0215.tif" /></maths> and arithmetics is done modulo <i>o<sup>w</sup></i> in the relations described for the argument. The remaining elements <i>j</i> ∈ [<i>m</i>] \ <i>J</i> are not similarly constrained by the modified argument.
0153An example with 3 pieces is described. Here, free indexes <i>i</i>, <i>a, b</i> are ranging over [2], [3], [3] respectively. Require <i>k</i><sup>[<i>i</i>]</sup> be all equal, and for simplicity assume all are equal to 1. Peter chooses <maths id="math0207"><math display="inline"><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mi>i</mi></mfenced></msubsup><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mi>m</mi></msubsup></math><img file="EP4040713A1_D0216.tif" /></maths> subject to <maths id="math0208"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mi>i</mi></mfenced></msubsup><mo>=</mo><msup><mi>t</mi><mfenced open="[" close="]"><mi>i</mi></mfenced></msup></mrow></mstyle><mfenced><mi>mod</mi><mspace width="1ex" /><mi>o</mi></mfenced></math><img file="EP4040713A1_D0217.tif" /></maths> and chooses <maths id="math0209"><math display="inline"><msub><mi>ν</mi><mi>a</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mi>m</mi></msubsup></math><img file="EP4040713A1_D0218.tif" /></maths> subject to <maths id="math0210"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><msub><mi>ν</mi><mi>a</mi></msub><mo>=</mo><mn>0</mn></mrow></mstyle></math><img file="EP4040713A1_D0219.tif" /></maths> (mod o). Let <i>a'</i> := <i>a</i> + 1 mod 3. Peter sets <i>w</i><sup>[<i>a</i>]</sup> := <i>υ<sub>a</sub></i> - <i>υ<sub>a'</sub></i> + <maths id="math0211"><math display="inline"><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>r</mi><mrow><mi>a</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0220.tif" /></maths>. Therefore, <i>w</i><sup>[<i>a</i>]</sup> are random in <maths id="math0212"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mi>m</mi></msubsup></math><img file="EP4040713A1_D0221.tif" /></maths> subject to <maths id="math0213"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><msup><mi>w</mi><mfenced open="[" close="]"><mi>a</mi></mfenced></msup></mstyle><mo>=</mo></math><img file="EP4040713A1_D0222.tif" /></maths><maths id="math0214"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></mrow></mstyle></math><img file="EP4040713A1_D0223.tif" /></maths> (mod o). Peter sets <maths id="math0215"><math display="inline"><msup><mi>r</mi><mfenced open="[" close="]"><mi>a</mi><mi>b</mi></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mi>r</mi><mi>a</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>r</mi><mi>b</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0224.tif" /></maths>, <i>r'</i><sup>[a,b]</sup> := <i>r</i><sup>[<i>a</i>,<i>b</i>]</sup> mod <i>o,</i><maths id="math0216"><math display="inline"><msubsup><mi>ν</mi><mi>a</mi><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><msub><mi>ν</mi><mi>a</mi></msub><mo>−</mo><msub><mi>ν</mi><mrow><mi>a</mi><mo>′</mo></mrow></msub></math><img file="EP4040713A1_D0225.tif" /></maths> mod <i>o</i> and computes a carry vector (or vectors) c for <maths id="math0217"><math display="inline"><mi>ƒ</mi><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><msup><mi>r</mi><mrow><mo>′</mo><mfenced open="[" close="]"><mi>a</mi><mi>b</mi></mfenced></mrow></msup></mstyle><mo>+</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><msubsup><mi>ν</mi><mi>a</mi><mo>′</mo></msubsup></mstyle></math><img file="EP4040713A1_D0226.tif" /></maths>, i.e. such that <i>oc</i> + <i>f</i> = (<i>f</i> mod <i>o</i>). Peter computes <i>h</i><sup>[a,b]</sup> := <i>h<sub>M</sub></i>(<i>r'</i><sup>[<i>a</i>,<i>b</i>]</sup>),<i>h'</i><sup>[a]</sup> := <i>h<sub>M</sub></i>(<i>υ'<sub>a</sub></i>), <i>y</i> := <i>h<sub>M</sub></i>(<i>c</i>)<i>.</i> Peter posts <i>h</i><sup>[<i>a</i>,<i>b</i>]</sup>, <i>h'</i><sup>[<i>a</i>]</sup>, <i>y</i> as commitments. Victor verifies that <i>h</i><sup>[<i>3</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup> = <maths id="math0218"><math display="inline"><mi mathvariant="italic">oy</mi><mo>+</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><msup><mi>h</mi><mfenced open="[" close="]"><mi>a</mi><mi>b</mi></mfenced></msup></mstyle><mo>+</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mn>3</mn></msubsup><mrow><mi>h</mi><msup><mo>′</mo><mfenced open="[" close="]"><mi>a</mi></mfenced></msup></mrow></mstyle><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>q</mi></math><img file="EP4040713A1_D0227.tif" /></maths>. Victor chooses a challenge <i>u</i> ∈ [3]. Let <i>u'</i> := <i>u</i> + 1 mod 3. Peter reveals secret pieces corresponding to 2 indices determined by Victor for <i>u</i>, namely <i>c</i>, <maths id="math0219"><math display="inline"><msubsup><mi>r</mi><mi>u</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0228.tif" /></maths>, <maths id="math0220"><math display="inline"><msubsup><mi>r</mi><mrow><mi>u</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0229.tif" /></maths>, <maths id="math0221"><math display="inline"><msubsup><mi>r</mi><mi>u</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0230.tif" /></maths>, <maths id="math0222"><math display="inline"><msubsup><mi>r</mi><mrow><mi>u</mi><mo>′</mo></mrow><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0231.tif" /></maths><i>, υ<sub>u</sub></i>, <i>υ<sub>u'</sub></i>, thus allowing Victor to learn <i>w</i><sup>[<i>u</i>]</sup><i>, w</i><sup>[<i>u'</i>]</sup> but not about any <i>t</i><sup>[<i>i</i>]</sup>. Victor verifies the argument by reconstructing <i>r'</i><sup>[<i>u</i>,<i>u</i>]</sup>, <i>r'</i><sup>[<i>u</i>',<i>u</i>]</sup>, <i>r'</i><sup>[<i>u,u'</i>]</sup>, <i>v'<sub>u</sub></i> and checking that they respectively hash to <i>h</i><sup>[<i>u,u</i>]</sup><i>, h</i><sup>[<i>u',u</i>]</sup><i>, h</i><sup>[<i>u,u'</i>]</sup><i>, h'</i><sup>[<i>u</i>]</sup>, and by checking that <i>h<sub>M</sub></i>(<i>c</i>) = <i>y.</i>
0154An eighth example zero-knowledge hashing argument for comparison of numbers is described. Peter makes zero-knowledge hashing arguments for comparison of numbers as follows. An argument for equality of numbers may be done by choosing and revealing equal parts. This may be done provided problems of finding a pre-image remain hard. In more detail, the argument may be made as follows. Let <i>s, s'</i> be secrets and let <i>K</i> ∈ [<i>m</i>]<i>.</i> Let <i>J</i> := {<i>j</i><sub>1</sub>,...<i>, j<sub>K</sub></i>}, <i>J'</i> := {<i>j'</i><sub>1</sub><i>,...,j'<sub>K</sub></i>} be sets where <i>J, J'</i> ⊆ [<i>m</i>] and ∀<i>k</i> ∈ [<i>K</i>] : <i>s<sub>j<sub2>k</sub2></sub></i> = <maths id="math0223"><math display="inline"><mi>s</mi><msub><mo>′</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></msub></math><img file="EP4040713A1_D0232.tif" /></maths><i>.</i> Peter makes an argument of knowledge of a pre-image modified as follows. In each round of the protocol, Peter may choose equal <i>r</i><sub>±,<i>jk</i></sub>, <maths id="math0224"><math display="inline"><msubsup><mi>r</mi><mrow><mo>±</mo><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0233.tif" /></maths> values and reveal only one pair, either <i>r</i><sub>+,<i>jk</i></sub>, <maths id="math0225"><math display="inline"><msubsup><mi>r</mi><mrow><mo>+</mo><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0234.tif" /></maths> or <i>r</i><sub><i>-</i>,<i>jk</i></sub>, <maths id="math0226"><math display="inline"><msubsup><mi>r</mi><mrow><mo>−</mo><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0235.tif" /></maths>, for all <i>k</i> ∈ <i>K,</i> e.g. using a challenge common to all these elements in a round pair. Victor verifies this argument for equality of numbers by checking said argument of knowledge of a pre-image and that the revealed <i>r</i><sub>0</sub> or <i>r</i><sub>1</sub> (one of <i>r</i><sub>±</sub>) has <maths id="math0227"><math display="inline"><mo>∀</mo><mi>k</mi><mo>∈</mo><mfenced open="[" close="]"><mi>K</mi></mfenced><mo>:</mo><mi>r</mi><msub><mo>.</mo><mrow><mo>,</mo><msub><mi>j</mi><mi>k</mi></msub></mrow></msub><mo>=</mo><mi>r</mi><mo>′</mo><msub><mo>.</mo><mrow><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow></msub></math><img file="EP4040713A1_D0236.tif" /></maths>.
0155An argument for inequality of numbers may be made as follows, provided problems of finding a pre-image remain hard. To argue that at least one number whose elements span [<i>m</i>] is unequal between two secrets <i>s</i><sup>[1]</sup> and <i>s</i><sup>[2]</sup>, Peter may post their unequal hash values (resp. hashes) <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup> where <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>) (resp. <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>s</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>s</i><sup>[2]</sup>))<i>.</i> Victor verifies this argument for inequality of elements by checking that <i>h</i><sup>[1]</sup> ≠ <i>h</i><sup>[2]</sup><i>.</i> To argue that at least one number in a set of numbers, whose elements span the set <i>J</i> ⊆ [<i>m</i>], is unequal between <i>s</i><sup>[1]</sup> and <i>s</i><sup>[2]</sup>, Peter may proceed as follows. Peter sets <i>s</i><sup>[3]</sup> where <maths id="math0228"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0237.tif" /></maths><i>for j</i> ∈ <i>J' :=</i> [<i>m</i>] \ <i>J</i> and <maths id="math0229"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0238.tif" /></maths> for <i>j</i> ∈ <i>J.</i> Now, Peter makes a partial argument for zero elements that <i>s</i><sup>[3]</sup> = 0 for <i>j</i> ∈ <i>J'</i> and one for modular subtraction of elements that <maths id="math0230"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0239.tif" /></maths> for <i>j</i> ∈ <i>J</i>, using argument techniques described herein. Thus, Peter makes <i>h</i><sup>[<i>3</i>]</sup> where <i>h</i><sup>[<i>3</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>) known to Victor. Victor verifies this argument for inequality of numbers by checking said arguments of knowledge of a pre-image and that <i>h</i><sup>[<i>3</i>]</sup> ≠ <i>h<sub>M</sub></i>(0)<i>.</i> With hardening, described herein, hardened hash values would be used instead, e.g. Peter would also make an argument for the hash value <i>h<sub>M</sub></i>(0<i>'</i>), where 0' is a harderning of 0, and Victor would use <i>h<sub>M</sub></i>(0<i>'</i>) in place of <i>h<sub>m</sub></i>(0) in verification.
0156An argument for ordering of numbers, e.g. one secret number being less than another, may be made using an argument for ordering of elements composing numbers, as follows. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> be secrets. To argue that s<sup>[1]</sup> ≥ <i>s</i><sup>[2]</sup> as numbers in <maths id="math0231"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0240.tif" /></maths>, Peter may make an argument for ordering of elements that <maths id="math0232"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>≥</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0241.tif" /></maths><i>for j</i> ∈ [<i>m</i>]<i>.</i> Here index <i>m</i> corresponds to the most significant digit of the numbers. To argue that <i>s</i><sup>[1]</sup> > <i>s</i><sup>[2]</sup> as numbers in <maths id="math0233"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0242.tif" /></maths>, Peter may make a similar argument for ordering of elements that <i>s</i><sup>[1]</sup> ≥ <i>s</i><sup>[2]</sup> + 1, using techniques for arguments with constant numbers as described herein. To argue that <i>s</i><sup>[1]</sup> ≤ <i>s</i><sup>[2]</sup> (resp. <i>s</i><sup>[1]</sup> < <i>s</i><sup>[2]</sup>) as numbers in <maths id="math0234"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0243.tif" /></maths>, Peter may make a similar argument with the roles of <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> swapped. Victor verifies each of these arguments for ordering of numbers by checking said argument for ordering of elements. These arguments may be modified to partial ones using techniques described herein applied to elements composing numbers.
0157A ninth example zero-knowledge hashing argument for constant numbers is described. Peter makes a zero-knowledge hashing argument for constant numbers as follows. Provided problems of finding a pre-image remains hard, arguing that a secret has (public) constant numbers may be done as follows. Let <i>J</i> ⊆ [<i>m</i>] be an element set and let <i>x<sub>j</sub></i> for <i>j</i> ∈ <i>J</i> be public, such that the numbers to be made public are composed of the elements in <i>J</i>. Let <i>s</i><sup>[1]</sup> be a secret where <maths id="math0235"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msub><mi>x</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0244.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Peter sets <i>s</i><sup>[2]</sup> where <i>s</i><sup>[2]</sup> = <i>x<sub>j</sub></i> for <i>j</i> ∈ <i>J</i> and <maths id="math0236"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><msub><mo>∈</mo><mi>R</mi></msub><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0245.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ <i>J</i> and posts <i>s</i><sup>[2]</sup>. Peter sets <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup> mod <i>q,</i> so that <maths id="math0237"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0246.tif" /></maths> for <i>j</i> ∈ <i>J</i> and <maths id="math0238"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>q</mi></math><img file="EP4040713A1_D0247.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ <i>J</i>, and makes a (partial) argument for subtraction of elements, as described herein, that <i>s</i><sup>[3]</sup> is the result of subtracting <i>s</i><sup>[2]</sup> from <i>s</i><sup>[1]</sup> and a (partial) argument for zero elements, as described herein, that <maths id="math0239"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0248.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Victor verifies this argument for constant numbers by checking said arguments of knowledge of a pre-image. This argument may also be made with subtraction of <i>s</i><sup>[1]</sup> from <i>s</i><sup>[2]</sup>.
0158A tenth example zero-knowledge hashing argument with negative numbers is described. Peter may make zero-knowledge hashing arguments with negative numbers as follows. First, Peter and Victor agree on a numeral system so that a certain set of positive numbers in <maths id="math0240"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>w</mi></msup></msub></math><img file="EP4040713A1_D0249.tif" /></maths>, where <i>w</i> is the number of elements composing a given number, is interpreted as negative numbers. To obtain simple arguments with negative numbers, a generalization of the two's complement numeral system to modulus <i>o</i> may be used, in which a number <maths id="math0241"><math display="inline"><mi>x</mi><mo>∈</mo><msub><mi>ℤ</mi><msup><mi>o</mi><mi>w</mi></msup></msub></math><img file="EP4040713A1_D0250.tif" /></maths>, <i>x</i> ≥ <i>o</i><sup><i>w</i>-1</sup> is interpreted as the negation of the number <maths id="math0242"><math display="inline"><mi>y</mi><mo>∈</mo><msub><mi>ℤ</mi><msup><mi>o</mi><mi>w</mi></msup></msub></math><img file="EP4040713A1_D0251.tif" /></maths> such that <i>x</i> + <i>y</i> = 0 mod <i>o<sup>w</sup></i>. A (possibly partial) argument that <i>x</i> is negative may be made by arguing that <i>x</i> ≥ <i>o</i><sup><i>w</i>-1</sup> using arguments for comparison of numbers and for constant numbers, described herein; similarly, an argument that a number <i>y</i> is (intepreted as) positive may be made by arguing that <i>y</i> < <i>o</i><sup><i>w</i>-1</sup>. An argument that the number <i>y</i> is the (positive) negation of <i>x</i> (argued to be negative) may be argued using an argument for addition for <i>x</i> + <i>y</i> followed by one for comparison to 0 of <i>x</i> + <i>y.</i> Other arguments for a relation with <i>x</i> may be made with arguments for a corresponding relation with <i>y</i>, where the connection between the two relation is determined by algebraic rules. In one example, an argument for addition (resp. subtraction) with <i>x</i> may be made using a corresponding argument for substraction (resp. addition) argument with <i>y.</i> In a second example, an argument for multiplication with numbers in said numeral system may be made using a corresponding argument for multiplication with the corresponding positive numbers followed by an adjustment for the sign, as follows. Let <i>y'</i> be the (positive) output of the latter argument. When both multiplicants of the former argument are argued to be positive or both negative, the output of the former argument is taken to be <i>y'</i> and otherwise it is taken to be <i>x</i>', which is a number argued to be the negative number corresponding to <i>y</i>'. If an argument output expected to be positive (resp. negative) in terms of number theory, e.g. the result of adding or of multiplying two positive numbers (resp. of adding two negative numbers or of multiplying a positive number and a negative number), is argued to be negative (resp. positive) in said numeral system then one may infer that an overflow has occured in the computation of the output.
0159An eleventh example zero-knowledge hashing argument for hashing is described. Peter makes a zero-knowledge hashing argument for hashing of elements or numbers as follows. Provided problems of finding a pre-image remain hard, arguing that a secret of size ≤ <i>m</i> elements hashes to some hash value may be a byproduct of other zero-knowledge hashing arguments described herein. For example, Peter may make an argument for o-ary elements, described herein, for the secret in order to argue that it hashes to some hash value that has been posted. If the size of the secret is > <i>m</i> elements then hashing may be done as follows. The secret <i>s</i> may be split element-wise into small secrets <i>s</i><sup>[<i>k</i>]</sup> of size ≤ <i>m</i> elements each. An argument for hashing of elements for a secret of size ≤ <i>m</i> elements as described is made for each of the small secret, thus posting the hash value <i>h</i><sup>[<i>k</i>]</sup> := <i>h<sub>M</sub></i>(<i>s</i><sup>[<i>k</i>]</sup>)<i>.</i> Finally, the hash value for <i>s</i> may be set to a cryptographic hash of the <i>h</i><sup>[<i>k</i>]</sup> values. The cryptographic hash may be any agreed one between the prover and the verifier. For example, an authenticated data structure, such as a Merkle tree, or an incremental hash, such as AdHash and LtHash, may be used for the cryptographic hash; such hashes have the benefit of supporting parallel and distributed evaluation. Standard techniques, such as applying another secure hash to the hash of the authenticated data structure, may be used to strengthen security, e.g. against a length extension attack. Moreover, arguments for hashing may be applied to pieces of a secret or to pieces of each secret corresponding to a node in an authenticated data structure. For example, each secret corresponding to a node in a Merkle tree <i>T</i> of secrets may be split into <i>p</i> pieces, such that <i>n</i> Merkle trees <maths id="math0243"><math display="inline"><msubsup><mi>T</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0252.tif" /></maths> for <i>i</i> ∈ [<i>p</i>] may be formed with all nodes corresponding to <i>i</i>th pieces for some <i>i</i> ∈ [<i>p</i>], and an argument for hashing may be made for each <maths id="math0244"><math display="inline"><msubsup><mi>T</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0253.tif" /></maths>.
0160<figref idref="f0013">FIG. 11</figref> is a schematic diagram of a system illustrating an example use of zero-knowledge hashing. With respect to the eleventh example zero-knowledge hashing, <figref idref="f0013">FIG. 11</figref> shows each Merkle tree 1110-1140 as a triangle, with internal nodes not shown, along with a root node and a leaf node. <figref idref="f0013">FIG. 11</figref> illustrates that the root node 1142 of tree 1140 is split into a corresponding root node 1112,1122,1132 in each of the piece trees 1110,1120,1130 and that the leaf node 1144 of tree 1140 is split into a corresponding leaf node 1114,1124,1134 in each of the piece trees 1110,1120,1130. This illustration conveys that each node, including internal nodes, on the tree 1140 is split into a corresponding node in each of the piece trees 1110,1120,1130. This structure of Merkle tree spliting enables arguing about <i>T</i>, e.g. that a specific leaf node in <i>T</i> has a secret hash value <i>h</i>, by making arguments about <maths id="math0245"><math display="inline"><msubsup><mi>T</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0254.tif" /></maths> for <i>i</i> ∈ [<i>p</i>], e.g. that each corresponding leaf node in <maths id="math0246"><math display="inline"><msubsup><mi>T</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0255.tif" /></maths> has hash value <maths id="math0247"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0256.tif" /></maths> without revealing all <maths id="math0248"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0257.tif" /></maths><i>.</i> For example, the <maths id="math0249"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0258.tif" /></maths> values may sum to <i>h</i>, perhaps with carry vectors as described herein, yet nothing may be learned about <i>h</i> by the revealing of only some <maths id="math0250"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0259.tif" /></maths> values. Such methods may be used in verifiable previewing applications that use an authenticated data structure, such as a Merkle tree, e.g. to commit to the digital good.
0161A twelfth example zero-knowledge hashing argument for modular exponentiation is described. Peter makes a zero-knowledge hashing argument for modular exponentiation as follows. In an operation for modular exponentiation, let <i>o</i> be the modulus, <i>B</i> be the base, <i>P</i> be the power, <i>b</i> be an upper bound on the bit length of <i>P</i>, and <maths id="math0251"><math display="inline"><msubsup><mfenced open="{" close="}"><msub><mi>P</mi><mi>u</mi></msub></mfenced><mrow><mi>u</mi><mo>=</mo><mn>1</mn></mrow><mi>b</mi></msubsup></math><img file="EP4040713A1_D0260.tif" /></maths> be the (zero-padded) bit representation of <i>P.</i> First, Peter sets <i>Q<sub>u</sub></i> := 1+(B-1)<i>P<sub>u</sub></i> mod <i>ο</i> for <i>u</i> ∈ [<i>b</i>]. Next, Peter makes arguments for <maths id="math0252"><math display="inline"><msubsup><mfenced open="{" close="}"><msub><mi>P</mi><mi>u</mi></msub><msub><mi>Q</mi><mi>u</mi></msub></mfenced><mrow><mi>u</mi><mo>=</mo><mn>1</mn></mrow><mi>b</mi></msubsup></math><img file="EP4040713A1_D0261.tif" /></maths>, involving arguments for addition and for multiplication of numbers. Finally, Peter sets <i>R<sub>b</sub></i> := <i>Q<sub>b</sub></i> and (following exponentiation-by-squaring) <i>R<sub>u</sub></i> := <maths id="math0253"><math display="inline"><msub><mi>Q</mi><mi>u</mi></msub><msubsup><mi>R</mi><mrow><mi>u</mi><mo>+</mo><mn>1</mn></mrow><mn>2</mn></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0262.tif" /></maths> for <i>u</i> ∈ [<i>b</i>-1]<i>,</i> and makes arguments for <maths id="math0254"><math display="inline"><msubsup><mfenced open="{" close="}"><msub><mi>R</mi><mi>u</mi></msub></mfenced><mrow><mi>u</mi><mo>=</mo><mn>1</mn></mrow><mi>b</mi></msubsup></math><img file="EP4040713A1_D0263.tif" /></maths>, involving arguments for multiplication of numbers, to show that <i>R</i><sub>0</sub><i>= B<sup>P</sup>.</i> This method may be viewed as a private information retrieval (PIR) one for computing the product Π<sub>{<i>u</i>|<i>u</i>∈[<i>b</i>],<i>Pu</i>=1}</sub><i>B<sup>u</sup></i> mod <i>o</i> using <maths id="math0255"><math display="inline"><msubsup><mfenced open="{" close="}"><msub><mi>P</mi><mi>u</mi></msub></mfenced><mrow><mi>u</mi><mo>=</mo><mn>1</mn></mrow><mi>b</mi></msubsup></math><img file="EP4040713A1_D0264.tif" /></maths> as the selection bits.
0162A thirteenth example zero-knowledge hashing argument with floating point numbers is described. Peter makes a zero-knowledge hashing argument with (generalized) floating point numbers as follows. Let <i>F<sub>i</sub></i> := <i>B<sup>E<sub2>i</sub2></sup>M<sub>i</sub></i> for any <i>i</i> denote floating point numbers with base <i>B</i>, exponents <i>E<sub>i</sub></i>, and mantissas <i>M<sub>i</sub></i>. Peter may make arguments with <i>F<sub>i</sub></i> by using a common exponent. For example, a binary operation over <i>F</i><sub>1</sub>, <i>F</i><sub>2</sub> where <i>F</i><sub>1</sub> ≥ <i>F</i><sub>2</sub> is described. Peter sets <i>F</i><sub>3</sub> := <i>B</i><sup><i>E</i><sub2>3</sub2></sup><i>M</i><sub>3</sub> where <i>E</i><sub>3</sub> := <i>E</i><sub>2</sub>, <i>M</i><sub>3</sub> := <i>M</i><sub>1</sub><i>B</i><sup><i>E</i><sub2>1</sub2><i>-E</i>2</sup><i>.</i> Peter argues these relations, which involves arguments for equality, subtraction, multiplication, and modular exponentiation, described herein, so that <i>F</i><sub>3</sub> = <i>F</i><sub>1</sub>, may be inferred by a verifier. Now <i>F</i><sub>2</sub>, <i>F</i><sub>3</sub> have a common exponent. Peter may make arguments for arithmetic operations over <i>F</i><sub>2</sub>, <i>F</i><sub>3</sub> by arguing operations on the mantissas and keeping the exponent, e.g. an addition <i>F</i><sub>4</sub> := <i>F</i><sub>2</sub> + <i>F</i><sub>3</sub> may be argued as <i>M</i><sub>4</sub> = <i>M</i><sub>2</sub> + <i>M</i><sub>3</sub><i>, E</i><sub>4</sub> = <i>E</i><sub>2</sub><i>.</i> Peter may truncate mantissas, by dropping least significant elements in them, or extend exponents, by zero-padding most significant elements to them, for example, when making arguments with floating point numbers. A signed mantissa may be used, and the sign may be argued using a comparison argument, described herein.
0163A fourteenth example zero-knowledge hashing argument for packing of elements is described. Peter makes a zero-knowledge hashing argument for packing of elements as follows. Herein, packing means composing an element from multiple elements as its digits, possibly with a varying base (radix). For example, an element in <maths id="math0256"><math display="inline"><msub><mi>ℤ</mi><msup><mn>2</mn><mrow><mn>2</mn><mi>d</mi></mrow></msup></msub></math><img file="EP4040713A1_D0265.tif" /></maths> with 2<i>d</i> binary digits may be made by packing 2<i>d</i> elements each in <maths id="math0257"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0266.tif" /></maths>, or alternatively <i>d</i> elements each in <maths id="math0258"><math display="inline"><msub><mi>ℤ</mi><msup><mn>2</mn><mn>2</mn></msup></msub></math><img file="EP4040713A1_D0267.tif" /></maths>, or alternatively a mix of elements each in <maths id="math0259"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0268.tif" /></maths> or <maths id="math0260"><math display="inline"><msub><mi>ℤ</mi><msup><mn>2</mn><mn>2</mn></msup></msub></math><img file="EP4040713A1_D0269.tif" /></maths> with a total of 2<i>d</i> bits. By way of example, packing of <i>ν</i> elements each in <maths id="math0261"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0270.tif" /></maths> into an element in <maths id="math0262"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>v</mi></msup></msub></math><img file="EP4040713A1_D0271.tif" /></maths> is described. Here, a free index <i>a</i> ranges over [<i>ν</i>]. Let <i>s</i><sup>[a]</sup> ∈ <i>S<sup>m</sup></i> and <maths id="math0263"><math display="inline"><msup><mi>s</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mfenced><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mi>ν</mi></msubsup><mrow><msup><mi>o</mi><mrow><mi>a</mi><mo>−</mo><mn>1</mn></mrow></msup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mi>a</mi></mfenced></msubsup></mrow></mstyle></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0272.tif" /></maths> be secrets. Peter argues knowledge of pre-images of <i>h</i><sup>[<i>a</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[<i>a</i>]</sup>), with all <i>k</i><sup>[<i>a</i>]</sup> equal, using a method as described above, thus posting <i>h</i><sup>[<i>a</i>]</sup><i>.</i> Peter sets <maths id="math0264"><math display="inline"><msup><mi>t</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msup><mo>:</mo><mo>=</mo><msubsup><mfenced><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mi>ν</mi></msubsup><mrow><msup><mi>o</mi><mrow><mi>a</mi><mo>−</mo><mn>1</mn></mrow></msup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mi>a</mi></mfenced></msubsup></mrow></mstyle></mfenced><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0273.tif" /></maths>, <i>h</i><sup>[<i>ξ</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[<i>ξ</i>)]</sup> and posts <i>h</i><sup>[<i>ξ</i>]</sup>. Now, <i>s</i><sup>[<i>ξ</i>]</sup> is determined by <i>t</i><sup>[<i>ξ</i>]</sup>, where <maths id="math0265"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup><mo>=</mo><mfenced open="|" close="|"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup></mfenced></math><img file="EP4040713A1_D0274.tif" /></maths> and <maths id="math0266"><math display="inline"><msubsup><mi>t</mi><mi>j</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup><mo>=</mo><msubsup><mi>k</mi><mi>j</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup></math><img file="EP4040713A1_D0275.tif" /></maths>, with <i>k</i><sup>[<i>ξ</i>]</sup> = <i>k</i><sup>[<i>a</i>]</sup>. Hence, h<sup>[<i>ξ</i>]</sup> is a hash value for <i>s</i><sup>[<i>ξ</i>]</sup>. Victor verifies this argument for packing of elements by checking said arguments of knowledge of a pre-image and that <maths id="math0267"><math display="inline"><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mi>ν</mi></msubsup><mrow><msup><mi>o</mi><mrow><mi>a</mi><mo>−</mo><mn>1</mn></mrow></msup><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mi>a</mi></mfenced></msubsup><mo>=</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>q</mi></mrow></mstyle></math><img file="EP4040713A1_D0276.tif" /></maths>.
0164This argument may be characterized as follows. For <i>o</i> = 2, packing of elements is equivalent to a bit-packing. Given arguments of knowledge of pre-images for <i>h</i><sup>[<i>a</i>]</sup> (as inputs to this argument) have already been made, the computational resources demanded by this argument for packing of elements are dominated by 1 argument of knowledge of a pre-image. The communication resources demanded by this argument may be reduced by having Victor recover <maths id="math0268"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>a</mi><mo>=</mo><mn>1</mn></mrow><mi>ν</mi></msubsup><mrow><msup><mi>o</mi><mrow><mi>a</mi><mo>−</mo><mn>1</mn></mrow></msup><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mi>a</mi></mfenced></msubsup></mrow></mstyle></math><img file="EP4040713A1_D0277.tif" /></maths> and Peter skip posting <maths id="math0269"><math display="inline"><msubsup><mi>r</mi><mo>±</mo><mfenced open="[" close="]"><mi>ξ</mi></mfenced></msubsup></math><img file="EP4040713A1_D0278.tif" /></maths>.
0165This argument may be enhanced as follows. Hashes of the form <i>h<sub>r,M</sub></i> and either a fixed base <i>S</i> or a varying base <maths id="math0270"><math display="inline"><msub><mi>S</mi><mi>j</mi></msub><mo>:</mo><mo>=</mo><msub><mi>ℤ</mi><msub><mi>o</mi><mi>j</mi></msub></msub></math><img file="EP4040713A1_D0279.tif" /></maths> for corresponding varying moduli <i>o<sub>j</sub></i> may be used similarly. A partial argument and an extended argument may be made in similar ways as well. An argument for unpacking of elements may be made using an argument for packing of elements, where ·<sup>[<i>ξ</i>]</sup> is on the input side and ·<sup>[<i>a</i>]</sup> are on the output side of the argument; in both packing and unpacking, the same relations in arguing and verifying apply.
0166A fifteenth example zero-knowledge hashing argument for logical operations on elements is described. Peter makes zero-knowledge hashing arguments for logical operations as follows. An argument for logical-NOT of elements in <maths id="math0271"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0280.tif" /></maths> may be made using an argument for subtraction of elements in <maths id="math0272"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0281.tif" /></maths> with a minuend 1. For example, to argue that <maths id="math0273"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>=</mo><mo>¬</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0282.tif" /></maths> where <i>o</i> = 2 for <i>j</i> ∈ [<i>m</i>], an argument that <maths id="math0274"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>=</mo><mn>1</mn><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0283.tif" /></maths> where <i>o</i> = 2 for <i>j</i> ∈ [<i>m</i>] may be made.
0167An argument for logical-AND of elements in <maths id="math0275"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0284.tif" /></maths> may be made using an argument for addition of elements in <maths id="math0276"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0285.tif" /></maths> with a carry 1. For example, to argue that <maths id="math0277"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>∧</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0286.tif" /></maths> where <i>o</i> = 2 for <i>j</i> ∈ [<i>m</i>], an argument that <maths id="math0278"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>−</mo><msub><mi mathvariant="italic">oc</mi><mi>j</mi></msub><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0287.tif" /></maths> where <i>o</i> = 2, <i>c<sub>j</sub></i> = 1 (by showing that <maths id="math0279"><math display="inline"><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>+</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><msub><mi mathvariant="italic">oy</mi><mi>i</mi></msub><mo>=</mo><msubsup><mi>h</mi><mi>i</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>q</mi></math><img file="EP4040713A1_D0288.tif" /></maths> as described herein) for <i>j</i> ∈ [<i>m</i>] may be made.
0168An argument for logical-AND of elements in <maths id="math0280"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0289.tif" /></maths> may also be made using an argument for modular multiplication of elements in <maths id="math0281"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0290.tif" /></maths>. For example, to argue that <maths id="math0282"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>∨</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0291.tif" /></maths> where <i>o</i> = 2 <i>for j</i> ∈ [<i>m</i>], an argument that <maths id="math0283"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0292.tif" /></maths> where <i>o</i> = 2 <i>for j</i> ∈ [<i>m</i>] may be made.
0169An argument for a logical operation may be made using one or more arguments for other logical operations that compose to it per Boolean algebra rules. For example, an argument for logical-NAND may be made composing ones for logical-AND and logical-NOT, and one for logical-NOR may be made by composing ones for logical-OR and logical-NOT. Similarly, an argument for a given Boolean function may be made by composing arguments for logical operations per the logical form of the Boolean function.
0170Arguments for logical operations on elements in <maths id="math0284"><math display="inline"><msub><mi>ℤ</mi><msup><mn>2</mn><mi>w</mi></msup></msub><mo>⊂</mo><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0293.tif" /></maths> may be made using arguments for unpacking, as described herein, each element into <i>w</i> elements in <maths id="math0285"><math display="inline"><msub><mi>ℤ</mi><mn>2</mn></msub></math><img file="EP4040713A1_D0294.tif" /></maths> and arguments for logical operations on the unpacked elements.
0171A sixteenth example zero-knowledge hashing argument for comparison of elements is described. Peter makes zero-knowledge hashing arguments for comparison of elements as follows. An argument for equality of elements may be done by choosing and revealing equal parts. This may be done provided problems of finding a pre-image remain hard. In more detail, the argument may be made as follows. Let <i>J</i> ⊆ [<i>m</i>] be a set of elements where ∀<i>j</i>, <i>j'</i> ∈ <i>J</i> : <i>s<sub>j</sub></i> = <i>s'<sub>j</sub></i>. Peter makes an argument of knowledge of a pre-image with the following modification. In each round of the protocol, Peter may choose equal r<sub>±,<i>j</i></sub> values for the elements and reveal only one value, either <i>r</i><sub>+,<i>j</i></sub> or <i>r<sub>-,j</sub></i>, for all elements in <i>J</i>, e.g. using a challenge common to all these elements in a round pair. Victor verifies this argument for equality of elements by checking said argument of knowledge of a pre-image and that the revealed <i>r</i><sub>0</sub> or <i>r</i><sub>1</sub> (one of <i>r</i><sub>±</sub>) has ∀<i>j</i>, <i>j'</i> : <i>r.<sub>,j</sub></i> = <i>r.<sub>,j'</sub>.</i> The described modification may be applied similarly to an argument involving more than one secret, where the equal elements may be of one or more secrets.
0172An argument for inequality of elements may be made as follows, provided problems of finding a pre-image remain hard. To argue that at least one element in [<i>m</i>] is unequal between two secrets <i>s</i><sup>[1]</sup> and <i>s</i><sup>[2]</sup>, Peter may post their unequal hash values (resp. hashes) <i>h</i><sup>[1]</sup><i>, h</i><sup>[2]</sup> where <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>) (resp. <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>s</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>s</i><sup>[2]</sup>))<i>.</i> Victor verifies this argument for inequality of elements by checking that <i>h</i><sup>[1]</sup> ≠ <i>h</i><sup>[2]</sup><i>.</i> To argue that at least one element in a set <i>J</i> ⊆ [<i>m</i>] is unequal between <i>s</i><sup>[1]</sup> and <i>s</i><sup>[2]</sup>, Peter may proceed as follows. Peter sets <i>s</i><sup>[3]</sup> where <maths id="math0286"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0295.tif" /></maths> for <i>j</i> ∈ <i>J'</i> := [<i>m</i>] \ <i>J</i> and <maths id="math0287"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0296.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Now, Peter makes a partial argument for zero elements, as described herin, that <i>s</i><sup>[3]</sup> = 0 for <i>j</i> ∈ <i>J'</i> and a partial argument for modular subtraction of elements, as described herein, that <i>s</i><sup>[3]</sup> = <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup> for <i>j</i> ∈ <i>J.</i> Thus, Peter makes <i>h</i><sup>[<i>3</i>]</sup> where <i>h</i><sup>[<i>3</i>]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>) known to Victor. Victor verifies this argument for inequality of elements by checking said arguments of knowledge of a pre-image and that <i>h</i><sup>[3]</sup> ≠ <i>h<sub>M</sub></i>(0)<i>.</i> With hardening, described herein, the hardened hash values would be used instead, e.g. Peter would also make an argument for the hash value <i>h<sub>M</sub></i>(0')<i>,</i> where 0' is a harderning of 0, and Victor would use <i>h<sub>M</sub></i>(0') in place of <i>h<sub>M</sub></i>(0) in verification.
0173A seventeenth example zero-knowledge hashing argument for comparison of elements is described. Peter makes zero-knowledge hashing arguments for comparison of numbers as follows. An argument for equality of numbers may be done by choosing and revealing equal parts. This may be done provided problems of finding a pre-image remain hard. In more detail, the argument may be made as follows. Let <i>s, s</i>' be secrets and let <i>K</i> ∈ [<i>m</i>]<i>.</i> Let <i>J</i> := {<i>j</i><sub>1</sub><i>,...,j<sub>K</sub></i>}, <maths id="math0288"><math display="inline"><mi>J</mi><mo>′</mo><mo>:</mo><mo>=</mo><mfenced open="{" close="}"><msubsup><mi>j</mi><mn>1</mn><mo>′</mo></msubsup><mo>,</mo><mo>…</mo><mo>,</mo><msubsup><mi>j</mi><mi>K</mi><mo>′</mo></msubsup></mfenced></math><img file="EP4040713A1_D0297.tif" /></maths> be sets where <i>J</i>, <i>J</i>' ⊆ [<i>m</i>] and <maths id="math0289"><math display="inline"><mo>∀</mo><mi>k</mi><mo>∈</mo><mfenced open="[" close="]"><mi>K</mi></mfenced><mo>:</mo><msub><mi>s</mi><msub><mi>j</mi><mi>k</mi></msub></msub><mo>=</mo><mi>s</mi><msub><mo>′</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></msub></math><img file="EP4040713A1_D0298.tif" /></maths><i>.</i> Peter makes an argument of knowledge of a pre-image modified as follows. In each round of the protocol, Peter may choose equal <i>r</i><sub>±,<i>j<sub>k</sub></i></sub>, <maths id="math0290"><math display="inline"><mi>r</mi><msub><mo>′</mo><mrow><mo>±</mo><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow></msub></math><img file="EP4040713A1_D0299.tif" /></maths> values and reveal only one pair, either r<sub>+,<i>j<sub>k</sub></i></sub>, <maths id="math0291"><math display="inline"><msubsup><mi>r</mi><mrow><mo>+</mo><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0300.tif" /></maths> or <i>r</i><sub>-,<i>j<sub>k</sub></i></sub>, <maths id="math0292"><math display="inline"><msubsup><mi>r</mi><mrow><mo>−</mo><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0301.tif" /></maths>, for all <i>k</i> ∈ <i>K</i>, e.g. using a challenge common to all these elements in a round pair. Victor verifies this argument for equality of numbers by checking said argument of knowledge of a pre-image and that the revealed <i>r</i><sub>0</sub> or <i>r</i><sub>1</sub> (one of <i>r</i><sub>±</sub>) has <maths id="math0293"><math display="inline"><mo>∀</mo><mi>k</mi><mo>∈</mo><mfenced open="[" close="]"><mi>K</mi></mfenced><mo>:</mo><msub><mi>r</mi><mrow><mo>,</mo><msub><mi>j</mi><mi>k</mi></msub></mrow></msub><mo>=</mo><msubsup><mi>r</mi><mrow><mo>,</mo><msubsup><mi>j</mi><mi>k</mi><mo>′</mo></msubsup></mrow><mo>′</mo></msubsup></math><img file="EP4040713A1_D0302.tif" /></maths><i>.</i>
0174An argument for inequality of numbers may be made as follows, provided problems of finding a pre-image remain hard. To argue that at least one number whose elements span [<i>m</i>] is unequal between two secrets <i>s</i><sup>[1]</sup> and <i>s</i><sup>[2]</sup>, Peter may post their unequal hash values (resp. hashes) <i>h</i><sup>[1]</sup>, <i>h</i><sup>[2]</sup> where <i>h</i><sup>[1]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>) (resp. <i>h</i><sup>[1]</sup> := <i>hM</i>(<i>s</i><sup>[1]</sup>), <i>h</i><sup>[2]</sup> := <i>h<sub>M</sub></i>(<i>s</i><sup>[2]</sup>))<i>.</i> Victor verifies this argument for inequality of elements by checking that <i>h</i><sup>[1]</sup> ≠ <i>h</i><sup>[2]</sup>. To argue that at least one number in a set of numbers, whose elements span the set <i>J</i> C [<i>m</i>], is unequal between <i>s</i><sup>[1]</sup> and <i>s</i><sup>[2]</sup>, Peter may proceed as follows. Peter sets <i>s</i><sup>[3]</sup> where <maths id="math0294"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0303.tif" /></maths><i>for j</i> ∈ <i>J'</i> := [<i>m</i>] \ J and <maths id="math0295"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>:</mo><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0304.tif" /></maths><i>for j</i> ∈ <i>J</i>. Now, Peter makes a partial argument for zero elements, described herein, that <i>s</i><sup>[3]</sup> = 0 for <i>j</i> ∈ <i>J</i>' and one for modular subtraction of elements, described herein, that <maths id="math0296"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0305.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Thus, Peter makes <i>h</i><sup>[3]</sup> where <i>h</i><sup>[3]</sup> := <i>h<sub>M</sub></i>(<i>t</i><sup>[3]</sup>) known to Victor. Victor verifies this argument for inequality of numbers by checking said arguments of knowledge of a pre-image and that <i>h</i><sup>[3]</sup> ≠ <i>h<sub>M</sub></i>(0). With hardening, the hardened hash values would be used instead, e.g. Peter would also make an argument for the hash value <i>h<sub>M</sub></i>(0'), where 0' is a harderning of 0, and Victor would use <i>h<sub>M</sub></i> (0') in place of <i>h<sub>M</sub></i> (0) in verification.
0175An eighteenth example zero-knowledge hashing argument for ordering of elements is described. An argument for ordering of elements, such as one element's secret value being less than another's, may be made using an argument for subtraction involving the elements and preserving the sign, as follows. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> be secrets. To argue that <maths id="math0297"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>≥</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0306.tif" /></maths> for <i>j</i> ∈ [<i>m</i>], Peter sets <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup> and makes an argument that <i>s</i><sup>[3]</sup> + <i>s</i><sup>[2]</sup> = <i>s</i><sup>[1]</sup> where <i>k</i><sup>[1]</sup> = <i>k</i><sup>[2]</sup> = <i>k</i><sup>[3]</sup>; this argument is similar to the one for modular addition of elements described herein without the signed carry vector. To argue that <maths id="math0298"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>></mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0307.tif" /></maths> for <i>j</i> ∈ [<i>m</i>], Peter makes a similar argument that <maths id="math0299"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>≥</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mo>+</mo><mn>1</mn></math><img file="EP4040713A1_D0308.tif" /></maths> using arguments with constant elements described herein. To argue that <maths id="math0300"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>≤</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0309.tif" /></maths> (resp. <maths id="math0301"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo><</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0310.tif" /></maths>) for <i>j</i> ∈ [<i>m</i>], Peter makes a similar argument with the roles of <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> swapped. Victor verifies each of these arguments for ordering of elements by checking said argument of knowledge of a pre-image and that <i>k</i><sup>[1]</sup> = <i>k</i><sup>[2]</sup> = <i>k</i><sup>[3]</sup>. This argument may be modified to a partial one for a set <i>J</i> ⊆ [<i>m</i>] of elements using techniques for arguments for permutation of elements described herein, e.g. by setting <i>r<sub>j</sub></i> values in <maths id="math0302"><math display="inline"><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0311.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ <i>J</i> while continuing to set <i>r<sub>j</sub></i> values in <maths id="math0303"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0312.tif" /></maths> for <i>j</i> ∈ <i>J.</i>
0176An argument for ordering of numbers, e.g. one secret number being less than another, may be made using an argument for ordering of elements composing numbers, as follows. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> be secrets. To argue that <i>s</i><sup>[1]</sup> ≥ <i>s</i><sup>[2]</sup> as numbers in <maths id="math0304"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0313.tif" /></maths>, Peter may make an argument for ordering of elements that <maths id="math0305"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>≥</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0314.tif" /></maths><i>for j</i> ∈ [<i>m</i>]. Here index <i>m</i> corresponds to the most significant digit of the numbers. To argue that <i>s</i><sup>[1]</sup> > <i>s</i><sup>[2]</sup> as numbers in <maths id="math0306"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0315.tif" /></maths>, Peter may make a similar argument for ordering of elements, described herein, that <i>s</i><sup>[1]</sup> ≥ <i>s</i><sup>[2]</sup> + 1. To argue that <i>s</i><sup>[1]</sup> ≤ <i>s</i><sup>[2]</sup> (resp. <i>s</i><sup>[1]</sup> < <i>s</i><sup>[2]</sup>) as numbers in <maths id="math0307"><math display="inline"><msub><mi>ℤ</mi><msup><mi>o</mi><mi>m</mi></msup></msub></math><img file="EP4040713A1_D0316.tif" /></maths>, Peter may make a similar argument with the roles of <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup> swapped. Victor verifies each of these arguments for ordering of numbers by checking said argument for ordering of elements. These arguments may be modified to partial ones using techniques for permutation of elements, described herein, applied to elements composing numbers.
0177A nineteenth example zero-knowledge hashing argument for constant elements or numbers is described. Peter makes a zero-knowledge hashing argument for constant elements as follows. Provided problems of finding a pre-image remains hard, arguing that a secret has (public) constant elements may be done as follows. Let <i>J</i> ⊆ [<i>m</i>] be an element set and let <i>x<sub>j</sub></i> for <i>j</i> ∈ <i>J</i> be public. Let <i>s</i><sup>[1]</sup> be a secret where <maths id="math0308"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msub><mi>x</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0317.tif" /></maths> for <i>j</i> ∈ <i>J.</i> Peter sets <i>s</i><sup>[2]</sup> where <i>s</i><sup>[2]</sup> = <i>x<sub>j</sub></i> for <i>j</i> ∈ <i>J</i> and <maths id="math0309"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0318.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ J and posts <i>s</i><sup>[2]</sup>. Peter sets <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup> mod <i>q,</i> so that <maths id="math0310"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0319.tif" /></maths> for <i>j</i> ∈ <i>J</i> and <maths id="math0311"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0320.tif" /></maths> mod <i>q</i> for <i>j</i> ∈ [<i>m</i>] \ <i>J,</i> and makes a (partial) argument for subtraction of elements, described herein, that <i>s</i><sup>[3]</sup> is the result of subtracting <i>s</i><sup>[2]</sup> from <i>s</i><sup>[1]</sup> and a (partial) argument for zero elements, described herein, that <maths id="math0312"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0321.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Victor verifies this argument for constant elements by checking said arguments of knowledge of a pre-image. This argument may also be made with subtraction of <i>s</i><sup>[1]</sup> from <i>s</i><sup>[2]</sup>.
0178Peter makes a zero-knowledge hashing argument for constant numbers as follows. Provided problems of finding a pre-image remains hard, arguing that a secret has (public) constant numbers may be done as follows. Let <i>J</i> ⊆ [<i>m</i>] be an element set and let <i>x<sub>j</sub></i> for <i>j</i> ∈ <i>J</i> be public, such that the numbers to be made public are composed of the elements in <i>J.</i> Let <i>s</i><sup>[1]</sup> be a secret where <maths id="math0313"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>=</mo><msub><mi>x</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0322.tif" /></maths><i>for j</i> ∈ <i>J</i>. Peter sets <i>s</i><sup>[2]</sup> where <i>s</i><sup>[2]</sup> = <i>x<sub>j</sub></i> for <i>j</i> ∈ <i>J</i> and <maths id="math0314"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0323.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ <i>J</i> and posts <i>s</i><sup>[2]</sup>. Peter sets <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup> - <i>s</i><sup>[2]</sup> mod <i>q,</i> so that <maths id="math0315"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0324.tif" /></maths> for <i>j</i> ∈ <i>J</i> and <maths id="math0316"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>−</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>q</mi></math><img file="EP4040713A1_D0325.tif" /></maths> for <i>j</i> ∈ [<i>m</i>] \ <i>J</i>, and makes a (partial) argument for subtraction of elements, described herein, that <i>s</i><sup>[3]</sup> is the result of subtracting <i>s</i><sup>[2]</sup> from <i>s</i><sup>[1]</sup> and a (partial) argument for zero elements, described herein, that <maths id="math0317"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><mn>0</mn></math><img file="EP4040713A1_D0326.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Victor verifies this argument for constant numbers by checking said arguments of knowledge of a pre-image. This argument may also be made with subtraction of <i>s</i><sup>[1]</sup> from <i>s</i><sup>[2]</sup>.
0179Methods for making zero-knowledge hashing arguments mixing secret and public elements are described. Given a zero-knowledge hashing argument of knowledge of a pre-image, as described herein, Peter may modify the argument to one for which some elements are public (i.e. no longer secret), provided problems of finding a pre-image remain hard, as follows. If all elements of a given vector are intended to be made public, then in addition to making the (unodified) argument, Peter may reveal all elements of said vector, and Victor may verify the argument and that said vector hashes to its hash value as obtained from the argument. If only some elements are intended to be made public, Peter may make a (partial) argument for constant elements, described herein, where the constants used are the values of the elements intended to be made public, and Victor verifies the argument as described there.
0180Hardening of arguments of knowledge of a pre-image is described. Herein, hardening refers to modifications to such arguments that make it harder to mount attacks intended to discover a pre-image without knowing the secrets a-priori. Methods of hardening, salting arguments of knowledge of a pre-image, are described. Herein, salting refers to the use random (non-informative) secret values in addition to non-random (informative) ones. Salting allows making an argument of knowledges of a pre-image significantly more resistant to some forms of attacks. For example, an attack that involves guessing a pre-image for a given hash value would be harder to mount against a salted argument, since an attacker utilizing this form of attack would need to guess not only informative values but also non-informative values that have high entropy. An example way to salt an argument of knowledge of a pre-image is using <i>t</i> elements out of the <i>m</i> available for non-informative values that are drawn with uniform probability from the domain, e.g. for <i>o</i> = 2, <i>m</i> = 4096 the choice <i>t</i> = 128 would correspond to <i>o<sup>t</sup></i> ≡ 2<sup>128</sup> guesses an attacker may have to make for non-informative elements and to <i>m</i> - <i>t</i> = 3968 informative elements that may be used for arguments as described herein. Another example way is a modification of the former one that uses <i>t</i> extra elements instead. Thus, for 4096 informative elements and 128 non-informative ones, <i>m</i> is set to 4224 provided that problems of finding a pre-image remain hard. Yet another example is a hybrid of the former examples, where some elements are available and the rest are extra. Hardening an argument involving a relation between secrets may result in a relation between the non-informative elements of the hardened secrets; however, provided problems of finding a pre-image remain hard this does not significantly help an attacker.
0181Strength of arguments of knowledge of a pre-image described herein is considered. In case Peter is honest, i.e. follows the protocol of the argument, then the argument is zero-knowledge, i.e. verification of the argument would pass and Victor would not learn anything about the secret pre-image from the protocol beyond what the argument is intended to convey, e.g. the secret's domain <i>S</i>. In this case, Victor may view a false-acceptance probability 2<sup>-<i>w</i></sup> for <i>w</i> pairs of rounds. In case Peter is not honest, i.e. tries to deviate from the protocol of the argument, Victor may view a false-acceptance probability <i>p</i> as follows. Peter may cheat by being lucky enough to escape from revealing a cheat-element <maths id="math0318"><math display="inline"><mi>x</mi><mo>∈</mo><msub><mi>ℤ</mi><mi>q</mi></msub><mo>\</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0327.tif" /></maths> in each pair of rounds. The negated case in which <maths id="math0319"><math display="inline"><mi>x</mi><mo>∈</mo><mo>−</mo><msub><mi>ℤ</mi><mi>q</mi></msub><mo>\</mo><mo>−</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0328.tif" /></maths> is similar. To this end, Peter selects <i>x</i><sub>+</sub>, <i>x</i>- where <i>x</i><sub>+</sub> + <i>x</i><sub>-</sub> = <i>x</i> mod <i>q</i> and at least one of <i>x</i><sub>±</sub> is in <maths id="math0320"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0329.tif" /></maths>. When <i>o</i> ≤ <i>x</i> < 2<i>o</i> - 1 Peter may select <i>x</i><sub>±</sub> ∈ {<i>x</i> - <i>o</i> + 1,..., <i>o</i> - 1} in some pairs of rounds and Victor observes that the values 0,..., <i>x</i> - <i>o</i> are missing. When <i>x</i> ≥ 2<i>o</i> - 1 Peter can only select one of <i>x</i><sub>±</sub> in <maths id="math0321"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0330.tif" /></maths>, and in each pair of rounds Victor has probability 1/2 of observing the other one; Peter may also do this when <i>o</i> ≤ <i>x</i> < 2o - 1 and would prefer to minimize <i>p</i>. Hence, the probability of Peter escaping with cheating in one pair of rounds is <i>c</i> := max(1/2, (2<i>o</i> - 1 - <i>x</i>)/<i>o</i>). The minimum number of pairs of rounds <i>w</i> to keep the false-acceptance probability no higher than 2<sup>-<i>t</i></sup> is at most ┌-<i>t</i>/log<sub>2</sub>(<i>c</i>)┐. When <i>o</i> = 2 or when <i>x</i> = 3<i>o</i>/2 - 1 it is at most <i>t</i>; the escaping probability decreases quickly as <i>x</i> increases towards 3<i>o</i>/2 - 1. Hence, a cheating Peter can only increase the escaping probability for a cheat value that is up to 50% higher than the range <maths id="math0322"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0331.tif" /></maths> argued for in an argument. Peter may select multiple cheat elements in one of <i>r</i><sub>±</sub>, yet this does not affect the escaping probability since an <i>r</i><sub>±</sub> vector is revealed in full, while Peter would not prefer to select cheat elements in both <i>r</i><sub>±</sub> as it only ensures verification would fail upon revealing. For argument composition, the hardness assumption means that a cheater in one argument is virtually forced to cheat in dependent arguments as well. Hence, the false-acceptance probability of the argument decreases quickly with <i>w</i> and the number of arguments transitivly dependent on it. A target for the false-acceptance probability may be used to determine the appropriate <i>w</i> to use with a given argument.
0182The system of <figref idref="f0015">FIG. 13</figref> shows an example embodiment of the system of <figref idref="f0001 f0002">FIG. 1</figref> that involves compilation. In the example, manifest source code may be provided to the manifest language front-ends 1310-1320. The manifest source code represents programs that may be compiled, in part of in full, from various high-level languages into executables with support for selective privacy and verification. The manifest source code may involve selective privacy and verification operations similar to general purpose programming languages such as the C language, e.g. with respect to operations on variables. The various zero-knowledge hashing arguments and techniques described herein, as well as others that would be apparent for one skilled in the art, may be used in implementing such operations. The manifest language front-ends 1310-1320 produce manifest middle code, which may be code in a form amenable for optimization that includes supports for selective privacy and verification. The manifest middle code is provided to the manifest code optimizer 1330 as input. The manifest code optimizer 1330 produces manifest optimized code, which may be in a form amenable for translation to program code with support for selective privacy and verification. Then, the manifest optimized code may be provided as input to any or all of the back-ends 1340-1360. The arguer back-end 1340 may use the manifest optimized code to produce program arguer code that includes support for arguing selective privacy. Such arguer code may be used by a first entity that wishes to avoid exposing secrets yet still allow a third-party entity to verify aspects of its secrets. The verifier back-end 1350 may use the manifest optimized code to produce program verifier code that includes support for selective verification. Such verifier code may be used by an entity that wishes to verify aspects of secrets of the first entity. The mixed back-end 1360 may use the manifest optimized code to produce program mixed code that includes support for selective arguing privacy and selective verification. Such mixed code may be used by entities that wish to play both roles of arguer and verifier.
0183The compilation process may involve standard techniques as well as techniques specific to arguments described herein. Here, compilation is understood in the wide sense, i.e. including processes performed by the front-ends, optimizer, and back-ends as described. The compilation process may, but is not limited to, use any of the example zero-knowledge hashing techniques described herein. For example, it may compile allocation of program variables by allocating memory for secret values and their parts. It may group variables together by allocating their secret values and their parts in the same vectors. It may rearrange such groups to facilitate SIMD operations by permuting secret values and their parts into vectors to apply a SIMD operation to vector values together. It may employ an argument cost model with code optimization to determine when it is beneficial to apply code transformation involving arguments such as SIMD ones. It may compile a simple expression, such as arithmetic, logical, and bitwise expressions, on program variables by making an argument involving the secret values and parts of these variables. It may compile a compound expression made of simple expressions by compiling arguments for the simple expressions and composing the arguments following the structure of the compound expression. It may compile control flow structures such as if- and loop- statements by compiling a control flow test on the result of a logical expression, which may be compound and involve other sub- expressions, e.g. arithmetic, and conditional branches corresponding to control branches. It may automatically harden arguments and/or determine the number of round pairs sufficient to bound the escape probability at a desirably low level for any argument that is compiled. It may also defer any of the above decisions to a later stage, e.g. to code execution time, by generating or including code for making these decisions.
0184Various techniques for zero-knowledge hashing argument with secret sharing are described. Secret sharing schemes, possibly verifiable and based on secure linear hashing schemes, may be used with linear zero-knowledge hashing arguments described herein. Such secret sharing schemes enable a dealer party to linearly split a secret into secret shares and distribute them to participant parties such that participants may later (independently from the dealer) collaborate to recover the secret by linearly combining their shares. If the secret sharing scheme used is verifiable then each participant may verify prior to collaboration that its share is valid, i.e. a collaboration would succeed in recovering the secret. An example for such a scheme is a lattice-based one due to Bansarkhani and Meziani. Such secret sharing schemes may be applied to a linear zero-knowledge hashing argument by taking the gestalt secret as the secret to share, the secret parts as the secret shares, and the same secure linear hashing scheme. For example, a zero-knowledge argument for modular addition of numbers, described herein, may be used with a verifiable secret sharing scheme based on secure linear hashing schemes, such that one secret share corresponds to <maths id="math0323"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0332.tif" /></maths>, <maths id="math0324"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0333.tif" /></maths>, <maths id="math0325"><math display="inline"><msubsup><mi>r</mi><mo>+</mo><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0334.tif" /></maths> and another to <maths id="math0326"><math display="inline"><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup></math><img file="EP4040713A1_D0335.tif" /></maths>, <maths id="math0327"><math display="inline"><msubsup><mi>r</mi><mo>−</mo><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0336.tif" /></maths>, <maths id="math0328"><math display="inline"><msup><mi>r</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msup></math><img file="EP4040713A1_D0337.tif" /></maths> while the hashes <i>h</i><sup>[1]</sup><i>, h</i><sup>[2]</sup><i>, h</i><sup>[3]</sup><i>, y</i> are public. Then, a verifier may verify that a collaboration between participants who together posses all secret shares would allow them to recover the result of the modular addition.
0185Techniques for streaming zero-knowledge hashing arguments, e.g. ones described herein, are described. Peter may stream arguments one after the other to Victor, so that each argument may be verified as it received. As a convention of the protocol between Peter and Victor or in information communicated between them, Peter may also indicate to Victor which states, e.g. hashes, need not be kept in order to reduce the amount of memory resources demanded by the protocol. For example, in a stream of arguments of a protocol designed to argue the average of a sequence of numbers, Peter may indicate to Victor that only state on sufficient statistics need be kept, e.g. the running count and sum of the numbers. Moreover, Peter may use multiple channels in streaming to Victor, e.g. in order to parallelize or for using channels with differing characteristics.
0186Techniques for transforming zero-knowledge hashing arguments are described. A sequence of arguments linear in their inputs may be folded into one argument. The resulting argument would have as input (resp. output) the union of these inputs (resp. outputs) and the relations it holds for the inputs and outputs would remain a linear one, and hence may be argued using similar zero-knowledge hashing techniques. For example, a sequence of three arguments for <i>t</i><sup>[3]</sup> = <i>t</i><sup>[1]</sup> + <i>t</i><sup>[2]</sup> mod <i>q, t</i><sup>[4]</sup> = γ<i>t</i><sup>[3]</sup> mod <i>q, t</i><sup>[5]</sup><i>= t</i><sup>[4]</sup> + <i>a</i> mod <i>q,</i> where <i>γ</i> is constant scalar and a is a constant vector, may be folded into one argument for <i>t</i><sup>[5]</sup> = <i>γt</i><sup>[1]</sup> + γ<i>t</i><sup>[2]</sup> + <i>a</i> mod <i>q.</i> In this case, the relation for the hashes would involve one or more carry vectors multiplied by <i>o</i>, as done in arguments for addition of elements or of numbers, described herein. In the same example, let <maths id="math0329"><math display="inline"><msub><mi>c</mi><mi>i</mi></msub><mo>∈</mo><msubsup><mi>ℤ</mi><mn>2</mn><mi>m</mi></msubsup><mo>,</mo><msub><mi>y</mi><mi>i</mi></msub><mo>:</mo><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msub><mi>c</mi><mi>i</mi></msub></mfenced><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>q</mi></math><img file="EP4040713A1_D0338.tif" /></maths> be carry vectors and their hashes for <i>i</i> ∈ [<i>u</i>] where <i>u</i> is the number of additions in the argument, then the resulting relation for hashes may be <maths id="math0330"><math display="inline"><msub><mi>h</mi><mi>M</mi></msub><mfenced><msup><mi>t</mi><mfenced open="[" close="]"><mn>5</mn></mfenced></msup></mfenced><mo>=</mo><mi>γ</mi><mfenced><msub><mi>h</mi><mi>M</mi></msub><mfenced><msup><mi>t</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msup></mfenced><mo>+</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><msup><mi>t</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msup></mfenced></mfenced><mo>+</mo><mi>a</mi><mo>+</mo><mi>o</mi><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>u</mi></msubsup><msub><mi>y</mi><mi>i</mi></msub></mstyle></math><img file="EP4040713A1_D0339.tif" /></maths> mod <i>q</i>. Further, a number <i>u</i>' of carry vectors in <maths id="math0331"><math display="inline"><msubsup><mi>ℤ</mi><mn>2</mn><mi>m</mi></msubsup></math><img file="EP4040713A1_D0340.tif" /></maths> may be folded into one carry vector in <maths id="math0332"><math display="inline"><msubsup><mi>ℤ</mi><mrow><mi>u</mi><mo>′</mo><mo>+</mo><mn>1</mn></mrow><mi>m</mi></msubsup></math><img file="EP4040713A1_D0341.tif" /></maths> provided problems of finding a pre-image remain hard. In the same example, with one fold for <i>u</i>' = <i>u</i>, let <maths id="math0333"><math display="inline"><mi>c</mi><mo>:</mo><mo>=</mo><mstyle displaystyle="true"><msubsup><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>u</mi></msubsup><mrow><msub><mi>c</mi><mi>i</mi></msub><mo>,</mo><mi>y</mi><mo>:</mo><mo>=</mo><msub><mi>h</mi><mi>M</mi></msub><mfenced><mi>c</mi></mfenced></mrow></mstyle></math><img file="EP4040713A1_D0342.tif" /></maths> be the carry vector and its hash, then the resulting relation for hashes may be <i>h<sub>M</sub></i>(<i>t</i><sup>[5]</sup>) = <i>γ</i>(<i>h<sub>M</sub></i>(<i>t</i><sup>[1]</sup>) + <i>h<sub>M</sub></i>(<i>t</i><sup>[2]</sup>)) + <i>a</i> + <i>oy</i> mod <i>q.</i>
0187Arguments in which multiple hashes are posted as commitments (by Peter) may be transformed into ones in which fewer commitments are posted as follows. Peter and Victor agree on a secure hash function <i>H</i>. Let C be the concatenation of all commitments that no other values depend on. After the transformation, the commitments composing <i>C</i> will not be posted. Peter computes <i>C</i>' := <i>H</i>(<i>C</i>) and posts <i>C</i>'. First, Victor reconstructs <i>C</i> from other posts by Peter. This is possible since no other values depends on commitments composing <i>C</i> and in the original arguments Victor is able to verify the commitments and hence compute an expected value for each of them. Victor verifies the transformed arguments as usual and in addition by and checking that <i>C</i>' = <i>H</i>(<i>C</i>).
0188Any argument other than one for zero elements, e.g an argument for modular multiplication of numbers described herein, may be transformed to a similar partial argument, e.g. a partial argument for modular multiplication of numbers, using an argument for partial equality of elements described herein, as in the following example. Let <i>s</i><sup>[1]</sup>, <i>s</i><sup>[2]</sup>, <i>s</i><sup>[3]</sup> be secrets, let ◇ be some binary operation, and let <i>J</i> ⊆ [<i>m</i>] be a set of elements such that <maths id="math0334"><math display="inline"><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>1</mn></mfenced></msubsup><mo>⋄</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>2</mn></mfenced></msubsup></math><img file="EP4040713A1_D0343.tif" /></maths> for <i>j</i> ∈ <i>J</i>. First, set <i>s</i><sup>[3]</sup> := <i>s</i><sup>[1]</sup>◇<i>s</i><sup>[2]</sup>, then make an argument that <maths id="math0335"><math display="inline"><mi>s</mi><msubsup><mo>′</mo><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup><mo>=</mo><msubsup><mi>s</mi><mi>j</mi><mfenced open="[" close="]"><mn>3</mn></mfenced></msubsup></math><img file="EP4040713A1_D0344.tif" /></maths> for <i>j</i> ∈ <i>J</i>. Arguments for unary opeartions and for numbers, for example, may be transformed similarly.
0189Linear zero-knowledge arguments described herein may be transformed as follows. A linear commitment method may be used to commit to a basis of elements of the vectors that would be revealed in the arguments being transformed. For example, for an argument for zero elements, described herein, the basis would include, or span, the elements of <i>r</i><sub>+</sub>, <i>r</i><sub>-</sub> involved in the argument. A commitment with selected openings method, e.g. with a pseudo-random sequence, may be used to reduce the communication demand for the linear commitment by opening only selected values as necessary by the verification protocol described next. A probabilistically checkable proof (PCP) for the relations, or constraints, involved in the verification of the arguments may be used. For example, a Hadamard-code based linear PCP may be used and optionally transformed into a multi-prover interactive proof (MIP), or, e.g. a shorter PCP may be used. For example, constructions such as one due to Ishai, Kushilevitz, and Ostrovsky, the Pepper one improving on in due to Setti, McPher-son, Blumberg and Walfish, and one due to Ben-Sasson, Goldreich, Harsha and Sudan may be used. A PCP has the benefit of faster verification than that of each argument separately. For example, a low number of queries to a PCP leads to a low number of selected openings in the described commitment with selected openings.
0190Zero-knowledge arguments described herein may be transformed by using other argument systems in a similar way. For example, PCPs of proximity, robust or interactive or multi-round PCPs, and hybrids thereof as well as succinct argument systems, such as ones based on quadratic (or square) span (or arithmetic) programs, as well as zero-knowledge from multiparti computation (MPC) may be used.
0191Homomorphic encryption machineries may also be used to enable the prover (Peter) to produce arguments in the encrypted domain, i.e. where operations on plain values are replaced with ones on values encrypted using some key that may be unknown to the prover, resulting in a verifiable homomorphically encrypted argument system. For example, lattice-based machineries described by Gama, Izabachene, Nguyen and Xie including the number-theoretic and generalized group constructions may be used.
0192Arguments described herein may also be. This enables transforming selected parts of a computation having a finite set of inputs and outputs to use precompute arguments for them, or a precomputed compound argument for the entire part, or a hybrid of these. For example, memoization may be used to avoid re-computation of (at least some) arguments, or (possibly speculative) prediction may be used to precompute arguments, or selected parts of a computation, before they are required by a computation. For example, one selected part may end with an argument for the (secure) hash of its output while another selected part may start with an argument for the same hash of its input, so that the second parts computation is a continuation of the firsts, yet the parts may be argued in a parallel or distributed fashion. A selected part may also be transformed from arguing how a result is computed to arguing a witness for the correctness of the result, which may be used to reduce the computational resources demanded. For example, a part arguing the computation of the <i>k</i>th highest number out of a group of <i>n</i> numbers may be transformed to an argument showing that said number is indeed the kth highest by making comparison arguments between it and each of the remaining <i>n</i> - 1 numbers.
0193Techniques for extending embodiments are described. This section describes a method for extending embodiments. By way of example, the extension is described for embodiments involving the discrete logarithm problem (DLP), which include all embodiments where a Schnorr-like protocol is used for constructing arguments. A group <i>G</i> of some order <i>o</i> is used in the description. An embodiment where argument <i>S</i> is constructed as a proof of knowledge of <i>x</i> in <i>y</i> := <i>g<sup>x</sup></i> in one instance may be extended to an embodiment having many instances. A possibly cryptographic, random or pseudo-random number generator <i>R</i>, for which <i>r<sub>i</sub></i> is the <i>i</i>th random number for <i>i</i> ∈ <img file="EP4040713A1_D0345.tif" /> , is set up. The number of <i>r<sub>i</sub></i> values may be bounded, e.g. polynomial in a security parameter. The initial instance corresponds to <i>i</i> = 0, <i>x</i><sub>0</sub> = <i>x</i>, <i>y</i><sub>0</sub> = <i>y</i>. In deriving instance <i>i</i> from instance <i>i</i> - 1, knowledge of <i>x</i><sub><i>i</i>-1</sub> in <i>y</i><sub><i>i</i>-1</sub> := <i>g</i><sup><i>x</i><sub2><i>i</i>-1</sub2></sup> leads to knowledge of <i>x<sub>i</sub></i> := <i>x</i><sub><i>i</i>-1</sub> + <i>r<sub>i</sub></i> mod <i>o</i> in <i>y<sub>i</sub></i> := <i>y</i><sub><i>i</i>-1</sub><i>g<sup>r<sub2>i</sub2></sup></i> or alternatively knowledge of <i>x<sub>i</sub></i> := <i>x</i><sub><i>i</i>-1</sub><i>r<sub>i</sub></i> mod <i>o</i> in <maths id="math0336"><math display="inline"><msub><mi>y</mi><mi>i</mi></msub><mo>:</mo><mo>=</mo><msubsup><mi>y</mi><mrow><mi>i</mi><mo>−</mo><mn>1</mn></mrow><msub><mi>r</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0346.tif" /></maths>. One may also copy, or reuse, <i>x<sub>i</sub></i> := <i>x</i><sub><i>i</i>-1</sub> in <i>y<sub>i</sub></i> := <i>y</i><sub><i>i</i>-1</sub>. Hence, no communication of <i>x<sub>i</sub>, y<sub>i</sub></i>, <i>r<sub>i</sub></i> is needed to construct the argument of the next instance, and it may be determined using shorter communications (and/or conventions, requiring no communication) for <i>R</i> and the derivation method for each <i>i</i>.
0194This construction may be enhanced to apply more widely, as described with respect to <figref idref="f0014">FIG. 12</figref>. A randomness generator 1210 may be used to obtain random numbers. The knowledge deriver 1220 uses the randomness provided by the randomness generator 1210. The knowledge deriver 1220 also uses existing knowledge provided by the knowledge storage engine 1230. By combining the provided existing knowledge and randomness, the knowledge deriver 1220 may produce new knowledge, which may be placed in the knowledge storage engine 1230, e.g. for future use. <figref idref="f0014">FIG. 12</figref> further shows example derivations 1221 for addition 1222, multiplication 1223, subtraction 1224, division 1225, and copying 1226. In general, more than one random number may be used in a single derivation, e.g. addition of two random numbers. Known information that is not random may also be used in addition to random values in order to derive new knowledge.
0195This construction may be enhanced to apply more widely. One may use more than one random number in a single derivation, e.g. addition of two random numbers. The above sequential structure of instances may be modified to a tree one using a tree-structured random number generator that is split at each node and that is applied a different derivation at each edge. As above, shorter communications (and/or conventions, requiring no communication) may be used to determine the next node to derive from and the derivation from it. One may apply the above to argument <i>T</i> of an embodiment, by observing that an implication of knowledge of <i>x</i><sub><i>i</i>-1</sub> in <i>y</i><sub><i>i</i>-1</sub> := <i>g</i><sup><i>x</i><sub2><i>i</i>-1</sub2></sup> leads to an implication of knowledge of <i>x<sub>i</sub></i> := <i>x</i><sub><i>i</i>-1</sub> +<i>r<sub>i</sub></i> mod <i>o</i> in <i>y<sub>i</sub></i> := <i>y</i><sub><i>i</i>-1</sub><i>g<sup>r<sub2>i</sub2></sup></i> or alternatively of <i>x<sub>i</sub></i> := <i>x</i><sub><i>i</i>-1</sub><i>r<sub>i</sub></i> mod <i>o</i> in <maths id="math0337"><math display="inline"><msub><mi>y</mi><mi>i</mi></msub><mo>:</mo><mo>=</mo><msubsup><mi>y</mi><mrow><mi>i</mi><mo>−</mo><mn>1</mn></mrow><msub><mi>r</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0347.tif" /></maths>. One may also apply the above, for <i>S</i> or <i>T</i>, with subtraction (resp. division) of <i>x</i><sub><i>i</i>-1</sub> by <i>r<sub>i</sub></i> using negation (resp. reciprocal) of <i>r<sub>i</sub></i> modulo <i>o</i> in an addition (resp. multiplication) derivation. One may also construct <i>G</i> with an unknown order and with a self-bilinear map <i>E</i> : <i>G</i> × <i>G</i> → <i>G</i>. The unknown order is beneficial for security, as the computational Diffie-Helman assumption does not hold for a group with a known order and a self-bilinear map. Now, one cannot find the negation or reciprocal modulo an unknown order, and so cannot derive using subtraction and division. One may still derive using addition and multiplication. One may derive knowledge of <i>x<sub>i</sub></i> := <i>x</i><sub><i>i</i>-1</sub><i>x</i><sub>0</sub> in <i>y<sub>i</sub></i> := <i>E</i>(<i>y</i><sub><i>i</i>-1</sub>, <i>y</i><sub>0</sub>), where <i>y</i><sub>0</sub> := <i>E</i>(<i>g</i><sup><i>x</i><sub2>0</sub2></sup><i>, g</i>), so that any power of <i>x</i> may be derived. By combining these types of derivation in the tree structure, one may derive polynomials of <i>x</i> in any degree. However, since <i>x</i> values cannot be applied an unknown modulus, they will grow in size fast, imposing practical limitations. The described techniques may also be generalized to embodiments with homomorphic cryptographic primitives other than DLP based ones, by using the homomorphic operations of the primitives for specification of the derivations for extending the embodiments.
0196A commitment scheme may be combined with verifiable communication to obtain a verifiable communication commitment. With respect to <figref idref="f0016">FIG. 14</figref>, the key committer 1410 produces the key commitment, which embeds the key argument, while the message committer 1420 produces the commitment message, which embeds the message argument. These key commitment is opened by the key opener 1430 to obtain the key opening and the key argument, while the message commitment is opened by the message opener 1440 to obtain the message opening and the message argument. The verifier 1450 compares the key opening with the key commitment and the message opening with the message commitment, and verifies that the commitments match the opening. The verifier also verifies the key argument and the message argument using available verifiable communication methods.
0197Several example methods for making verifiable communication commitments are described. A commitment scheme may be combined with verifiable communication to obtain a verifiable communication commitment. In order to convert an argument <i>S</i> (resp. <i>T</i>) into a commitment for <i>S</i> (resp. <i>T</i>), one may make a verifiable argument that opening of the commitment will reveal <i>S</i> (resp. <i>T</i>), or that knowledge of <i>r</i> implies <i>S</i> (resp. <i>T</i>). The opening does not reveal <i>M,</i> which remains secret as in verifiable communication. An interpretation of this construction is as chaining an implication argument from <i>r</i> to the argument <i>S</i> (resp. <i>T</i>). For example, for an argument <i>T</i>, an encoding of a message <i>M</i> such as Enc(<i>M</i>) := <i>g<sup>M</sup></i> mod <i>p</i> may appear with a commitment Com(Enc(<i>M</i>), <i>r</i>) for which one may verify that its opening, by the revealing of <i>r</i>, implies <i>T.</i> The notations Com(<i>S</i>, <i>r</i>), Com(<i>T</i>, <i>r</i>) may be used for a commitment for argument <i>S, T</i> respectively. Pedersen commitment scheme, the message remains secret. Using techniques for modifying embodiments described here and in prior art, this example may be generalized to other methods of verifiable communication based on DLP. As the construction relies on Pedersen commitments, security of existing commitments may be increased when desired by producing new commitments tied to the previous ones, while maintaining computational binding and information hiding properties of Pedersen commitments, using prolongation.
0198A first example of embodiments with verifiable communication commitments is described. A group <i>G</i> of prime order <i>p</i> of bit length <i>k</i> with a subgroup of prime order <i>o</i> of bit length <i>l</i>, such that <i>o</i>|<i>p</i> - 1, and two random generators <i>g, h</i> of the subgroup, such that DLP is hard for <i>g, h</i> and the discrete logarithm of <i>h</i> to base <i>g</i> is unknown, are set up. This establishes the set <i>G</i>.
0199User <i>A</i> wishing to receive a message from user <i>B</i> first chooses a secret key <maths id="math0338"><math display="inline"><mi>d</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0348.tif" /></maths> and a secret <maths id="math0339"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0349.tif" /></maths>, and constructs a corresponding public key <i>t</i> where <i>t := g<sup>d</sup></i> and a commitment <i>t</i>' to it where <i>t</i>' := <i>th<sup>a</sup>.</i> User <i>A</i> communicates (<i>g</i>, <i>t'</i>) openly and communicates <i>a, d</i> securely to user <i>B</i> using a traditional cryptographic communication system. This establishes pk = (<i>g, t'</i>) as a public key, sk = <i>d</i> as a secret key and <i>a</i> as a secret of the commitment shared by both user <i>A</i> and user <i>B.</i>
0200User <i>A</i> produces a commitment to an argument of knowing sk as <i>S</i>. User <i>A</i> chooses <i>r</i><sub>1</sub>, <maths id="math0340"><math display="inline"><msub><mi>r</mi><mn>2</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0350.tif" /></maths>, sets <i>v</i> := <i>g</i><sup><i>r</i><sub2>1</sub2></sup><i>h</i><sup><i>r</i>2</sup> and posts <i>v.</i> Given a challenge <i>c</i>' ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> sets <i>w</i><sub>1</sub> := <i>r</i><sub>1</sub> + <i>c'd</i> mod <i>o</i>, <i>w</i><sub>2</sub> := <i>r</i><sub>2</sub> + <i>c'a</i> mod <i>o</i> and posts <i>w</i><sub>1</sub><i>, w</i><sub>2</sub><i>.</i> The commitment to the argument is verified by checking that <i>g</i><sup><i>w</i><sub2>1</sub2></sup><i>h</i><sup><i>w</i>2</sup> = <i>vt'<sup>c'</sup>, g</i><sup><i>w</i>1</sup> = <i>v't<sup>c'</sup></i> where <i>v' := v</i>/<i>h</i><sup><i>r</i>2</sup>, and may be opened by revealing <i>r</i><sub>2</sub>, thereby revealing <i>a</i> as <i>a</i> = (<i>w</i><sub>2</sub> - <i>r</i><sub>2</sub>)/<i>c'</i> mod <i>o</i> and <i>t</i> as <i>t'</i>/<i>h<sup>a</sup>.</i>
0201User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces a commitment to an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. User <i>B</i> chooses <i>b</i>, <maths id="math0341"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0351.tif" /></maths>, sets <i>t</i>" := <i>t</i>, <i>u</i> := <i>g<sup>b</sup>h<sup>r</sup>, y</i> := <i>g<sup>M</sup>, y</i>' := <i>yh<sup>b</sup></i> and communicates <i>t</i>", <i>u</i>, <i>y</i>'. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>B</i> communicates (<i>s, w</i>) where <i>s</i> := <i>b</i>+<i>d</i>+<i>cM</i> mod <i>o, w</i> := <i>r</i>+<i>cb</i> mod <i>o</i>. The commitment to the argument is verified by checking that <i>g<sup>s</sup>h<sup>w</sup></i> = <i>ut"y'<sup>c</sup>, g<sup>s</sup></i> = <i>u't"y<sup>c'</sup></i> where <i>u</i>' := <i>u</i>/<i>h<sup>r</sup>,y</i> := <i>y'</i>/<i>h<sup>b</sup></i> and may be opened by revealing r, thereby also revealing <i>b</i> as <i>b</i> = (<i>w</i> - <i>r</i>)/<i>c</i> mod <i>o</i>. User <i>A</i> recovers M as (<i>s</i> - <i>b</i> - <i>d</i>)/<i>c</i> mod <i>o</i> once <i>b</i> has been revealed. Once the commitments to <i>S, T</i> are opened, one may verify they are related to the same sk by checking that <i>t</i>" = <i>t</i>. In this embodiment, one may view that the opening <i>r<sub>s</sub></i> for argument <i>S</i> is <i>a</i> (resp. and/or <i>r</i><sub>2</sub>) and the opening <i>r<sub>T</sub></i> of argument <i>T</i> is <i>b</i> (resp. and/or <i>r</i>).
0202A second example of embodiments with verifiable communication commitments is described. In this embodiment the commitment for argument <i>T</i> may only be opened if that for argument <i>S</i> was. One way to obtain this is by having the opening of argument <i>S</i> be inferred from that of argument <i>T. G, p, o, g, h</i> are set up similarly. This establishes the set <i>G.</i> User <i>A</i> sets up <i>d, a, t, t</i>' and communicates (<i>g, t'</i>) openly and communicates <i>a, d</i> securely to user <i>B</i> similarly. This establishes pk = (<i>g, t'</i>) and sk = <i>d,</i> and <i>a</i> as a secret shared by user <i>A</i> and user <i>B.</i> User <i>A</i> produces a commitment to an argument of knowing sk as <i>S</i> similarly, namely by setting up <i>r</i><sub>1</sub>, <i>r</i><sub>2</sub>, <i>v, w</i><sub>1</sub><i>, w</i><sub>2</sub> and posting <i>v, w</i><sub>1</sub><i>, w</i><sub>2</sub> similarly. The commitment is verified and opened similarly.
0203User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces a commitment to an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. User <i>B</i> chooses <i>b, r</i> ∈<i><sub>R</sub></i><maths id="math0342"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0352.tif" /></maths>, sets <i>u</i> := <i>g<sup>b</sup>h<sup>r</sup>, y</i> := <i>g<sup>M</sup>, y</i>' := <i>yh<sup>b</sup></i> and communicates <i>u</i>, <i>y</i>'. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>B</i> communicates (<i>s</i>, <i>w</i>) where <i>s</i> := <i>b</i> + <i>d</i> + <i>cM</i> mod <i>o, w</i> := <i>a</i> + <i>r</i> + <i>cb</i> mod <i>o</i>. The commitment to the argument is verified by checking that <i>g<sup>s</sup>h<sup>w</sup></i> = <i>ut'y'<sup>c</sup>,g<sup>s</sup></i> = <i>u'ty<sup>c'</sup></i> where <i>u</i>' := <i>u</i>/<i>h<sup>r</sup>, y</i> := <i>y'</i>/<i>h<sup>b</sup></i> and may be opened by revealing <i>r</i>, thereby also revealing <i>b</i> as <i>b</i> = (<i>w</i> - <i>a</i> - <i>r</i>)/<i>c</i> mod <i>o</i> once <i>a</i> has been revealed (also for argument <i>S</i>). User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>b - d</i>)/<i>c</i> mod <i>o</i> once <i>b</i> has been revealed. It is verified that <i>S, T</i> are related to the same sk in that the same <i>t</i> is used in their corresponding verifications. In this embodiment, one may view that the opening <i>r<sub>s</sub></i> for argument <i>S</i> is <i>a</i> (resp. and/or <i>r</i><sub>2</sub>) and the opening <i>r<sub>T</sub></i> of argument <i>T</i> is <i>a, b</i> (resp. and/or <i>r</i><sub>2</sub>, <i>r</i>).
0204Example methods for zero-knowledge hashing with communication, applicable, for example, to the above described verifiable previewing system, are described herein. Zero-knowledge hashing may be implemented in cryptographic devices, such as cryptographic processors, for example in systems described herein. For example, the Random Value Generator may be implemented in a trusted computing module, the Committer for Secret Bits and the Committer for Hash Values and the Hasher may be implemented in a cryptographic processor, and the Verifier may be implemented in a processing device attached to a monitoring system. An advantage of using zero-knowledge hashing, as described, is a reduced amount of memory, computational, and communication resources needed as compared to traditional methods that involve complex verifiable computing machinery. In more detail, in various examples, a zero-knowledge argument of knowledge of a pre-image of some collision-free hash functions and its verifiable communication are described. Some zero-knowledge argument systems may employ collision-free hashing as a building block and may use these as building blocks. Hash values for secret bits and random values are computed and made public. An argument is made for commitments to the secret bits and random values. An argument for commitments to the hash values of the secret bits and random values is made.
0205Example methods for zero-knowledge hashing with communication are described. A group <i>G</i> of prime order <i>p</i> of bit length <i>k</i> with a subgroup of prime order <i>o</i> of bit length <i>l</i>, such that <i>o</i>|<i>p</i> - 1, and two random generators <i>g, h</i> of the subgroup, such that DLP is hard for <i>g, h</i> and the discrete logarithm of <i>h</i> to base <i>g</i> is unknown, are set up. This establishes the set <i>G</i>. User <i>A</i> wishing to receive a message from user <i>B</i> first chooses a secret key <maths id="math0343"><math display="inline"><mi>d</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0353.tif" /></maths> and a secret <maths id="math0344"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0354.tif" /></maths>, and constructs a corresponding public key <i>t</i> where <i>t</i> := <i>g<sup>d</sup></i> and a commitment <i>t</i>' to it where <i>t</i>' := <i>th<sup>a</sup>.</i> User <i>A</i> communicates (<i>g, t'</i>) openly and communicates <i>a, d</i> securely to user <i>B</i> using a traditional cryptographic communication system. This establishes pk = (<i>g, t'</i>) as a public key, sk = <i>d</i> as a secret key and <i>a</i> as a secret of the commitment shared by both user <i>A</i> and user <i>B.</i> User <i>A</i> produces a commitment to an argument of knowing sk as <i>S</i>. User <i>A</i> chooses <i>r</i><sub>1</sub>, <maths id="math0345"><math display="inline"><msub><mi>r</mi><mn>2</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0355.tif" /></maths>, sets <i>v</i> := <i>g</i><sup><i>r</i><sub2>1</sub2></sup><i>h</i><sup><i>r</i>2</sup> and posts <i>v.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> sets <i>w</i><sub>1</sub> := <i>r</i><sub>1</sub> + <i>c'd</i> mod <i>o</i>, <i>w</i><sub>2</sub> := <i>r</i><sub>2</sub> + <i>c'a</i> mod <i>o</i> and posts <i>w</i><sub>1</sub><i>,w</i><sub>2</sub><i>.</i> The commitment to the argument is verified by checking that <i>g</i><sup><i>w</i>1</sup><i>h</i><sup><i>w</i>2</sup> = <i>vt'<sup>c'</sup>, g</i><sup><i>w</i>1</sup> = <i>v't<sup>c'</sup></i> where <i>v'</i> := <i>v</i>/<i>h</i><sup><i>r</i><sub2>2</sub2></sup> and may be opened by revealing <i>r</i><sub>2</sub>, thereby revealing <i>a</i> as <i>a</i> = (<i>w</i><sub>2</sub> - <i>r</i><sub>2</sub>)/<i>c'</i> mod <i>o</i> and <i>t</i> as <i>t'</i>/<i>h<sup>a</sup>.</i>
0206User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces a commitment to an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. User <i>B</i> chooses <i>b</i>, <maths id="math0346"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0356.tif" /></maths>, sets <i>t</i>" := <i>t, u</i> := <i>g<sup>b</sup>h<sup>r</sup>, y</i> := <i>g<sup>M</sup>, y</i>' := <i>yh<sup>b</sup></i> and communicates <i>t"</i>, <i>u</i>, <i>y</i>'. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>B</i> communicates (<i>s</i>, <i>w</i>) where <i>s</i> := <i>b</i>+<i>d</i>+<i>cM</i> mod <i>o</i>,<i>w</i> := <i>r</i>+<i>cb</i> mod <i>o</i>. The commitment to the argument is verified by checking that <i>g<sup>s</sup>h<sup>w</sup></i> = <i>ut"y'<sup>c</sup>, g<sup>s</sup></i> = <i>u't"y<sup>c'</sup></i> where <i>u'</i> := <i>u</i>/<i>h<sup>r</sup>,y</i> := <i>y'</i>/<i>h<sup>b</sup></i> and may be opened by revealing <i>r,</i> thereby also revealing <i>b</i> as <i>b</i> = (<i>w</i> - <i>r</i>)/<i>c</i> mod <i>o</i>. User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>b</i> - <i>d</i>)/<i>c</i> mod <i>o</i> once <i>b</i> has been revealed. Once the commitments to <i>S, T</i> are opened, one verifies they are related to the same sk by checking that <i>t</i>" = <i>t</i>. In this embodiment, one may view that the opening <i>r<sub>s</sub></i> for argument <i>S</i> is <i>a</i> (resp. and/or <i>r</i><sub>2</sub>) and the opening <i>r<sub>T</sub></i> of argument <i>T</i> is <i>b</i> (resp. and/or r).
0207An example method for verifiable communication of a pre-image of a hash value of such a function is described as follows. Bob chooses <maths id="math0347"><math display="inline"><mi>u</mi><mo>∈</mo><msub><mi>ℤ</mi><mi>q</mi></msub></math><img file="EP4040713A1_D0357.tif" /></maths>, sets <i>v</i> := <i>g<sup>u</sup></i>, and posts <i>v.</i> Bob makes an argument <i>S</i> of knowledge of <i>u</i> for <i>v</i> using a well-known method. Bob communicates <i>u</i> securely to Alice using a traditional cryptographic communication system. This establishes sk = <i>u</i> and pk = <i>v</i>. Alice wishing to verifiably communicate the hash value <i>w</i> to Bob first invokes a method for making a zero-knowledge argument of knowledge of the hash value like the one just described. Now, Alice makes an argument <i>T</i> that knowledge of sk implies knowledge of the DL to base <i>g'</i> of <i>e<sub>j</sub></i> or <i>e<sub>j</sub></i>/<i>g.</i> This may be done for example using verifiable partial communication, e.g as applied to a Schnorr based method. This argument implies Bob knows <i>t<sub>j</sub></i> and hence also <i>s<sub>j</sub></i>, as Bob recovers <i>s<sub>j</sub></i> as 0 (resp. 1) when he knows the DL to base <i>g'</i> of <i>e<sub>j</sub></i> (resp. <i>e<sub>j</sub></i>/<i>g</i>).
0208The described zero-knowledge hashing with communication methods may be generalized to handle a secret <i>s</i> := (<i>s</i><sub>1</sub>, <i>s</i><sub>2</sub>,...,<i>s<sub>m</sub></i>) ∈ {0, 1,...,<i>k</i> - 1}<i><sup>m</sup></i> with <i>k</i> > 2 by using range commitments for {<i>s<sub>j</sub></i>} or log<sub>2</sub><i>k</i>-bits commitments when <i>k</i> is a whole power of 2. They may be further generalized to handle a secret <maths id="math0348"><math display="inline"><mi>s</mi><mo>:</mo><mo>=</mo><mfenced><msub><mi>s</mi><mn>1</mn></msub><mo>,</mo><msub><mi>s</mi><mn>2</mn></msub><mo>,</mo><mo>…</mo><mo>,</mo><msub><mi>s</mi><mi>m</mi></msub></mfenced><mo>∈</mo><msubsup><mo>×</mo><mrow><mi>j</mi><mo>=</mo><mn>1</mn></mrow><mi>m</mi></msubsup><mfenced open="{" close="}"><mn>0,1</mn><mo>,</mo><mo>…</mo><mo>,</mo><msub><mi>k</mi><mi>j</mi></msub><mo>−</mo><mn>1</mn></mfenced></math><img file="EP4040713A1_D0358.tif" /></maths> with <i>k<sub>j</sub></i> ≥ 2 by using bit-, multiple-bits-, or range- commitments fitting the domains of {<i>s<sub>j</sub></i>}, or to shifted domains for {<i>s<sub>j</sub></i>} by using corresponding shifted commitments, or to set domains for {<i>s<sub>j</sub></i>} by using set-membership commitments. They may be implemented using parallelized or distributed computation, e.g. along the <i>i</i> or <i>j</i> indices, and their performance may be improved by computing multiple group-exponentiations concurrently, e.g. by combining pre-computed group-exponentiations to powers of 2 into each desired group-exponentiation.
0209Embodiments may involve commitments to multiple communications. Example methods for making a commitment to multiple communications are described. Once a commitment to multiple communications is made it may be opened so that all the communications are performed together, as will be elaborated on later. A commitment to multiple communications may be used with the above described system for verifiable previewing. For example, by applying the commitment to the verifiable communication of selected parts, the opening of the commitment performs the communication of all selected parts together. Thus, a large amount of information may be revealed to recipients upon a much smaller communication of an opening. This enables reducing the observed latency of, and the effort involved in, completing the delivery of multiple communications. In some implementations, a large commitment to multiple communications may be set up by advanced communication systems, incorporating devices for the Arguer <i>S</i> and Committer for <i>T</i> components, situated around the world, while the opening may be affected by a much simpler device, such as a handheld terminal or a smartwatch incorporating a Commitment Opener, requiring relatively little resources for the opening.
0210Commitment to multiple communications involves a single commitment <i>x</i> made for verifiable communication of multiple messages {<i>M<sub>i</sub></i>}, each to a secret key sk<i><sub>i</sub></i>, for <i>i</i> ∈ [<i>k</i>], where <i>k</i> is the number of communications involved. An argument <i>S</i> is made for knowledge of sk<i><sub>i</sub></i> while a commitment with a common opening <i>x</i> is made for verifiable communication of <i>M<sub>i</sub>,</i> for <i>i</i> ∈ [<i>k</i>]. The opening of the commitment lets a verifier simultaneously verify communication of each message.
0211Example methods for committing to multiple verifiable communications, possibly with different sending and/or receiving parties, are described. A group <i>G,</i> with a generator <i>g</i> of large prime order <i>o</i> of bit length <i>l</i>, is set up such that DLP is hard in <i>G.</i> This establishes the set <i>G.</i> Let <i>k</i> ∈ <img file="EP4040713A1_D0359.tif" /> where <i>k</i> ≪ <i>o</i>, and let <i>i</i> range over [<i>k</i>]. Let <i>h</i> be a generator of a group <i>H</i> of order <i>o</i> such that DLP is hard in <i>H.</i> The notations <i>m</i> + <i>h</i> mod <i>o, m</i> - <i>h</i> mod <i>o, mh</i> mod <i>o, m</i>/<i>h</i> mod <i>o</i> and <i>g<sup>h</sup>,</i> for a message <i>m</i> and <i>h</i> ∈ <i>H</i>, refer to a representation of <i>m</i> in <maths id="math0349"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0360.tif" /></maths> and to a representation (or cryptogrphic hash) of <i>h</i> in <maths id="math0350"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0361.tif" /></maths>. User <i>A<sub>i</sub></i> and user <i>B<sub>i</sub></i> may be different for each <i>i</i> which corresponds to one verifiable communication. User <i>C</i> is to open a commitment to these multiple verifiable communications, as described below.
0212User <i>C</i> chooses a key <i>x</i> ∈<i><sub>R</sub> H.</i> User C computes <i>w</i> := <i>h<sup>x</sup></i> and posts <i>w</i>, thus committing to <i>x.</i> User <i>A<sub>i</sub></i> chooses secret <maths id="math0351"><math display="inline"><msub><mi>r</mi><mi>i</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0362.tif" /></maths>. User <i>A<sub>i</sub></i> computes <i>t<sub>i</sub></i> := <i>g<sup>r<sub2>i</sub2></sup></i> and posts <i>t<sub>i</sub></i>. This establishes sk<i><sub>i</sub></i> = <i>r<sub>i</sub></i> and pk<i><sub>i</sub></i> = <i>t<sub>i</sub></i>. User <i>A<sub>i</sub></i> produces an argument <i>S</i> of knowing sk<i><sub>i</sub></i>, i.e. knowing <i>r<sub>i</sub></i> for <i>t<sub>i</sub></i>, using a known verifiable communication method. User <i>A<sub>i</sub></i> communicates <i>r<sub>i</sub></i> securely to user <i>B<sub>i</sub></i> using a traditional cryptographic communication system. User <i>B<sub>i</sub></i> wishing to commit (on key <i>x</i>) to communicate message <i>M<sub>i</sub></i> to user <i>A<sub>i</sub></i> produces a commitment to an argument <i>T</i> whereby knowing sk<i><sub>i</sub></i> implies knowing <i>M<sub>i</sub></i> as follows. User <i>B<sub>i</sub></i> computes <i>y<sub>i</sub></i> := <i>g<sup>M<sub2>i</sub2></sup></i> and posts <i>y<sub>i</sub></i>. Given a challenge <i>c<sub>i</sub></i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>B<sub>i</sub></i> chooses <maths id="math0352"><math display="inline"><msub><mi>b</mi><mi>i</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0363.tif" /></maths>, sets <i>s<sub>i</sub></i> := <i>r<sub>i</sub></i> + <i>c<sub>i</sub>M<sub>i</sub></i> mod <i>o</i>, <i>v<sub>i</sub></i> := <i>h<sup>b<sub2>i</sub2></sup>, u<sub>i</sub></i> := <i>s<sub>i</sub></i> + <i>w<sup>b<sub2>i</sub2></sup></i> mod <i>o</i>, and posts <i>v<sub>i</sub></i>, <i>u<sub>i</sub>.</i> The pair <i>v<sub>i</sub>, u<sub>i</sub></i> constitutes a variant of ElGamal encryption of <i>s<sub>i</sub></i> using key <i>x.</i> Optionally, user <i>B<sub>i</sub></i> may compute <i>z<sub>i</sub></i> := <i>g<sup>w<sub2>b</sub2>i</sup></i> and post <i>z<sub>i</sub></i>, allowing a verifier to check that <maths id="math0353"><math display="inline"><msup><mi>g</mi><msub><mi>u</mi><mi>i</mi></msub></msup><mo>=</mo><msub><mi>z</mi><mi>i</mi></msub><msub><mi>t</mi><mi>i</mi></msub><msubsup><mi>y</mi><mi>i</mi><msub><mi>c</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0364.tif" /></maths>. User <i>C</i> opens the commitment by revealing <i>x</i>', where <i>x</i>' := <i>x</i>, thereby revealing <maths id="math0354"><math display="inline"><msubsup><mi>s</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0365.tif" /></maths> as <maths id="math0355"><math display="inline"><msub><mi>u</mi><mi>i</mi></msub><mo>−</mo><msubsup><mi>ν</mi><mi>i</mi><mrow><mi>x</mi><mo>′</mo></mrow></msubsup></math><img file="EP4040713A1_D0366.tif" /></maths> mod <i>o</i>. The opening is verified by checking that <i>w</i> = <i>h<sup>x'</sup>,</i> and the communications are verified by checking that <maths id="math0356"><math display="inline"><msup><mi>g</mi><msubsup><mi>s</mi><mi>i</mi><mo>′</mo></msubsup></msup><mo>=</mo><msub><mi>t</mi><mi>i</mi></msub><msubsup><mi>y</mi><mi>i</mi><msub><mi>c</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0367.tif" /></maths> if not already verified via <i>z<sub>i</sub></i> as described above.
0213An example alternative is described. Let <i>E</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub></i> be a pairing, for which <maths id="math0357"><math display="inline"><msub><mo>∀</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0368.tif" /></maths> : <i>E</i>(<i>g<sup>a</sup></i>,<i>g<sup>b</sup></i>) = <i>E</i>(<i>g</i>,<i>g</i>)<i><sup>ab</sup></i> and <i>E</i>(<i>g, g</i>) generates <i>G<sub>T</sub>,</i> such that DLP is hard in <i>G<sub>T</sub>.</i> Modify the above method as follows: in place of <i>u<sub>i</sub></i> := <i>s<sub>i</sub></i> + <i>w<sup>b<sub2>i</sub2></sup></i> mod <i>o</i> use <i>u<sub>i</sub></i> := <i>s<sub>i</sub>w<sup>b<sub2>i</sub2></sup></i> mod <i>o</i>, in place of <maths id="math0358"><math display="inline"><msup><mi>g</mi><msub><mi>u</mi><mi>i</mi></msub></msup><mo>=</mo><msub><mi>z</mi><mi>i</mi></msub><msub><mi>t</mi><mi>i</mi></msub><msubsup><mi>y</mi><mi>i</mi><msub><mi>c</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0369.tif" /></maths> use <maths id="math0359"><math display="inline"><mi>E</mi><mfenced><mi>g</mi><msup><mi>g</mi><msub><mi>u</mi><mi>i</mi></msub></msup></mfenced><mo>=</mo><mi>E</mi><mfenced><msub><mi>z</mi><mi>i</mi></msub><mo>,</mo><msub><mi>t</mi><mi>i</mi></msub><msubsup><mi>y</mi><mi>i</mi><msub><mi>c</mi><mi>i</mi></msub></msubsup></mfenced></math><img file="EP4040713A1_D0370.tif" /></maths>, and in place of <maths id="math0360"><math display="inline"><msub><mi>u</mi><mi>i</mi></msub><mo>−</mo><msubsup><mi>ν</mi><mi>i</mi><mrow><mi>x</mi><mo>′</mo></mrow></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0371.tif" /></maths> mod <i>ο</i> use <maths id="math0361"><math display="inline"><msub><mi>u</mi><mi>i</mi></msub><mo>/</mo><msubsup><mi>ν</mi><mi>i</mi><mrow><mi>x</mi><mo>′</mo></mrow></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></math><img file="EP4040713A1_D0372.tif" /></maths>.
0214These methods may be generalized by using different encryption methods in argument <i>T</i> and a corresponding commitment to a key for such an encryption. A commitment to multiple communications may be configured so that its opening would result in openings of other commitments to multiple communications. Some ways to do so include encrypting the other commitment values {<i>x<sub>j</sub></i>} under the same key used for the commitment <i>x</i>, assigning these {<i>x<sub>j</sub></i>} values to some (possibly related) messages {<i>M<sub>j</sub></i>}, and making the opening of <i>x</i> reveal these multiple commitment values.
0215Example methods for communicating messages related in certain ways are described. A group <i>G</i>, with a generator <i>g</i> of large order <i>o</i> of bit length <i>l</i>, is set up along with a pairing <i>E</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub>,</i> for which <maths id="math0362"><math display="inline"><msub><mo>∀</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0373.tif" /></maths> : <i>E</i>(<i>g<sup>a</sup></i>,<i>g<sup>b</sup></i>) = <i>E</i>(<i>g</i>,<i>g</i>)<i><sup>ab</sup></i> and <i>E</i>(<i>g</i>, <i>g</i>) generates <i>G<sub>T</sub>,</i> such that DLP is hard in <i>G,G<sub>T</sub>.</i> This establishes the set <i>G.</i> Let <i>i</i> range over [<i>l</i>], let <i>j</i> range over {0,...,<i>J</i> - 1} where <i>J</i> ∈ <img file="EP4040713A1_D0374.tif" /> , <i>J</i> << <i>o</i>, and let {<i>a<sub>j</sub></i>} be distinct where <maths id="math0363"><math display="inline"><msub><mi>a</mi><mi>j</mi></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0375.tif" /></maths>. A binary operator ⊕ is defined with a group structure on <maths id="math0364"><math display="inline"><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0376.tif" /></maths>, with the inverse element of <i>w</i> denoted by -<i>w</i>, along with a set of functions <i>z<sub>j</sub></i>(<i>w</i>) such that ∀<i>w</i>,<i>w'</i> : <i>z<sub>j</sub></i>(<i>w</i> ⊕ <i>w'</i>) = <i>z<sub>j</sub></i>(<i>w</i>)<i>z<sub>j</sub></i>(<i>w'</i>). In a first example construction, let <i>a<sub>j</sub></i> > 1, <i>w</i><sub>1</sub> ⊕ <i>w</i><sub>2</sub> := <i>w</i><sub>1</sub> + <i>w</i><sub>2</sub> mod <i>o</i>, <maths id="math0365"><math display="inline"><msub><mi>z</mi><mi>j</mi></msub><mfenced><mi>w</mi></mfenced><mo>:</mo><mo>=</mo><msubsup><mi>a</mi><mi>j</mi><mi>w</mi></msubsup><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi><mo>,</mo></math><img file="EP4040713A1_D0377.tif" /></maths>, and the double-DL problem is hard in <i>G.</i> In a second example construction, let <i>a<sub>j</sub></i> > 0, e.g. <i>a<sub>j</sub></i> = <i>j</i> + 1 or <i>a<sub>j</sub></i> := <i>e<sup>j</sup></i> mod <i>o</i> for <maths id="math0366"><math display="inline"><mi>e</mi><mo>∈</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0378.tif" /></maths>, e > 1, let <i>w</i><sub>1</sub> ⊕ <i>w</i><sub>2</sub> := <i>w</i><sub>1</sub><i>w</i><sub>2</sub> mod <i>o, z<sub>j</sub></i>(<i>w</i>) := <i>w<sup>a<sub2>j</sub2></sup></i> mod <i>o</i>, and the <i>e</i>th-root of DL problem is hard in G.
0216User <i>A</i> chooses secrets <i>x</i>, <maths id="math0367"><math display="inline"><msub><mi>x</mi><mi>j</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0379.tif" /></maths>, sets <i>s<sub>j</sub></i> := <i>g<sup>x<sub2>j</sub2></sup></i>, <i>v<sub>j</sub></i> := <i>g</i><sup><i>x<sub>j</sub>z<sub>j</sub></i>(<i>x</i>)</sup>, and posts <i>s<sub>j</sub>, v<sub>j</sub>.</i> In one example alternative, user A may be constrained to choose all <i>x<sub>j</sub></i> to be the same, in which case only one <i>s<sub>j</sub></i> value is posted. In another example alternative, user <i>A</i> may be constrained to choose all <i>x<sub>j</sub></i> as 1, in which case no <i>s<sub>j</sub></i> value is posted. The unconstrained case generalizing these cases is described here. This establishes sk = {<i>x, x<sub>j</sub></i>}, pk = {<i>s<sub>j</sub>, v<sub>j</sub></i>}. User <i>A</i> communicates <i>x</i> to user <i>B</i> securely using a traditional cryptographic communication system. User <i>A</i> produces an argument <i>S</i> of knowing sk as follows. User <i>A</i> chooses secrets <maths id="math0368"><math display="inline"><msub><mi>r</mi><mi>i</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0380.tif" /></maths>, sets <i>u</i><sub><i>i</i>,<i>j</i></sub> := <i>g</i><sup><i>z<sub>j</sub></i>(<i>r<sub>i</sub></i>)</sup>, and posts <i>u</i><sub><i>i</i>,<i>j</i></sub>. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> posts <i>t<sub>i</sub></i> where <i>t<sub>i</sub></i> := <i>r<sub>i</sub></i> if <i>c</i>[<i>i</i>] = 0 or <i>t<sub>i</sub></i> := <i>r<sub>i</sub></i> ⊕ <i>x</i> mod <i>o</i> if <i>c</i>[<i>i</i>] = 1. The argument is verified by checking that <i>u</i><sub><i>i</i>,<i>j</i></sub> = <i>g</i><sup><i>z<sub>j</sub></i>(<i>t<sub>i</sub></i>)</sup> if <i>c</i>[<i>i</i>] = 0 or <i>E</i>(<i>u</i><sub><i>i</i>,<i>j</i></sub>, <i>v<sub>j</sub></i>) = <i>E</i>(<i>s<sub>j</sub></i>, <i>g</i><sup><i>zj</i>(<i>t<sub>i</sub></i>)</sup>) if <i>c</i>[<i>i</i>] = 1. A simulator given <i>w<sub>j</sub>,</i> possibly with <i>w<sub>j</sub></i> = <i>z<sub>j</sub></i>(<i>x</i>) for unknown <i>x</i>, may choose <i>c</i> and set <i>v<sub>j</sub></i> := <i>g<sup>x<sub2>j</sub2>w<sub2>j</sub2></sup></i>, <i>t<sub>i</sub></i> := <i>r<sub>i</sub></i>, and <i>u</i><sub><i>i</i>,<i>j</i></sub> := <i>g</i><sup><i>z<sub>j</sub></i>(<i>r<sub>i</sub></i>)</sup> if <i>c</i>[<i>i</i>] = 0 or <maths id="math0369"><math display="inline"><msub><mi>u</mi><mrow><mi>i</mi><mo>,</mo><mi>j</mi></mrow></msub><mo>:</mo><mo>=</mo><msup><mi>g</mi><msubsup><mi>w</mi><mi>j</mi><mo>′</mo></msubsup></msup></math><img file="EP4040713A1_D0381.tif" /></maths> where <maths id="math0370"><math display="inline"><msubsup><mi>w</mi><mi>j</mi><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><msub><mi>z</mi><mi>j</mi></msub><mfenced><msub><mi>r</mi><mi>i</mi></msub></mfenced><mo>/</mo><msub><mi>w</mi><mi>j</mi></msub></math><img file="EP4040713A1_D0382.tif" /></maths> mod <i>o</i> if <i>c</i>[<i>i</i>] = 1 to pass verification. When 1/<i>w<sub>j</sub></i> mod <i>o</i> is not unique, any reciprocal may be used.
0217User <i>B</i> wishing to communicate messages {<i>z<sub>j</sub></i>(<i>M</i>)} to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing {<i>z<sub>j</sub></i>(<i>M</i>)} as follows. User <i>B</i> first posts <i>y<sub>j</sub></i>, where <i>y<sub>j</sub></i> := <i>g</i><sup><i>z<sub>j</sub></i>(<i>M</i>)</sup>. User <i>B</i> proves knowledge of <i>M</i> for <i>y<sub>j</sub></i>, e.g. using the just said method for argument <i>S</i>. User <i>B</i> posts s where <i>s</i> := <i>x</i> ⊕ <i>M</i> mod <i>o</i>. The argument is verified by checking that <i>E</i>(<i>v<sub>j</sub></i>, <i>y<sub>j</sub></i>) <i>= E</i>(<i>s<sub>j</sub></i>, <i>g</i><sup><i>z<sub>j</sub></i>(<i>s</i>)</sup>). User <i>A</i> recovers <i>M</i> as <i>s</i>⊕ -<i>x</i> mod <i>o</i> and {<i>z<sub>j</sub></i>(<i>M</i>)} from it. A simulator given <i>m<sub>j</sub></i>, possibly with <i>m<sub>j</sub></i> = <i>z<sub>j</sub></i>(<i>M</i>) for unknown <i>M</i>, may choose <i>s</i> and set <i>y<sub>j</sub></i> := <i>g<sup>m<sub2>j</sub2></sup>, v<sub>j</sub></i> := <i>g<sup>x<sub2>j</sub2>w<sub2>j</sub2></sup></i> with <i>w<sub>j</sub></i> := <i>z<sub>j</sub></i>(<i>s</i>)/<i>m<sub>j</sub></i> mod <i>o</i>, where <i>w<sub>j</sub></i> may be given to the above simulator, to pass verification.
0218Example embodiments involving techniques for verifiable oblivious communication are described. These techniques enable a wider range of systems for verifiable previewing, digital goods and information compensation. As elaborated on below, verifiable oblivious communications may be used to implement a complex computation of an encyphered preview from a digital good while enabling verification and recovery. This preview computation may be used in verifiable previewing instead of the preview process for obtaining a selection of parts. An verifiable oblivious communication results in the verifiable communication of a message in a way that is only partially controlled by the sending party. Methods for verifiable oblivious communication are described below in general and later in specific embodiments for certain cryptosystems.
0219Example methods for verifiable oblivious communication described below may be used for communicating 1-out-of-2 messages given to the sending party. This is analogous to 1-out-of-2 oblivious transfer, where Alice chooses two messages and Bob gets to choose which one to receive yet Bob does not receive the other message and Alice does not learn which one of the messages Bob received. However, in verifiable oblivious communication the same message chosen by Bob is also communicated to Charlie, and this may be verified without learning which of the two messages was communicated. Hence, verifiable oblivious communication may be viewed as an enhancement of oblivious transfer, inheriting many of its properties. The methods may be generalized to k-out-of-n verifiable oblivious communication by generalizing 1-out-of-2 oblivious transfer to k-out-of-n oblivious transfer and utilizing said analogy. The methods may also be generalized by extending verifiable oblivious communication, i.e. implementing a large number of verifiable oblivious communications using a small number of verifiable oblivious communications, by extending oblivious transfer and utilizing said analogy. The methods may be further generalized to secure-multiparty-computation, where information learned by a party for any computation step may be verifiably communicated to another party, by basing secure-multiparty-computation on 1 out-of-2 oblivious transfer and utilizing said analogy. 1-out-of-2 oblivious transfer is a complete primitive for secure-multiparty-computation. Similarly, 1-out-of-2 verifiable oblivious communication is a complete primitive for verifiable communication of secure-multiparty-computation.
0220Techniques for verifiable oblivious communication may be implemented in cryptographic devices, such as trusted computing modules, for example in systems as described herein. An advantage of using verifiable oblivious communication in such systems is the reduced computational and communication resources needed for delivering results of a complex computation from one device to multiple other devices concurrently compared to those that would be required by serial repetition.
0221Verifiable oblivious communication embodiments are described with respect to <figref idref="f0020">FIG. 18</figref> in comparison to <figref idref="f0001">FIG. 1A</figref>. The manifest generator 1810, which corresponds to the manifest generator 140, is used to produce a manifest. The manifest driver 1840, which corresponds to the manifest driver 160, is used to drive the production of the manifest. The manifest verifier 1820, which corresponds to the manifest verifier 180, is used to verify the manifest. The oblivious shared channel 1830 provides access to the manifest while enabling the verification of the oblivious communication.
0222A first example method for 1-out-of-2 verifiable oblivious communication for Paillier cryptosystem is described. The method may be viewed as involving a 1-out-of-2 oblivious transfer with Paillier cryptosystem and verifiable communication of related messages, described herein. Let <i>p</i>,<i>q</i> be large primes having gcd<i>(pq, (p</i> - <i>1</i>)(<i>q</i> - 1)) = 1, assured when <i>p</i>,<i>q</i> are of equal bit length. Let <i>n := pq</i>, <i>λ</i> := lcm(<i>p</i> - 1, <i>q</i> - 1). Let <i>g'</i> be as <maths id="math0371"><math display="inline"><mi>g</mi><mo>′</mo><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><msup><mi>n</mi><mn>2</mn></msup><mo>*</mo></msubsup></math><img file="EP4040713A1_D0383.tif" /></maths> until <i>µ</i> := (<i>L</i>(<i>g'<sup>λ</sup></i> mod <i>n</i><sup>2</sup>))<sup>-1</sup> mod <i>n</i> exists, where <maths id="math0372"><math display="inline"><mi>L</mi><mfenced><mi>u</mi></mfenced><mo>:</mo><mo>=</mo><mfrac><mrow><mi>u</mi><mo>−</mo><mn>1</mn></mrow><mi>n</mi></mfrac></math><img file="EP4040713A1_D0384.tif" /></maths>.Here, <maths id="math0373"><math display="inline"><mfrac><mi>a</mi><mi>b</mi></mfrac></math><img file="EP4040713A1_D0385.tif" /></maths> is the quotient, i.e. <maths id="math0374"><math display="inline"><msub><mi>max</mi><mrow><mi>ν</mi><mo>∈</mo><mi>ℕ</mi></mrow></msub><mi>a</mi><mo>≥</mo><mi mathvariant="italic">νb</mi></math><img file="EP4040713A1_D0386.tif" /></maths><i>.</i> If <i>p</i>, <i>q</i> are of equal bit length, simpler is setting <i>g'</i> := <i>n</i> + 1, <i>λ</i> := <i>φ</i>(<i>n</i>), <i>µ</i> := <i>ϕ</i>(<i>n</i>)<sup>-1</sup> where <i>ϕ</i>(<i>n</i>) <i>:= (p</i> - <i>1</i>)(<i>q</i> - 1). Let <i>n, g'</i> be public and <i>λ</i>, <i>µ</i> be known to Alice. Let <i>g</i> be a generator of an order-<i>n</i><sup>2</sup> group G where the double-DL problem is hard. Let <i>h</i>(·) be a cryptographic hash function.
0223Alice sets up secrets <maths id="math0375"><math display="inline"><msub><mi>m</mi><mi>i</mi></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0387.tif" /></maths> and posts commitments <i>h<sub>i</sub></i> := <i>h</i>(<i>m<sub>i</sub></i>) for them. Alice chooses <maths id="math0376"><math display="inline"><msub><mi>x</mi><mi>i</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0388.tif" /></maths> and posts them. Bob chooses secrets <i>b</i> ∈<i><sub>R</sub></i> {0, 1}, <maths id="math0377"><math display="inline"><mi>k</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0389.tif" /></maths>, <maths id="math0378"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>n</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0390.tif" /></maths> (r may be set to 1). Bob sets <i>v</i> := <i>x<sub>b</sub></i> + <i>g'<sup>k</sup>r<sup>n</sup></i> mod <i>n</i><sup>2</sup> and posts <i>v.</i> The term <i>g'<sup>k</sup>r<sup>n</sup></i> mod <i>n</i><sup>2</sup> of <i>v</i> constitutes a Paillier encryption of <i>k.</i> Bob makes an argument of knowledge of double-DL to bases <i>g'</i>, <i>g</i> for (<i>v</i> - <i>x</i><sub>0</sub>)/<i>r<sup>n</sup></i> or (<i>v</i> - <i>x</i><sub>1</sub>)/<i>r<sup>n</sup></i>, e.g. using a first construction of verifiable communication of related messages, where J := 1 and <i>a</i><sub>0</sub> := <i>g'</i>, and where <i>x<sub>j</sub></i> are constrained to be the same value <i>r<sup>n</sup></i>, as follows. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], Bob chooses <maths id="math0379"><math display="inline"><mi>z</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0391.tif" /></maths> and sets <i>c</i><sub>1-<i>b</i></sub> := <i>z</i>, <i>c<sub>b</sub></i> := <i>c</i> ⊕ <i>c</i><sub>1-<i>b</i></sub>. Not knowing any <i>of p, q</i>, <i>λ</i>, <i>µ</i>, Bob cannot find <i>k'</i> such that <i>v</i> = <i>x</i><sub>1-<i>b</i></sub> + <i>g'<sup>k</sup>r<sup>n</sup></i> mod <i>n</i><sup>2</sup>, solved by <i>k'</i> = <i>L</i>((<i>v - x</i><sub>1-<i>b</i></sub>)<i><sup>λ</sup></i> mod <i>n</i><sup>2</sup>)<i>µ</i> mod <i>n.</i> Bob verifiably communicates to Charlie <i>k</i> in <i>v</i> - <i>x<sub>b</sub></i> using a challenge <i>c<sub>b</sub></i> and simulates verifiable communication to Charlie of <i>k'</i> in <i>v</i> - <i>x</i><sub>1-<i>b</i></sub> using a simulated challenge <i>c</i><sub>1-<i>b</i></sub>. With this, as described herein, one can verify that Bob and Charlie know the same <i>k</i>, <i>b</i> which remain unknown to Alice. Alice computes <i>k<sub>i</sub></i> := <i>L</i>((<i>v</i> - <i>x<sub>i</sub></i>)<i><sup>λ</sup></i> mod <i>n</i><sup>2</sup>)<i>µ</i> mod <i>n</i>, sets <maths id="math0380"><math display="inline"><msubsup><mi>m</mi><mi>i</mi><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><msub><mi>m</mi><mi>i</mi></msub><mo>+</mo><msub><mi>k</mi><mi>i</mi></msub></math><img file="EP4040713A1_D0392.tif" /></maths> mod <i>n</i>, and posts <maths id="math0381"><math display="inline"><msubsup><mi>m</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0393.tif" /></maths>. Bob and Charlie recover <i>k<sub>b</sub></i> as <i>k</i> and <i>m<sub>b</sub></i> as <maths id="math0382"><math display="inline"><msubsup><mi>m</mi><mi>b</mi><mo>′</mo></msubsup><mo>−</mo><msub><mi>k</mi><mi>b</mi></msub></math><img file="EP4040713A1_D0394.tif" /></maths> mod <i>n</i>, and verify that <i>h</i>(<i>m<sub>b</sub></i>) = <i>h<sub>b</sub>.</i> If this verification passes, Bob and/or Charlie post a message (e.g. "OK") indicating acceptance; otherwise, Bob and/or Charlie post <i>k</i>, <i>r</i> to allow a verifier to find <i>b</i> ∈ {0, 1} such that <i>v</i> = <i>x<sub>b</sub></i> + <i>g'<sup>k</sup>r<sup>n</sup></i> mod <i>n</i><sup>2</sup>, recover <i>k<sub>b</sub></i> and <i>m<sub>b</sub></i> similarly, and see that <i>h</i>(<i>m<sub>b</sub></i>) ≠ <i>h<sub>b</sub>.</i> This method may be generalized to use other encryption methods based on hardness of a DLP.
0224A second example method for 1-out-of-2 verifiable oblivious communication for RSA cryptosystem is described. The method may be viewed as involving a 1-out-of-2 oblivious transfer with RSA cryptosystem and verifiable communication of related messages, described herein. Let <i>g</i> be a generator of a group G of order <i>n</i> such that DLP is hard in G and <i>n</i> := <i>pq</i>, <i>o := (p</i> - <i>1</i>)(<i>q</i> - 1) for <i>p</i>, <i>q</i> large safe primes of similar bit length. Let <i>d</i>, <i>e</i> be a RSA key pair with <i>d</i> verifiably known to Alice and let e, <i>n</i>, <i>g, G</i> be public. Let <i>i</i> range over {0, 1}. Let <i>h</i>(·) be a cryptographic hash function.
0225Alice sets up secrets <maths id="math0383"><math display="inline"><msub><mi>m</mi><mi>i</mi></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0395.tif" /></maths> and posts commitments <i>h<sub>i</sub></i> := <i>h</i>(<i>m<sub>i</sub></i>) for them. Alice chooses <maths id="math0384"><math display="inline"><msub><mi>x</mi><mi>i</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0396.tif" /></maths> and posts them. Bob chooses secrets <i>b</i> ∈<i><sub>R</sub></i> {0, 1}, <maths id="math0385"><math display="inline"><mi>k</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0397.tif" /></maths><i>.</i> Bob computes <i>v</i> := <i>x<sub>b</sub></i> + <i>k<sup>e</sup></i> mod <i>n</i> and posts <i>v.</i> The term <i>k<sup>e</sup></i> mod <i>n</i> appearing in <i>υ</i> constitutes an RSA encryption of <i>k.</i> Bob makes an argument of knowledge of eth-root of DL to base <i>g</i>, e.g. using a second construction of verifiable communication of related messages, where J := 1 and <i>a</i><sub>0</sub> := e, and where <i>x<sub>j</sub></i> is constrained to be 1, as follows. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], Bob chooses <maths id="math0386"><math display="inline"><mi>z</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0398.tif" /></maths> and sets <i>c</i><sub>1-<i>b</i></sub> := <i>z</i>, <i>c<sub>b</sub></i> := <i>c</i> ⊕ <i>c</i><sub>1-<i>b</i></sub>. Not knowing any <i>of p, q</i>, <i>d, o,</i> Bob cannot find <i>k'</i> such that <i>v</i> = <i>x</i><sub>1<i>-b</i></sub> + <i>k'<sup>e</sup></i> mod <i>n</i>, solved by <i>k'</i> = (<i>v</i> - <i>x</i><sub>1-<i>b</i></sub>)<i><sup>d</sup></i> mod <i>n.</i> Bob verifiably communicates to Charlie <i>k</i> in <i>v</i> - <i>x<sub>b</sub></i> using a challenge <i>c<sub>b</sub></i> and simulates verifiable communication to Charlie of <i>k'</i> in <i>v</i> - <i>x</i><sub>1-<i>b</i></sub> using a simulated challenge <i>c</i><sub>1-<i>b</i></sub>. With this, as discussed herein, one may verify that Bob and Charlie know the same <i>k</i>, <i>b</i> which remain unknown to Alice. Alice computes <i>k<sub>i</sub></i> := (<i>v</i> - <i>x<sub>i</sub></i>)<i><sup>d</sup></i> mod <i>n</i>, sets <maths id="math0387"><math display="inline"><msubsup><mi>m</mi><mi>i</mi><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><msub><mi>m</mi><mi>i</mi></msub><mo>+</mo><msub><mi>k</mi><mi>i</mi></msub></math><img file="EP4040713A1_D0399.tif" /></maths> mod <i>n</i>, and posts <maths id="math0388"><math display="inline"><msubsup><mi>m</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0400.tif" /></maths>. Bob and Charlie recover <i>k<sub>b</sub></i> as <i>k</i> and <i>m<sub>b</sub></i> as <maths id="math0389"><math display="inline"><msubsup><mi>m</mi><mi>b</mi><mo>′</mo></msubsup><mo>−</mo><msub><mi>k</mi><mi>b</mi></msub></math><img file="EP4040713A1_D0401.tif" /></maths> mod <i>n</i>, and verify that <i>h</i>(<i>m<sub>b</sub></i>) = <i>h<sub>b</sub>.</i> If this verification passes, Bob and/or Charlie post a message (e.g. "OK") indicating acceptance; otherwise, Bob and/or Charlie post <i>k</i> to allow a verifier to find <i>b</i> ∈ {0, 1} such that <i>υ</i> = <i>x<sub>b</sub></i> + <i>k<sup>e</sup></i> mod <i>n</i>, recover <i>k<sub>b</sub></i> and <i>m<sub>b</sub></i> similarly, and see that <i>h</i>(<i>m<sub>b</sub></i>) ≠ <i>h<sub>b</sub>.</i> This method may be generalized to use other encryption methods based on hardness of an eth-root problem.
0226Arguments of partial knowledge may be used in verifiable communication methods to obtain verifiable partial communication. <figref idref="f0017">FIG. 15</figref> is a schematic diagram illustrating the use of verifiable partial communication in the system of <figref idref="f0001">FIG. 1A</figref>. The key argument 1510 and the key argument 1520 are combined using a logical disjunction operation, as will be described, to obtain the partial key argument 1550. Then, the key-message argument 1530 and the key-message argument 1540 are combined using a logical disjunction operation, as will be described, to obtain the partial key-message argument 1560. Finally, the partial key argument 1550 and the key-message argument 1560 are combined to obtain the partial message argument 1570. Thus, there is only partial knowledge with respect to the communication.
0227Example methods for verifiable partial communication are described. Arguments of partial knowledge may be used to convince that an unspecified part of a specified knowledge set (i.e. along with any deducible knowledge) is known, e.g. one-out-of-two pieces of knowledge. An argument may be constructed using a sigma-protocol for each piece of knowledge along with an argument that (only) some of the challenges are fake, i.e. chosen by the arguer rather than unpredictable to it. In verifiable partial communication, one may convince that an unspecified part of a specified message set has been communicated, e.g. one-out-of-two messages. One may generalize from one-out-of-two messages to k-out-of-n messages using standard techniques, such as combining multiple one-out-of-two constructions. In the example of <figref idref="f0017">FIG. 15</figref>, <i>S</i>[<i>x</i>] stands for an argument of knowledge <i>of x,</i> and <i>T</i>[<i>x</i>, <i>y</i>] stands for an argument whereby knowledge of <i>x</i> implies knowledge of <i>y</i>, and V stands for logical disjunction. Well-known arguments of partial knowledge involving logical disjunction, conjunction and negation (yielding non-monotone formulae) may be used to obtain methods of verifiable partial communication with these logical operations in a similar way.
0228Further, examples embodiments of verifiable partial communication may be constructed by combining arguments of partial knowledge and verifiable communication. In these embodiments, argument <i>S</i> is an argument of partial knowledge of sk and argument <i>T</i> is an argument that partial knowledge of sk implies partial knowledge of M. The embodiments use one-of-two arguments of partial knowledge and may be generalized by similarly using <i>k</i>-of-<i>n</i> arguments of partial knowledge, which are well-known. They use some DLP-based method of verifiable communication and may be generalized by using other DLP-based methods and sigma-protocols for them.
0229A first example of embodiments with verifiable partial communication is described. In this embodiment, user <i>B</i> verifiably partially communicates one-of-two messages in its control to user <i>A</i> using one-of-two arguments of partial knowledge. A group G, with generator <i>g</i> of prime order <i>o</i> of bit length <i>l</i>, where DLP is hard, is set up. This establishes the set G. A random element <i>z</i> ∈<i><sub>R</sub> G,</i> whose discrete logarithm to base <i>g</i> is not known to communicating and observing parties, is also set up. Here <i>a</i> is used as an index running over {0, 1}.
0230User <i>A</i> wishing to receive a message from user <i>B</i> first chooses a secret key <maths id="math0390"><math display="inline"><mi>d</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0402.tif" /></maths> with a corresponding public key <i>t</i><sub>1</sub> := <i>g<sup>d</sup></i>, and values <maths id="math0391"><math display="inline"><msub><mi>w</mi><mn>0</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><msubsup><mrow><mspace width="1ex" /><mi mathvariant="normal">Z</mi></mrow><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0403.tif" /></maths>, <maths id="math0392"><math display="inline"><msubsup><mi>c</mi><mn>0</mn><mo>′</mo></msubsup><mo>∈</mo><mi>C</mi><mfenced open="[" close="]"><mi>l</mi></mfenced></math><img file="EP4040713A1_D0404.tif" /></maths>, <i>i</i> ∈<i><sub>R</sub></i> {0, 1}. User <i>A</i> sets <i>t</i><sub>0</sub> := <i>z</i>/<i>g<sup>d</sup></i>, <maths id="math0393"><math display="inline"><msub><mi>ν</mi><mn>0</mn></msub><mo>:</mo><mo>=</mo><msup><mi>g</mi><msub><mi>w</mi><mn>0</mn></msub></msup><mo>/</mo><msubsup><mi>t</mi><mn>0</mn><msubsup><mi>c</mi><mn>0</mn><mo>′</mo></msubsup></msubsup></math><img file="EP4040713A1_D0405.tif" /></maths>, <i>j</i> := 1 - <i>i</i>. User <i>A</i> communicates (<i>g</i>, <i>t<sub>i</sub></i>, <i>t<sub>j</sub></i>) openly and <i>d</i> securely to user <i>B</i> using a traditional cryptographic communication system. This establishes pk = (<i>g</i>, <i>t<sub>i</sub></i>, <i>t<sub>j</sub></i>) as a public key, and sk = <i>d</i> as a secret key shared by both user <i>A</i> and user <i>B.</i> User <i>B</i> can distinguish <i>t</i><sub>1</sub> from <i>t</i><sub>0</sub>, by checking <i>t</i><sub>1</sub> = <i>g<sup>d</sup></i>, and determine <i>i</i>, <i>j</i> while observers not knowing <i>d</i> cannot do so. User <i>A</i> produces an argument of partially knowing sk as <i>S.</i> User <i>A</i> chooses <maths id="math0394"><math display="inline"><msub><mi>r</mi><mn>1</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0406.tif" /></maths> , sets <i>υ<sub>a</sub></i> := <i>g<sup>r<sub2>a</sub2></sup></i>, and communicates (<i>υ<sub>i</sub></i>, <i>υ<sub>j</sub></i>). Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> sets <maths id="math0395"><math display="inline"><msubsup><mi>c</mi><mn>1</mn><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><mi>c</mi><mo>′</mo><mo>⊕</mo><msubsup><mi>c</mi><mn>0</mn><mo>′</mo></msubsup></math><img file="EP4040713A1_D0407.tif" /></maths>, <maths id="math0396"><math display="inline"><msub><mi>w</mi><mi>a</mi></msub><mo>:</mo><mo>=</mo><msub><mi>r</mi><mi>a</mi></msub><mo>+</mo><msubsup><mi>c</mi><mi>a</mi><mo>′</mo></msubsup><mi>d</mi></math><img file="EP4040713A1_D0408.tif" /></maths> mod <i>o</i>, and communicates ( <maths id="math0397"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0409.tif" /></maths>, <maths id="math0398"><math display="inline"><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0410.tif" /></maths>, <i>w<sub>i</sub></i>, <i>w<sub>j</sub></i>). The argument is verified by checking that <maths id="math0399"><math display="inline"><mi>c</mi><mo>′</mo><mo>=</mo><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup><mo>⊕</mo><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0411.tif" /></maths>, <i>t<sub>i</sub>t<sub>j</sub></i> = <i>z</i>, <maths id="math0400"><math display="inline"><msup><mi>g</mi><msub><mi>w</mi><mi>a</mi></msub></msup><mo>=</mo><msub><mi>ν</mi><mi>a</mi></msub><msubsup><mi>t</mi><mi>a</mi><msubsup><mi>c</mi><mi>a</mi><mo>′</mo></msubsup></msubsup></math><img file="EP4040713A1_D0412.tif" /></maths><i>.</i>
0231User <i>B</i> wishing to partially communicate message M to user <i>A</i> produces an argument <i>T</i> whereby partially knowing sk implies partially knowing M as follows. User <i>B</i> chooses <i>c</i><sub>0</sub> ∈<i><sub>R</sub> C</i>[<i>l</i>], <maths id="math0401"><math display="inline"><mi>u</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0413.tif" /></maths>, sets <maths id="math0402"><math display="inline"><msub><mi>y</mi><mn>0</mn></msub><mo>:</mo><mo>=</mo><msup><mi>g</mi><mi>u</mi></msup><msubsup><mi>t</mi><mn>0</mn><mrow><mo>−</mo><mn>1</mn><mo>/</mo><msub><mi>c</mi><mn>0</mn></msub><mspace width="1ex" /><mi>mod</mi><mspace width="1ex" /><mi>o</mi></mrow></msubsup></math><img file="EP4040713A1_D0414.tif" /></maths>, <i>y</i><sub>1</sub> := <i>g<sup>M</sup></i> and communicates (<i>y<sub>i</sub></i>, <i>y<sub>j</sub></i>). Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> sets <i>c</i><sub>1</sub> := <i>c</i> ⊕ <i>c</i><sub>0</sub>, <i>s</i><sub>0</sub> := <i>uc</i><sub>0</sub> mod <i>o</i>, <i>s</i><sub>1</sub> := <i>d</i> + <i>c</i><sub>1</sub><i>M</i> mod <i>o</i> and communicates (<i>c<sub>i</sub></i>, <i>c<sub>j</sub>, s<sub>i</sub></i>, <i>s<sub>j</sub></i>). The argument is verified by checking that <i>c</i> = <i>c<sub>i</sub></i> ⊕ <i>c<sub>j</sub></i>, <maths id="math0403"><math display="inline"><msup><mi>g</mi><msub><mi>s</mi><mi>a</mi></msub></msup><mo>=</mo><msub><mi>t</mi><mi>a</mi></msub><msubsup><mi>y</mi><mi>a</mi><msub><mi>c</mi><mi>a</mi></msub></msubsup></math><img file="EP4040713A1_D0415.tif" /></maths><i>.</i> User <i>A</i> recovers M as (<i>s</i><sub>1</sub> - <i>d</i>)/<i>c</i><sub>1</sub> mod <i>o</i>. Since <i>c<sub>j</sub></i> (resp. <maths id="math0404"><math display="inline"><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0416.tif" /></maths> or <i>t<sub>j</sub></i>) can be determined from <i>c<sub>i</sub></i> (resp. <maths id="math0405"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0417.tif" /></maths> or <i>t<sub>i</sub></i>), one may improve verifiable partial communication protocols such as this one by communicating <i>c<sub>i</sub></i> (resp. <maths id="math0406"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0418.tif" /></maths> or <i>t<sub>i</sub></i>) instead of <i>c<sub>i</sub></i>, <i>c<sub>j</sub></i> (resp. <maths id="math0407"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0419.tif" /></maths>, <maths id="math0408"><math display="inline"><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0420.tif" /></maths> or <i>t<sub>i</sub>, t<sub>j</sub></i>).
0232A second example of embodiments with verifiable partial communication is described. In this embodiment, user <i>B</i> verifiably partially communicates one of two messages, only one of which is under its control, to user <i>A</i> using one-of-two arguments of partial knowledge. A group <i>G</i>, with generator <i>g</i> of prime order <i>o</i> of bit length <i>l</i>, where DLP is hard, is set up. This establishes the set G. An element <i>z</i> ∈ G, whose discrete logarithm to base <i>g</i> is not known to communicating and observing parties and corresponds to an unknown message <maths id="math0409"><math display="inline"><mi>M</mi><mo>′</mo><mo>∈</mo><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0421.tif" /></maths> where <i>g<sup>M'</sup></i> = <i>z</i>, is given to user <i>B.</i> Here <i>a</i> is used as an index running over {0, 1}.
0233User <i>B</i> wishing to partially communicate message <i>M</i> or <i>M'</i> to user <i>A</i> produces an argument <i>T</i> whereby partially knowing sk implies partially knowing M or M' as follows. User <i>B</i> chooses <i>c</i><sub>0</sub> ∈<i><sub>R</sub> C</i>[<i>l</i>], <maths id="math0410"><math display="inline"><msub><mi>s</mi><mn>0</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><msubsup><mrow><mspace width="1ex" /><mi mathvariant="normal">Z</mi></mrow><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0422.tif" /></maths>, sets <i>y</i><sub>0</sub> := <i>z</i>, <i>y</i><sub>1</sub> := <i>g<sup>M</sup></i>, <maths id="math0411"><math display="inline"><msub><mi>t</mi><mn>0</mn></msub><mo>:</mo><mo>=</mo><msup><mi>g</mi><msub><mi>s</mi><mn>0</mn></msub></msup><mo>/</mo><msubsup><mi>y</mi><mn>0</mn><msub><mi>c</mi><mn>0</mn></msub></msubsup></math><img file="EP4040713A1_D0423.tif" /></maths>, and communicates <i>t</i><sub>0</sub> securely to user <i>A</i> using a traditional cryptographic communication system. User <i>A</i> wishing to receive a message from user <i>B</i> first chooses a secret key <maths id="math0412"><math display="inline"><mi>d</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0424.tif" /></maths> with a corresponding public key <i>t</i><sub>1</sub> := <i>g<sup>d</sup></i>, and values <maths id="math0413"><math display="inline"><msub><mi>w</mi><mn>0</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0425.tif" /></maths>, <maths id="math0414"><math display="inline"><msubsup><mi>c</mi><mn>0</mn><mo>′</mo></msubsup><mo>∈</mo><mi>C</mi><mfenced open="[" close="]"><mi>l</mi></mfenced></math><img file="EP4040713A1_D0426.tif" /></maths>, <i>i</i> ∈<i><sub>R</sub></i> {0, 1}. User <i>A</i> sets <i>j</i> := 1 - <i>i</i>, <maths id="math0415"><math display="inline"><msub><mi>ν</mi><mn>0</mn></msub><mo>:</mo><mo>=</mo><msup><mi>g</mi><msub><mi>w</mi><mn>0</mn></msub></msup><mo>/</mo><msubsup><mi>t</mi><mn>0</mn><msubsup><mi>c</mi><mn>0</mn><mo>′</mo></msubsup></msubsup></math><img file="EP4040713A1_D0427.tif" /></maths><i>.</i> User <i>A</i> communicates (<i>g</i>, <i>t<sub>i</sub></i>, <i>t<sub>j</sub></i>) openly and <i>d</i> securely to user <i>B</i> using a traditional cryptographic communication system. This establishes pk = (<i>g</i>, <i>t<sub>i</sub>, t<sub>j</sub></i>) as a public key, and sk = <i>d</i> as a secret key shared by both user <i>A</i> and user <i>B.</i> User <i>B</i> can distinguish <i>t</i><sub>1</sub> from <i>t</i><sub>0</sub>, by checking <i>t</i><sub>1</sub> = <i>g<sup>d</sup></i>, and determine <i>i</i>, <i>j</i> while observers not knowing <i>d</i> cannot do so. User <i>A</i> produces an argument of partially knowing sk as <i>S</i>. User <i>A</i> chooses <maths id="math0416"><math display="inline"><msub><mi>r</mi><mn>1</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0428.tif" /></maths>, sets <i>v</i><sub>1</sub> := <i>g</i><sup><i>r</i><sub2>1</sub2></sup>, and communicates (<i>v<sub>i</sub></i>, <i>v<sub>j</sub></i>). Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> sets <maths id="math0417"><math display="inline"><msubsup><mi>c</mi><mn>1</mn><mo>′</mo></msubsup><mo>:</mo><mo>=</mo><mi>c</mi><mo>′</mo><mo>⊕</mo><msubsup><mi>c</mi><mn>0</mn><mo>′</mo></msubsup></math><img file="EP4040713A1_D0429.tif" /></maths>, <maths id="math0418"><math display="inline"><msub><mi>w</mi><mn>1</mn></msub><mo>:</mo><mo>=</mo><msub><mi>r</mi><mn>1</mn></msub><mo>+</mo><msubsup><mi>c</mi><mn>1</mn><mo>′</mo></msubsup><mi>d</mi></math><img file="EP4040713A1_D0430.tif" /></maths> mod <i>o</i>, and communicates ( <maths id="math0419"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0431.tif" /></maths>, <maths id="math0420"><math display="inline"><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0432.tif" /></maths>, <i>w<sub>t</sub></i>, <i>w<sub>j</sub></i>). The argument is verified by checking that <maths id="math0421"><math display="inline"><mi>c</mi><mo>′</mo><mo>=</mo><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup><mo>⊕</mo><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0433.tif" /></maths>, <maths id="math0422"><math display="inline"><msup><mi>g</mi><msub><mi>w</mi><mi>a</mi></msub></msup><mo>=</mo><msub><mi>ν</mi><mi>a</mi></msub><msubsup><mi>t</mi><mi>a</mi><msubsup><mi>c</mi><mi>a</mi><mo>′</mo></msubsup></msubsup></math><img file="EP4040713A1_D0434.tif" /></maths><i>.</i>
0234User <i>B</i> communicates (<i>y<sub>i</sub></i>, <i>y<sub>j</sub></i>) openly. Given a challenge c ∈ <i>C</i>[<i>l</i>], user <i>B</i> sets <i>c</i><sub>1</sub> := <i>c</i> ⊕ <i>c</i><sub>0</sub>, <i>s</i><sub>1</sub> := <i>d</i> + <i>c</i><sub>1</sub><i>M</i> mod <i>o</i> and communicates (<i>c<sub>i</sub></i>, <i>c<sub>j</sub></i>, <i>s<sub>i</sub></i>, <i>s<sub>j</sub></i>). The argument is verified by checking that <i>c</i> = <i>c<sub>i</sub></i> ⊕ <i>c<sub>j</sub></i>, <maths id="math0423"><math display="inline"><msup><mi>g</mi><msub><mi>s</mi><mi>a</mi></msub></msup><mo>=</mo><msub><mi>t</mi><mi>a</mi></msub><msubsup><mi>y</mi><mi>a</mi><msub><mi>c</mi><mi>a</mi></msub></msubsup></math><img file="EP4040713A1_D0435.tif" /></maths><i>.</i> User <i>A</i> recovers M as (<i>s</i><sub>1</sub> - <i>d</i>)/<i>c</i><sub>1</sub> mod <i>o</i>. Since <i>c<sub>j</sub></i> (resp. <maths id="math0424"><math display="inline"><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0436.tif" /></maths>) can be determined from <i>c<sub>i</sub></i> (resp. <maths id="math0425"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0437.tif" /></maths>), one may improve verifiable partial communication protocols such as this one by communicating <i>c<sub>i</sub></i> (resp. <maths id="math0426"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0438.tif" /></maths>) instead of <i>c<sub>i</sub></i>, <i>c<sub>j</sub></i> (resp. <maths id="math0427"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0439.tif" /></maths>, <maths id="math0428"><math display="inline"><msubsup><mi>c</mi><mi>j</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0440.tif" /></maths>). z may be given by some party and/or an upfront commitment to <i>z</i> may be given to that party, so that the party may verify that <i>z</i> = <i>y</i><sub>0</sub> and/or that the commitment opens to <i>z</i>. Other upfront commitments, such as to <i>c</i><sub>0</sub>, <i>s</i><sub>0</sub> by user <i>B</i>, may also be used.
0235A first example of embodiments with verifiable communication is described. This example embodiment uses a Schnorr-like protocol for constructing <i>T</i> and an ElGamal-signature-like protocol for constructing <i>S</i>. User <i>A</i> wishing to receive a message from user <i>B</i> first constructs a group <i>G</i>, with generator <i>g</i> of prime order <i>o</i> of bit length <i>l</i>, where DLP is hard, a secret key <maths id="math0429"><math display="inline"><mi>d</mi><msub><mo>∈</mo><mi>R</mi></msub><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0441.tif" /></maths>, and a corresponding public key <i>t</i> = <i>g<sup>d</sup>.</i> In other embodiments, <i>G</i> may be well-known or given by others. Both a multiplicative group and an elliptic curve group are applicable here. The multiplicative group modulo <i>p</i> for prime <i>p</i> has a known order <i>o = p</i> - 1. For an elliptic curve group, Schoof showed a polynomial time algorithm, later improved by Elkies and Atkin and analyzed by Dewaghe, for determining the group's order <i>o</i> given its parameters.
0236User <i>A</i> communicates (<i>g</i>, <i>t</i>) openly and communicates <i>d</i> securely to user <i>B</i> using a traditional cryptographic communication system. This establishes pk = (<i>g</i>, <i>t</i>) as a public key, sk = <i>d</i> as a secret key shared by both user <i>A</i> and user <i>B,</i> and the set G. User <i>A</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> as follows. Alternatively, one may produce <i>S</i> based on Schnorr as follows. User <i>A</i> produces an argument of knowing sk as <i>S</i>. User <i>A</i> chooses <maths id="math0430"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0442.tif" /></maths>, sets <i>υ</i> = <i>g<sup>r</sup></i>, and communicates <i>υ.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> communicates <i>w</i> = <i>r</i> + <i>c'd</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>w</sup></i> = <i>vt<sup>c'</sup>.</i> Let <i>H</i>(<i>·</i>) be a cryptographic hash function that is publicly known. User <i>A</i> chooses <maths id="math0431"><math display="inline"><mi>j</mi><mo>′</mo><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0443.tif" /></maths> having gcd(j, o)' = 1, sets <i>r</i> = <i>g<sup>j'</sup></i>, and computes <i>q</i> = (<i>H</i>(<i>Q</i>) - <i>dr</i>)/<i>j'</i> mod <i>o</i>; this step is repeated until <i>q</i> ≠ 0. Herein, when an <i>x</i> ∈ <i>G</i> appears in the exponent, it may be converted to <maths id="math0432"><math display="inline"><mi>x</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0444.tif" /></maths> using a function <maths id="math0433"><math display="inline"><mi>G</mi><mo>→</mo><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0445.tif" /></maths> with unpredictable image. A public cryptographic hash function on a binary form of <i>x</i> may be used.User <i>A</i> communicates <i>r, q</i> openly. The argument is verified by checking that <i>g</i><sup><i>H</i>(<i>Q</i>)</sup> = <i>t<sup>r</sup>r<sup>q</sup>.</i> User <i>B</i> wishing to communicate message M to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y</i> = <i>g<sup>M</sup></i>, <i>s = d</i> + <i>cM</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>s</sup></i> = <i>ty<sup>c</sup></i>. User <i>A</i> recovers M as (<i>s</i> - <i>d</i>)/<i>c</i> mod <i>o</i>.
0237A second example of embodiments with verifiable communication is described. This example embodiment is a modification of the first example of embodiments with verifiable communication where user <i>A</i> construct <i>G, g, d</i> once and reuses them in the communication of multiple messages, while cryptographic security remains similar. This is done using a blinding-like technique, as described below. This technique applies to other embodiments where ElGamal is used for <i>S.</i>
0238User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly. In addition, user <i>A</i> randomly chooses <maths id="math0434"><math display="inline"><mi>j</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0446.tif" /></maths> and communicates <i>k</i>, where <i>k</i> = <i>d</i> + <i>j</i> mod <i>o</i>, securely to user <i>B</i> using a traditional cryptographic communication system, and communicates <i>u</i> where <i>u</i> = <i>g<sup>j</sup></i> openly. This establishes pk = (<i>g</i>, <i>t</i>, <i>u)</i> as a public key and sk = <i>k</i> as a secret key shared by both user <i>A</i> and user <i>B,</i> and the set <i>G</i>. User <i>A</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> as follows. Alternatively, one may produce <i>S</i> based on Schnorr as follows. User <i>A</i> produces an argument of knowing sk as <i>S</i>. User <i>A</i> chooses <maths id="math0435"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0447.tif" /></maths>, sets <i>v</i> = <i>g<sup>r</sup></i>, and communicates <i>v.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> communicates <i>w</i> = <i>r</i> + <i>c'k</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>w</sup> = v</i>(<i>ut</i>)<i><sup>c'</sup>.</i> Let <i>H</i>(·) be a cryptographic hash function that is publicly known. User <i>A</i> chooses <maths id="math0436"><math display="inline"><mi>j</mi><mo>′</mo><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0448.tif" /></maths> having gcd(<i>j'</i>, <i>o</i>) = 1, sets <i>r</i> = <i>g<sup>j'</sup></i>, and computes <i>q</i> = <i>(H(Q)</i> - <i>kr</i>)/<i>j'</i> mod <i>o</i>; this step is repeated until <i>q</i> ≠ 0. User <i>A</i> communicates <i>r</i>, <i>q</i> openly. The argument is verified by checking that <i>g</i><sup><i>H</i>(<i>Q</i>)</sup><i>=</i> (<i>tu</i>)<i><sup>r</sup>r<sup>q</sup>.</i> User <i>A</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> similarly, with <i>k</i> replacing <i>d.</i> User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing M as follows. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y = g<sup>M</sup></i>, <i>s</i> = <i>k</i> + <i>cM</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>s</sup></i> = <i>tuy<sup>c</sup></i>. User <i>A</i> recovers <i>M</i> as (s - <i>k</i>)/<i>c</i> mod <i>o</i>.
0239A third example of embodiments with verifiable communication is described. This example embodiment is a modification of the first example of embodiments with verifiable communication where user <i>B</i> is the one producing <i>S</i> using user <i>A</i>'s secret key, as if it is delegated. This technique applies to other embodiments where user <i>A</i> and user <i>B</i> share sk. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly. User <i>A</i> communicates (<i>g</i>, <i>t</i>) openly and communicates <i>d</i> securely to user <i>B</i> similarly, establishing pk = (<i>g</i>, <i>t</i>), sk = <i>d,</i> and G similarly. User <i>B</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> similarly. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> similarly. User <i>A</i> recovers <i>M</i> similarly.
0240A fourth example of embodiments with verifiable communication is described. This example embodiment is a modification of the second example of embodiments with verifiable communication where user <i>B</i> is the one producing <i>S</i> using user <i>A</i>'s secret key, as if it is delegated. This technique applies to other embodiments where user <i>A</i> and user <i>B</i> share sk. It demonstrates that techniques described here may be used together. Here we demonstrate this for multiple combination of techniques. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i>, <i>j</i>, <i>u, k</i> similarly. User <i>A</i> communicates (<i>g</i>, <i>t</i>, <i>u</i>) openly and communicates <i>k</i> securely to user <i>B</i> similarly, establishing pk = (<i>g</i>, <i>t</i>, <i>u</i>), sk = <i>k</i>, and G similarly. User <i>B</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> similarly. User <i>B</i> wishing to communicate message M to user <i>A</i> produces an argument <i>T</i> similarly. User <i>A</i> recovers <i>M</i> similarly.
0241A fifth example of embodiments with verifiable communication is described. This example embodiment is a modification of the third example of embodiments with verifiable communication where user <i>A</i> constructs additional <i>k</i> secret parameters. This technique applies to other embodiments employing the discrete logarithm problem. From both security and practical points of view, <i>k</i> would be much smaller than <i>o</i>.
0242Here, formulas with a free subscript <i>i</i> apply for all <i>i</i> ∈ {1,..., <i>k</i>}. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly. In addition, user <i>A</i> randomly chooses <maths id="math0437"><math display="inline"><msub><mi>m</mi><mi>i</mi></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0449.tif" /></maths> and computes <i>y<sub>i</sub></i> = <i>g<sup>m<sub2>i</sub2></sup>.</i> User <i>A</i> communicates (<i>g</i>, <i>t, y<sub>i</sub></i>) openly and communicates (<i>d</i>, <i>m<sub>i</sub></i>) securely to user <i>B</i> similarly, establishing pk = (<i>g</i>, <i>t</i>, <i>y<sub>i</sub></i>), sk = (<i>d</i>, <i>m<sub>i</sub></i>), and <i>G</i> similarly. User <i>A</i> produces an argument <i>S</i> of knowing sk using signatures of <i>Q</i> as follows. Given challenges <i>c<sub>i</sub></i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> communicates <i>s</i><sub>1</sub> where <i>s</i><sub>1</sub> = <i>d</i> + <i>c<sub>i</sub>m<sub>i</sub></i> mod <i>o</i>. Let <i>H</i>(·) be a cryptographic hash function that is publicly known. User <i>A</i> chooses <i>j</i>, <maths id="math0438"><math display="inline"><mi>j</mi><mo>′</mo><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0450.tif" /></maths> having gcd(<i>j</i>, <i>o</i>) = 1, gcd(<i>j'</i>, <i>o</i>) = 1, sets <i>r</i> = <i>g<sup>j'</sup></i>, <maths id="math0439"><math display="inline"><msub><mi>r</mi><mi>i</mi></msub><mo>=</mo><msup><mi>g</mi><msubsup><mi>j</mi><mi>i</mi><mo>′</mo></msubsup></msup></math><img file="EP4040713A1_D0451.tif" /></maths>, and computes <i>q =</i> (<i>H</i>(<i>Q</i>) - <i>dr</i>)<i>j'</i> mod <i>o</i>, <maths id="math0440"><math display="inline"><msub><mi>q</mi><mi>i</mi></msub><mo>=</mo><mfenced><mi>H</mi><mfenced><mi>Q</mi></mfenced><mo>−</mo><msub><mi>m</mi><mi>i</mi></msub><mi>r</mi></mfenced><mo>/</mo><msubsup><mi>j</mi><mi>i</mi><mo>′</mo></msubsup></math><img file="EP4040713A1_D0452.tif" /></maths> mod <i>o</i>; a step is repeated until its <i>q</i> ≠ 0 or <i>q<sub>i</sub></i> ≠ 0. User <i>A</i> communicates <i>r</i>, <i>r<sub>i</sub></i>, <i>q</i>, <i>q<sub>i</sub></i> openly. The argument is verified by checking that <maths id="math0441"><math display="inline"><msup><mi>g</mi><msub><mi>s</mi><mi>i</mi></msub></msup><mo>=</mo><msubsup><mi mathvariant="italic">ty</mi><mi>i</mi><msub><mi>c</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0453.tif" /></maths> and that <maths id="math0442"><math display="inline"><msup><mi>g</mi><mrow><mi>H</mi><mfenced><mi>Q</mi></mfenced></mrow></msup><mo>=</mo><msup><mi>t</mi><mi>r</mi></msup><msup><mi>r</mi><mi>q</mi></msup><mo>=</mo><msup><mi>t</mi><msub><mi>r</mi><mi>i</mi></msub></msup><msubsup><mi>r</mi><mi>i</mi><msub><mi>q</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0454.tif" /></maths><i>.</i> User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. Given challenges <i>c</i>, <maths id="math0443"><math display="inline"><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup><mo>∈</mo><mi>C</mi><mfenced open="[" close="]"><mi>l</mi></mfenced></math><img file="EP4040713A1_D0455.tif" /></maths>, user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y</i> = <i>g<sup>M</sup></i>, <maths id="math0444"><math display="inline"><mi>s</mi><mo>=</mo><mi>d</mi><mo>+</mo><mfenced><mstyle displaystyle="true"><mo>∑</mo><mrow><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup><msub><mi>m</mi><mi>i</mi></msub></mrow></mstyle></mfenced><mo>+</mo><mi mathvariant="italic">cM</mi></math><img file="EP4040713A1_D0456.tif" /></maths> mod <i>o</i>. The argument is verified by checking that <maths id="math0445"><math display="inline"><msup><mi>g</mi><mi>s</mi></msup><mo>=</mo><mi>t</mi><mfenced><mstyle displaystyle="true"><mo>∏</mo><msubsup><mi>y</mi><mi>i</mi><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup></msubsup></mstyle></mfenced><msup><mi>y</mi><mi>c</mi></msup></math><img file="EP4040713A1_D0457.tif" /></maths>. User <i>A</i> recovers <i>m<sub>i</sub></i> as (<i>s<sub>i</sub></i> - <i>d</i>)/<i>c<sub>i</sub></i> mod <i>o</i> and <i>M</i> as <maths id="math0446"><math display="inline"><mfenced><mi>s</mi><mo>−</mo><mi>d</mi><mo>−</mo><mstyle displaystyle="true"><mo>∑</mo><mrow><msubsup><mi>c</mi><mi>i</mi><mo>′</mo></msubsup><msub><mi>m</mi><mi>i</mi></msub></mrow></mstyle></mfenced><mo>/</mo><mi>c</mi></math><img file="EP4040713A1_D0458.tif" /></maths> mod <i>o</i>.
0243A sixth example of embodiments with verifiable communication is described. This example embodiment is a modification of the first example of embodiments with verifiable communication where user <i>A</i> and user <i>B</i> produce the argument <i>T</i> together, without user <i>B</i> knowing the private key corresponding to pk, which remains secret rather than shared between them. This technique applies to other embodiments where a Schnorr-like protocol is used for <i>T.</i> It demonstrates a case where sk is not a private key corresponding to the public key pk. User <i>A</i> sets up two sets of ElGamal parameters <i>G</i>, <i>g, o</i> and <i>G'</i>, <i>g'</i>, <i>d'</i>, <i>t'</i>, <i>o'</i> similarly, where <i>G</i>' is (possibly isomorphic to) a subgroup of <maths id="math0447"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0459.tif" /></maths> so that <i>g<sup>g'<sup2>x</sup2></sup></i> is well-defined for <i>x</i> ∈ [<i>o'</i>]. User <i>A</i> communicates both (<i>g</i>, <i>g'</i>) openly, establishing pk = (<i>g</i>, <i>g'</i>), sk = <i>t'</i>, and <i>G</i> similarly, leaving <i>d'</i> secret. User <i>A</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> (with <i>d'</i>, <i>t'</i>) similarly. Here, when an <i>x</i> ∈ <i>G'</i> (e.g. <i>t'</i>) appears in the exponent, a function <maths id="math0448"><math display="inline"><mi>G</mi><mo>→</mo><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0460.tif" /></maths> with unpredictable image may apply to <i>x.</i> Any public cryptographic hash function on a binary form <i>of x</i> can be used.
0244User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. First, user <i>A</i> communicates <i>t'</i> to user <i>B</i> privately using a traditional cryptographic communication system. Note that user <i>B</i> does not learn the secret <i>d'</i>. Next, user <i>A</i> randomly chooses <maths id="math0449"><math display="inline"><mi>j</mi><mo>′</mo><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0461.tif" /></maths>, computes <i>k'</i> = <i>d'</i> + <i>j'</i>, and communicates <i>u"</i>, <i>v'</i> where <i>u"</i> = <i>g<sup>g'<sup2>k'</sup2></sup></i>, <i>v'</i> = <i>g'<sup>j'</sup>.</i> Note that since DLP is hard in <i>G'</i>, only knowing <i>d'</i> allows producing <i>u"</i>. User <i>B</i> verifies that <i>u"</i> = <i>g<sup>v't'</sup>.</i> User <i>B</i> communicates <i>u</i>, <i>y</i> where <i>u</i> = <i>g<sup>t'</sup></i>, <i>y</i> = <i>g<sup>M</sup>.</i> Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates <i>s</i> where <i>s = t'</i> + <i>cM.</i> The argument is verified by checking that <i>u<sup>v'</sup></i> = <i>u"</i>, <i>g<sup>s</sup></i> = <i>uy<sup>c</sup></i>. User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>t'</i>)/<i>c</i> mod <i>o</i>.
0245A seventh example of embodiments with verifiable communication is described. This example embodiment is a modification of the third example of embodiments with verifiable communication where a Diffie-Helman-like protocol is used for constructing <i>T</i>. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly. User <i>A</i> communicates (<i>g</i>, <i>t</i>) openly and communicates <i>d</i> securely to user <i>B</i> similarly, establishing pk = (<i>g</i>, <i>d)</i> and sk = <i>d.</i> User <i>B</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> similarly. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. User <i>B</i> randomly chooses <maths id="math0450"><math display="inline"><mi>j</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0462.tif" /></maths> and communicates <i>j.</i> Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y</i> = <i>g<sup>M</sup></i>, <i>s</i> = <i>dj</i> + <i>cM</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>s</sup></i> = <i>t<sup>j</sup>y<sup>c</sup>.</i> User <i>A</i> recovers <i>M</i> as (s - <i>dj</i>)/<i>c</i> mod <i>o</i>.
0246An eighth example of embodiments with verifiable communication is described. This example embodiment is a modification of the example of embodiments with verifiable communication where a blinding-like technique similar to that in the second example of embodiments with verifiable communication is applied. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly. In addition, user <i>A</i> randomly chooses <maths id="math0451"><math display="inline"><mi>j</mi><mo>′</mo><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0463.tif" /></maths> and communicates <i>k</i>, where <i>k</i> = <i>d</i> + <i>j'</i> mod <i>o</i>, securely to user <i>B</i> using a traditional cryptographic communication system, and communicates <i>u</i> where <i>u</i> = <i>g<sup>j'</sup></i> openly. This establishes pk = (<i>g</i>, <i>t</i>, <i>u</i>) as a public key and sk = <i>k</i> as a secret key shared by both user <i>A</i> and user <i>B,</i> and the set <i>G</i>.
0247User <i>B</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> similarly. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. User <i>B</i> randomly chooses <maths id="math0452"><math display="inline"><mi>j</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0464.tif" /></maths> and communicates (<i>j</i>, <i>v</i>) where <i>v</i> = <i>g<sup>kj</sup>.</i> Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y</i> = <i>g<sup>M</sup></i>, <i>s</i> = <i>kj</i> + <i>cM</i> mod <i>o</i>. The argument is verified by checking that <i>v</i> = (<i>tu</i>)<i><sup>j</sup></i>, <i>g<sup>s</sup></i> = <i>vy<sup>c</sup>.</i> User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>kj</i>)/<i>c</i> mod <i>o</i>.
0248A ninth example of embodiments with verifiable communication is described. This example embodiment is a modification of the third example of embodiments with verifiable communication where a Cramer-Shoup-like protocol is used for constructing <i>T.</i> User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly. User <i>A</i> wishing to receive a message from user <i>B</i> first randomly chooses <i>j</i><sub>1</sub>, <i>j</i><sub>2</sub>, <i>k</i><sub>1</sub>, <maths id="math0453"><math display="inline"><msub><mi>k</mi><mn>2</mn></msub><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0465.tif" /></maths>, then sets up a Cramer-Shoup key pair on <i>G</i> with <i>z</i> := <i>d,</i> with generators <i>g</i><sub>1</sub>, <i>g</i><sub>2</sub> where <i>g</i><sub>1</sub> := <i>g</i>, and with <i>x<sub>i</sub></i> := <i>j<sub>i</sub></i>/<i>d</i> mod <i>o</i>, <i>y<sub>i</sub></i>, := <i>k<sub>i</sub></i>/<i>d</i> mod <i>o</i> for <i>i</i> ∈ {1, 2}. This yields a public key <i>(c', d', h</i>) where <maths id="math0454"><math display="inline"><mi>c</mi><mo>′</mo><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><msub><mi>x</mi><mn>1</mn></msub></msubsup><msubsup><mi>g</mi><mn>2</mn><msub><mi>x</mi><mn>2</mn></msub></msubsup></math><img file="EP4040713A1_D0466.tif" /></maths>, <maths id="math0455"><math display="inline"><mi>d</mi><mo>′</mo><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><msub><mi>y</mi><mn>1</mn></msub></msubsup><msubsup><mi>g</mi><mn>2</mn><msub><mi>y</mi><mn>2</mn></msub></msubsup></math><img file="EP4040713A1_D0467.tif" /></maths>, <maths id="math0456"><math display="inline"><mi>h</mi><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><mi>z</mi></msubsup><mo>=</mo><mi>t</mi></math><img file="EP4040713A1_D0468.tif" /></maths>, a secret key (<i>x</i><sub>1</sub>, <i>x</i><sub>2</sub>, <i>y</i><sub>1</sub>, <i>y</i><sub>2</sub>, <i>z</i>), and a cryptographic hash function <i>H.</i> User <i>A</i> communicates (<i>t</i>, <i>g</i><sub>1</sub>, <i>g</i><sub>2</sub>, <i>c'</i>, <i>d'</i>, <i>h</i>, <i>j</i><sub>1</sub>, <i>j</i><sub>2</sub>, <i>k</i><sub>1</sub>, <i>k</i><sub>2</sub>, <i>H</i>) openly and <i>d</i> securely to user <i>B</i> similarly, establishing pk = (<i>t</i>, <i>g</i><sub>1</sub>, <i>g</i><sub>2</sub>, <i>c'</i>, <i>d'</i>, <i>h</i>, <i>j</i><sub>1</sub>, <i>j</i><sub>2</sub>, <i>k</i><sub>1</sub>, <i>k<sub>2</sub></i>, <i>H</i>) and sk = <i>d.</i>
0249User <i>B</i> produces an argument of knowing sk as a signature <i>S</i> of <i>Q</i> similarly. User <i>B</i> wishing to communicate message M to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> randomly chooses <i>j</i>, <i>k</i>, <maths id="math0457"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0469.tif" /></maths>, computes <maths id="math0458"><math display="inline"><mi>w</mi><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><mi>j</mi></msubsup></math><img file="EP4040713A1_D0470.tif" /></maths><i>w</i><maths id="math0459"><math display="inline"><msub><mi>u</mi><mn>1</mn></msub><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><mi>k</mi></msubsup></math><img file="EP4040713A1_D0471.tif" /></maths>, <maths id="math0460"><math display="inline"><msub><mi>u</mi><mn>2</mn></msub><mo>=</mo><msubsup><mi>g</mi><mn>2</mn><mi>k</mi></msubsup></math><img file="EP4040713A1_D0472.tif" /></maths>, <maths id="math0461"><math display="inline"><mi>y</mi><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><mi>M</mi></msubsup></math><img file="EP4040713A1_D0473.tif" /></maths>, <i>e'</i> = <i>h<sup>k</sup>y</i>, <i>α</i> = <i>H</i>(<i>u</i><sub>1</sub>, <i>u</i><sub>2</sub>, <i>e'</i>), <i>v</i> = <i>c'<sup>k</sup>d'<sup>kα</sup></i>, <i>v'</i> = <i>v<sup>d</sup></i>, <maths id="math0462"><math display="inline"><mi>a</mi><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup></math><img file="EP4040713A1_D0474.tif" /></maths>, <i>b</i> = <i>v<sup>r</sup></i> and posts (<i>w</i>, <i>y</i>, <i>u</i><sub>1</sub>, <i>u</i><sub>2</sub>, <i>e'</i>, <i>v</i>, <i>v'</i>). User <i>B</i> verifiably communicates <i>j</i> for <maths id="math0463"><math display="inline"><msubsup><mi>g</mi><mn>1</mn><mi>j</mi></msubsup></math><img file="EP4040713A1_D0475.tif" /></maths> using one of the known methods. Given challenges <i>c</i><sub>1</sub>, <i>c</i><sub>2</sub> ∈ <i>C</i>[<i>l</i>], user <i>B</i> computes <i>s</i> = <i>d</i> + <i>j</i> + <i>c</i><sub>1</sub><i>M</i> mod <i>o</i>, <i>x</i> = <i>r</i> + <i>c</i><sub>2</sub><i>d</i> mod <i>o</i> and communicates (<i>s</i>, <i>x</i>). Each of the challenges <i>c</i><sub>1</sub>, <i>c</i><sub>2</sub> may be set to a function of <i>α</i>. The argument is verified by recovering <i>α</i> as <i>H</i>(<i>u</i><sub>1</sub>, <i>u</i><sub>2</sub>, <i>e'</i>), checking that <maths id="math0464"><math display="inline"><msubsup><mi>g</mi><mn>1</mn><mi>x</mi></msubsup><mo>=</mo><msup><mi mathvariant="italic">ah</mi><msub><mi>c</mi><mn>2</mn></msub></msup></math><img file="EP4040713A1_D0476.tif" /></maths>, <i>v<sup>x</sup></i> = <i>bv'</i><sup><i>c</i><sub2>2</sub2></sup> which shows the same exponent appears in <i>h, v'</i> to bases <i>g</i><sub>1</sub>, <i>v</i> respectively, and checking that <maths id="math0465"><math display="inline"><msubsup><mi>g</mi><mn>1</mn><mi>s</mi></msubsup><mo>=</mo><msup><mi mathvariant="italic">hwy</mi><msub><mi>c</mi><mn>1</mn></msub></msup></math><img file="EP4040713A1_D0477.tif" /></maths> and <maths id="math0466"><math display="inline"><mi>ν</mi><mo>′</mo><mo>=</mo><msubsup><mi>u</mi><mn>1</mn><msub><mi>j</mi><mn>1</mn></msub></msubsup><msubsup><mi>u</mi><mn>2</mn><msub><mi>j</mi><mn>2</mn></msub></msubsup><msup><mfenced><msubsup><mi>u</mi><mn>1</mn><msub><mi>k</mi><mn>1</mn></msub></msubsup><msubsup><mi>u</mi><mn>2</mn><msub><mi>k</mi><mn>2</mn></msub></msubsup></mfenced><mi>α</mi></msup></math><img file="EP4040713A1_D0478.tif" /></maths>. User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>d</i> - <i>j</i>)/<i>c</i><sub>1</sub> mod <i>o</i>.
0250A tenth example of embodiments with verifiable communication is described. This example embodiment uses a Schnorr-like protocol for constructing both <i>T</i> and <i>S</i>. User <i>A</i> wishing to receive a message from user <i>B</i> first constructs a group <i>G</i>, with generator <i>g</i> of prime order <i>o</i> of bit length <i>l</i>, where DLP is hard, a secret key <maths id="math0467"><math display="inline"><mi>d</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0479.tif" /></maths>, and a corresponding public key <i>t</i> = <i>g<sup>d</sup>.</i> This establishes the set <i>G</i>. User <i>A</i> communicates (<i>g</i>, <i>t</i>) openly and communicates <i>d</i> securely to user <i>B</i> using a traditional cryptographic communication system. This establishes pk = (<i>g</i>, <i>t</i>) as a public key and sk = <i>d</i> as a secret key shared by both user <i>A</i> and user <i>B.</i> User <i>A</i> produces an argument of knowing sk as <i>S</i>. User <i>A</i> chooses <maths id="math0468"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0480.tif" /></maths>, sets <i>v</i> := <i>g<sup>r</sup></i>, and communicates <i>v.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> communicates <i>w := r</i> + <i>c'd</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>w</sup></i> = <i>vt<sup>c'</sup></i>. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y</i> := <i>g<sup>M</sup></i>, <i>s := d</i> + <i>cM</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>s</sup></i> = <i>ty<sup>c</sup></i>. User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>d</i>)/<i>c</i> mod <i>o</i>.
0251An eleventh example of embodiments with verifiable communication is described. This example embodiment is a modification of the tenth example embodiment with verifiable communication where a blinding-like protocol is used. User <i>A</i> sets up <i>G, g, o</i>, <i>d, t</i> similarly. In addition, user <i>A</i> chooses <maths id="math0469"><math display="inline"><mi>j</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>Z</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0481.tif" /></maths> and sets <i>k</i> := <i>d</i> + <i>j</i> mod <i>o</i>, <i>u</i> := <i>g<sup>j</sup>.</i> User <i>A</i> communicates (<i>g</i>, <i>t</i>, <i>u</i>) openly and communicates <i>k</i> securely to user <i>B</i> similarly, establishing pk = (<i>g</i>, <i>t</i>, <i>u</i>) and sk = <i>k.</i> User <i>A</i> produces an argument of knowing sk as <i>S.</i> User <i>A</i> chooses <maths id="math0470"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0482.tif" /></maths>, sets <i>v</i> := <i>g<sup>r</sup></i>, and communicates <i>v.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>], user <i>A</i> communicates <i>w</i> := <i>r</i> + <i>c'k</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>w:</sup></i> = <i>v</i>(<i>tu</i>)<i><sup>c'</sup>.</i> User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> whereby knowing sk implies knowing <i>M</i> as follows. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>], user <i>B</i> communicates (<i>y</i>, <i>s</i>) where <i>y</i> := <i>g<sup>M</sup></i>, <i>s</i> := <i>k</i> + <i>cM</i> mod <i>o</i>. The argument is verified by checking that <i>g<sup>s</sup></i> = <i>tuy<sup>c</sup></i>. User <i>A</i> recovers <i>M</i> as (s - <i>k</i>)/<i>c</i> mod <i>o</i>.
0252A twelfth example of embodiments with verifiable communication is described. This example embodiment uses a pairing. It includes a description of a method for constructing an argument of knowledge of a discrete logarithm. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly with a pairing <i>E : G</i> × <i>G</i> → <i>G<sub>T</sub></i>, for which ∀<i>a</i>, <maths id="math0471"><math display="inline"><mi>b</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0483.tif" /></maths> : <i>E</i>(<i>g<sup>a</sup></i>, <i>g<sup>b</sup></i>) = <i>E</i>(<i>g</i>, <i>g</i>)<i><sup>ab</sup></i> and <i>E</i>(<i>g</i>, <i>g</i>) generates <i>G<sub>T</sub>.</i> Two well-known ones are Weil and Tate pairings, which are efficient to compute. The order <i>o</i> may be chosen as a Solinas prime to allow for certain optimizations. This establishes the set <i>G</i>.
0253User <i>A</i> produces an argument of knowing sk as <i>S</i> as follows. User <i>A</i> chooses <maths id="math0472"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0484.tif" /></maths>, sets <i>u</i> := <i>g<sup>a</sup></i>, and posts <i>u</i>. To prove knowledge of <i>d</i> in <i>t</i>, user <i>A</i> sets <i>s' := ad</i> mod <i>o</i> and posts <i>s'</i>. The argument is verified by checking that <i>E</i>(<i>g</i>, <i>g</i>)<i><sup>s'</sup></i> = <i>E</i>(<i>u</i>, <i>t</i>). User <i>A</i> communicates <i>d</i> to user <i>B</i> by a traditional cryptographic protocol. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> sets <i>y</i> := <i>g<sup>M</sup></i> and posts <i>y.</i> User <i>A</i> sets <i>s := dM</i> mod <i>o</i> and posts <i>s</i>. The argument is verified by checking that <i>E</i>(<i>g</i>, <i>g</i>)<i><sup>s</sup></i> = <i>E(t, y).</i> User <i>A</i> recovers <i>M</i> as s/d mod <i>o</i>.
0254A thirteenth example of embodiments with verifiable communication is described. This example embodiment is a modification of the twelfth example embodiment with verifiable communication where sk may be shared in the construction of multiple instances of the embodiment for communicating between the users. User <i>A</i> sets up <i>G, g, d, t</i>, <i>o</i> similarly with a pairing <i>E : G</i> × <i>G</i> → <i>G<sub>T</sub>.</i> User <i>A</i> wishing to receive a message from user <i>B</i> produces an argument <i>S</i> similarly. This is only necessary in the first instance as will be understood next. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. First, <i>M'</i> is assumed to be a previous message that was verifiably communicated for <i>g<sup>M'</sup></i> by user <i>B</i> to user <i>A,</i> using this method or one such as that of the tenth example of embodiments with verifiable communication, e.g. if this is the first instance. It is ensured no message verifiably communicated in this manner is ever repeated. Let <i>u</i> := <i>g<sup>M'</sup></i> which as assumed has been previously posted. Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>B</i> computes <i>s</i> := <i>dM'</i> + <i>cM</i> mod <i>o</i> and posts <i>s</i>. The argument is verified by setting <i>v</i> := <i>E</i>(<i>t, u</i>), <i>z</i> := <i>E</i>(<i>g, y</i>) so that <i>v</i> = <i>E</i>(<i>g, g</i>)<i><sup>dM'</sup>, z</i> = <i>E</i>(<i>g, g</i>)<i><sup>M</sup></i> and checking that <i>E</i>(<i>g, g</i>)<i><sup>s</sup></i> = <i>vz<sup>c</sup>.</i> User <i>A</i> recovers <i>M</i> as <i>(s</i> - <i>dM'</i>)/<i>c</i> mod <i>o</i>.
0255A fourteenth example of embodiments with verifiable communication is described. This example embodiment is a modification of the twelfth example embodiment with verifiable communication where an eth root of a discrete logarithm is communicated. It includes a description of a method for constructing an argument of knowledge of an eth-root of a discrete logarithm. User <i>A</i> sets up <i>G, g, d, t, o</i> similarly with a pairing <i>E</i> : <i>G</i> × <i>G → G<sub>T</sub></i> where DLP in <i>G, G<sub>T</sub></i> and eth-root of the discrete logarithm in <i>G</i> are hard. However, in this case, for a fixed <i>e</i>, user <i>A</i> chooses <maths id="math0473"><math display="inline"><mi>x</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0485.tif" /></maths> and sets <i>d</i> := <i>x<sup>e</sup></i> mod <i>o</i>, so <i>x</i> is a root of a discrete logarithm of <i>t</i>. This establishes sk = <i>x</i> instead of <i>d,</i> and the set <i>G</i>. User <i>A</i> produces an argument of knowing sk as <i>S</i> as follows. User <i>A</i> chooses <maths id="math0474"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0486.tif" /></maths>, sets <i>u</i> := <i>g<sup>a<sup2>e</sup2></sup></i>, and posts <i>u</i>. To prove knowledge of <i>x</i> in <i>t,</i> user <i>A</i> sets <i>s'</i> := <i>ax</i> mod <i>o</i> and posts <i>s'</i>. The argument is verified by checking that <i>E</i>(<i>g</i>, <i>g</i>)<i><sup>s<sup2>'e</sup2></sup></i> = <i>E</i>(<i>u</i>, <i>t</i>). User <i>A</i> communicates <i>x</i> to user <i>B</i> by a traditional cryptographic protocol. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> sets <i>y</i> := <i>g<sup>M<sup2>e</sup2></sup></i> and posts <i>y</i>. User <i>A</i> sets <i>s</i> := <i>xM</i> mod <i>o</i> and posts <i>s</i>. The argument is verified by checking that <i>E</i>(<i>g, g</i>)<i><sup>s<sup2>e</sup2></sup></i> = <i>E</i>(<i>t</i>, <i>y</i>). User <i>A</i> recovers <i>M</i> as <i>s</i>/<i>x</i> mod <i>o</i>.
0256A fifthteenth example of embodiments with verifiable communication is described. This example embodiment is a modification of the twelfth example embodiment with verifiable communication where a double-discrete logarithm is communicated. It includes a description of a method for constructing an argument of knowledge of a double-discrete logarithm. User <i>A</i> sets up <i>G, g, d, t, o</i> similarly with a pairing <i>E</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub></i> where DLP in <i>G, G<sub>T</sub></i> and double-discrete logarithm problem in <i>G</i> are hard. However, in this case, for a fixed <i>h</i> of order <i>o'</i> in <maths id="math0475"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0487.tif" /></maths>, user <i>A</i> chooses <maths id="math0476"><math display="inline"><mi>x</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0488.tif" /></maths>, and sets <i>d</i> := <i>h<sup>x</sup></i> mod <i>o</i>, so <i>x</i> is a double discrete logarithm of <i>t</i>. This establishes sk = <i>x</i> instead of <i>d</i>, and the set <i>G</i>. User <i>A</i> produces an argument of knowing sk as <i>S</i> as follows. User <i>A</i> chooses <maths id="math0477"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mrow><mi>o</mi><mo>′</mo></mrow><mo>*</mo></msubsup></math><img file="EP4040713A1_D0489.tif" /></maths>, sets <i>u</i> := <i>g<sup>h<sup2>a</sup2></sup></i>, and posts <i>u</i>. To prove knowledge of <i>x</i> in <i>t</i>, user <i>A</i> sets <i>s'</i> := <i>a</i> + <i>x</i> mod <i>o</i> and posts <i>s'</i>. The argument is verified by checking that <i>E</i>(<i>g, g</i>)<i><sup>hs'</sup></i> = <i>E</i>(<i>u</i>, <i>t</i>)<i>.</i> User <i>A</i> communicates <i>x</i> to user <i>B</i> by a traditional cryptographic protocol. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> sets <i>y</i> := <i>g<sup>h<sup2>M</sup2></sup></i> and posts <i>y</i>. User <i>A</i> sets <i>s</i> := <i>x</i> + <i>M</i> mod <i>o</i> and posts <i>s</i>. The argument is verified by checking that <i>E</i>(<i>g</i>, <i>g</i>)<i><sup>h<sup2>s</sup2></sup></i> = <i>E</i>(<i>t</i>, <i>y</i>). User <i>A</i> recovers <i>M</i> as <i>s</i> - <i>x</i> mod <i>o</i>.
0257A sixteenth example of embodiments with verifiable communication is described. This example embodiment is a modification of the twelfth example embodiment with verifiable communication where an <i>e</i>th-root of a discrete logarithm is communicated using Schnorr-like protocols. It includes a description of a method for constructing an argument of knowledge of an <i>e</i>th-root of a discrete logarithm. User <i>A</i> sets up <i>G, g, d, t, o</i> similarly with a pairing <i>E</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub></i> where DLP in <i>G, G<sub>T</sub></i> and root-of-discrete-logarithm problem in <i>G</i> are hard. For a fixed <i>e</i>, user <i>A</i> chooses <maths id="math0478"><math display="inline"><mi>x</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0490.tif" /></maths> and sets <i>d</i> := <i>x<sup>e</sup></i> mod <i>o</i>, so <i>x</i> is a root of discrete logarithm of <i>t</i>. User <i>A</i> communicates <i>x</i> to user <i>B</i> by a traditional cryptographic protocol. This establishes sk = <i>x</i> instead of <i>d</i>, and pk, <i>G</i> similarly. User <i>A</i> produces an argument of knowing sk as <i>S</i> as follows. User <i>A</i> chooses <i>a</i>, <maths id="math0479"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0491.tif" /></maths>, sets <i>u</i> := <i>g<sup>r<sup2>e</sup2></sup></i>, <i>v</i> := <i>g<sup>a</sup>,</i> and posts <i>u, v.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> sets <i>v'</i> := <i>g<sup>a<sup2>c'</sup2></sup></i>, <i>u'</i> := <i>ax<sup>e</sup></i> mod <i>o</i>, <i>t'</i> := <i>g<sup>x<sup2>c'e</sup2></sup></i>, <i>s'</i> := <i>rx<sup>c'</sup></i> mod <i>o</i> and posts <i>v', u', t', s'.</i> The argument is verified by setting <maths id="math0480"><math display="inline"><mi>u</mi><mo>"</mo><mo>:</mo><mo>=</mo><msup><mi>g</mi><mrow><mi>u</mi><msup><mo>′</mo><mrow><mi>c</mi><mo>′</mo></mrow></msup></mrow></msup></math><img file="EP4040713A1_D0492.tif" /></maths> and checking that <i>E</i>(<i>g, u"</i>) = <i>E</i>(<i>v', t'</i>)<i>, , E</i>(<i>v'</i>, <i>y<sup>s'<sup2>e</sup2></sup></i>) = <i>E</i>(<i>u</i>, <i>u"</i>). User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> chooses <maths id="math0481"><math display="inline"><mi>b</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0493.tif" /></maths>, sets <i>w</i> := <i>g<sup>b</sup></i>, <i>y</i> := <i>g<sup>M<sup2>e</sup2></sup></i> and posts <i>w, y.</i> Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> sets <i>w'</i> := <i>g<sup>b<sup2>c</sup2></sup></i>, <i>z</i> := <i>bM<sup>e</sup></i> mod <i>o, y'</i> := <i>g<sup>M<sup2>ce</sup2></sup></i>, <i>s</i> := <i>xM<sup>c</sup></i> mod <i>o</i> and posts <i>w', z, y', s.</i> The argument is verified by setting <i>z'</i> := <i>g<sup>z<sup2>c</sup2></sup></i> and checking that <i>E</i>(<i>g</i>, <i>z'</i>) = <i>E</i>(<i>w'</i>, <i>y'</i>), <i>E</i>(<i>w</i>, <i>y</i>) = <i>E</i>(<i>g</i>, <i>g<sup>z</sup></i>), <i>E</i>(<i>w'</i>, <i>g<sup>s<sup2>e</sup2></sup></i>) = <i>E</i>(<i>t</i>, <i>z'</i>). User <i>A</i> recovers M as (<i>s</i>/<i>x</i>)<sup>1/<i>c</i></sup> mod <i>o</i>.
0258A seventeenth example of embodiments with verifiable communication is here described. This example embodiment is a modification of the twelfth example embodiment with verifiable communication where a double-discrete logarithm is communicated using Schnorr-like protocols. It includes a description of a method for constructing an argument of knowledge of a double-discrete logarithm. User <i>A</i> sets up <i>G, g, d, t, o</i> similarly with a pairing <i>E</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub></i> where DLP in <i>G, G<sub>T</sub></i> and double-discrete logarithm problem in <i>G</i> are hard. For a fixed <i>h</i> of order <i>o'</i> in <maths id="math0482"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0494.tif" /></maths>, user <i>A</i> chooses <maths id="math0483"><math display="inline"><mi>x</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0495.tif" /></maths><i>,</i> and sets <i>d</i> := <i>h<sup>x</sup></i> mod <i>o</i>, so <i>x</i> is a double discrete logarithm of <i>t</i>. User <i>A</i> communicates <i>x</i> to user <i>B</i> by a traditional cryptographic protocol. This establishes sk = <i>x</i> instead of <i>d,</i> and pk, <i>G</i> similarly. User <i>A</i> produces an argument of knowing sk as <i>S</i> as follows. User <i>A</i> chooses <maths id="math0484"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0496.tif" /></maths>, <maths id="math0485"><math display="inline"><mi>r</mi><mo>∈</mo><msubsup><mi>ℤ</mi><mrow><mi>o</mi><mo>′</mo></mrow><mo>*</mo></msubsup></math><img file="EP4040713A1_D0497.tif" /></maths>, sets <i>u</i> := <i>g<sup>h<sup2>r</sup2></sup></i>, <i>v</i> := <i>g<sup>a</sup>,</i> and posts <i>u, v.</i> Given a challenge <i>c'</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> sets <i>v'</i> := <i>g<sup>a<sup2>c'</sup2></sup></i>, <i>u'</i> := <i>ah<sup>x</sup></i> mod <i>o, t'</i> := <i>g<sup>h<sup2>c'x</sup2></sup></i>, <i>s'</i> := <i>r</i> + <i>c'x</i> mod <i>o</i> and posts <i>v', u', t', s'.</i> The argument is verified by setting <i>u"</i> := <i>g<sup>u'<sup2>c'</sup2></sup></i> and checking that <i>E</i>(<i>g, u"</i>) = <i>E</i>(<i>v'</i>, <i>t'</i>), <i>E</i>(<i>v'</i>, <i>t</i>) = <i>E</i>(<i>g</i>, <i>g<sup>u'</sup></i>), <i>E</i>(<i>v'</i>, <i>g<sup>h<sup2>s'</sup2></sup></i>) = <i>E</i>(<i>u</i>, <i>u"</i>)<i>.</i> User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> chooses <maths id="math0486"><math display="inline"><mi>b</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0498.tif" /></maths>, sets <i>w</i> := <i>g<sup>b</sup>, y</i> := <i>g<sup>h<sup2>M</sup2></sup></i> and posts <i>w, y.</i> Given a challenge <i>c</i> ∈ <i>C</i>[<i>l</i>]<i>,</i> user <i>A</i> sets <i>w'</i> := <i>g<sup>b<sup2>c</sup2></sup>, z</i> := <i>bh<sup>M</sup></i> mod <i>o</i>, <i>y'</i> := <i>g<sup>h<sup2>cM</sup2></sup>, s</i> := <i>x</i> + <i>cM</i> mod <i>o</i> and posts <i>w', z, y', s.</i> The argument is verified by setting <i>z'</i> := <i>g<sup>z<sup2>c</sup2></sup></i> and checking that <i>E</i>(<i>g</i>, <i>z'</i>) = <i>E</i>(<i>w'</i>, <i>y'</i>)<i>, E</i>(<i>w, y</i>) = <i>E</i>(<i>g, g<sup>z</sup></i>)<i>, E</i>(<i>w'</i>, <i>g<sup>h<sup2>s</sup2></sup></i>) = <i>E</i>(<i>t</i>, <i>z'</i>)<i>.</i> User <i>A</i> recovers <i>M</i> as (<i>s</i> - <i>x</i>)/<i>c</i> mod <i>o</i>.
0259An eighteenth example of embodiments with verifiable communication is here described. This example embodiment is a modification of the fourteenth example embodiment with verifiable communication where a plain protocol is used for constructing argument <i>T</i>. User <i>A</i> sets up <i>G, g, x, d, t, o, E</i> similarly. This establishes sk = <i>x</i> and the set <i>G</i>. User <i>A</i> produces an argument of knowing sk as <i>S</i> similarly. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> computes <i>a</i> := <i>M</i>/<i>x</i> mod <i>o</i> and posts <i>a.</i> The argument is verified by computing <i>y</i> := <i>t<sup>a<sup2>e</sup2></sup></i>, noting that <i>y</i> = <i>g<sup>M<sup2>e</sup2></sup>.</i> User <i>A</i> recovers <i>M</i> as <i>ax</i> mod <i>o</i>.
0260A nineteenth example of embodiments with verifiable communication is described. This example embodiment is a modification of the twelfth example embodiment with verifiable communication where a plain protocol is used for constructing argument <i>T</i>. User <i>A</i> sets up <i>G, g, x, d, t, o, h, E</i> similarly. This establishes sk = <i>x</i> and the set <i>G</i>. User <i>A</i> produces an argument of knowing sk as <i>S</i> similarly. User <i>B</i> wishing to communicate message <i>M</i> to user <i>A</i> produces an argument <i>T</i> as follows. User <i>B</i> computes <i>a</i> := <i>M</i> - <i>x</i> mod <i>o</i> and posts <i>a.</i> The argument is verified by computing <i>y</i> := <i>t<sup>h<sup2>a</sup2></sup>,</i> noting that <i>y</i> = <i>g<sup>h<sup2>M</sup2></sup>.</i> User <i>A</i> recovers <i>M</i> as <i>a</i> + <i>x</i> mod <i>o</i>.
0261A twentieth example of embodiments with verifiable communication is described. The example includes a description of a method for verifiable communication of an ElGamal encryption of a message. User <i>A</i> sets up two sets of ElGamal parameters <i>G, g, o</i> and <i>G', g', d', t', o'</i> similarly with a pairing <i>E</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub>,</i> where <i>G'</i> is (possibly isomorphic to) a subgroup of <maths id="math0487"><math display="inline"><msubsup><mi>ℤ</mi><mi>o</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0499.tif" /></maths> so that <i>g<sup>g'<sup2>x</sup2></sup></i> is well-defined for <i>x</i> ∈ [<i>o'</i>], such that DLP in <i>G, G', G<sub>T</sub></i> and double-discrete logarithm problem in <i>G</i> are hard. Let <i>b</i> in <i>t</i> := <i>g<sup>g'<sup2>b</sup2></sup></i> be a secret shared by Alice and Bob. Bob proves knowledge of <i>b</i> using a double-discrete logarithm method as described above. To verifiably communicate <i>k</i> in <i>y</i> := <i>g<sup>g'<sup2>k</sup2></sup></i> to Bob, Alice posts <i>z</i> := <i>g'<sup>a</sup></i> for <i>a</i> := <i>k</i> - <i>b</i> mod <i>o'</i>. One can determine <i>y</i> as <i>t<sup>z</sup></i> and infer that Bob can recover <i>g'<sup>k</sup></i> mod <i>o'</i> as <i>zg'<sup>b</sup></i> mod <i>o'</i>. Alice verifiably communicates a message <i>M</i> ∈ [<i>o'</i>] as follows. Alice posts a commitment <i>m</i> to <i>M</i> where <i>m</i> := <i>g<sup>M</sup></i> mod <i>o</i>. Alice posts <i>s</i> where <i>s</i> := <i>Mg'<sup>k</sup></i> mod <i>o'</i>. The argument is verified by checking that <i>E</i>(<i>g, g<sup>s</sup></i>) = <i>E</i>(<i>m, y</i>). Bob recovers <i>M</i> as <i>s</i>/<i>g'<sup>k</sup></i> mod <i>o'</i>. The pair of posts <i>z</i>, s by Alice constitute an ElGamal encryption in <i>G'</i> having a shared secret <i>g'<sup>k</sup>.</i>
0262A twenty-first example of embodiments with verifiable communication is here described. This example includes a description of a method for verifiable communication of a Paillier encryption of a message. Alice and Bob do not know the Paillier secrets. The public Paillier parameters are a generator <i>g</i> and a modulus <i>n</i><sup>2</sup>. Alice and Bob use a traditional cryptographic protocol to share a secret <maths id="math0488"><math display="inline"><mi>a</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>n</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0500.tif" /></maths>. Bob proves knowledge of <i>a</i> in <i>t</i> := <i>g<sup>a</sup></i> mod <i>n</i><sup>2</sup> using a DL method, for which some choices have been described above, resulting in posting <i>t</i>. For a given <maths id="math0489"><math display="inline"><mi>M</mi><mo>∈</mo><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0501.tif" /></maths>, Alice choose <maths id="math0490"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>n</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0502.tif" /></maths>, sets <i>y</i> := <i>g<sup>M</sup>r<sup>n</sup></i> mod <i>n</i><sup>2</sup> and posts <i>y</i> which is a Paillier encryption of <i>M</i>. Given a challenge <maths id="math0491"><math display="inline"><mi>c</mi><mo>∈</mo><msub><mi>ℤ</mi><mi>n</mi></msub></math><img file="EP4040713A1_D0503.tif" /></maths>, Alice sets <i>s</i> := <i>a</i> + <i>cM, u</i> := <i>r<sup>c</sup></i> mod <i>n</i><sup>2</sup> and posts <i>s</i>, <i>u</i>. This argument is verified by checking that <i>ty<sup>c</sup></i> = <i>g<sup>s</sup>u<sup>n</sup></i> mod <i>n</i><sup>2</sup>.
0263A twenty-second example of embodiments with verifiable communication is described. This example includes a description of a method for verifiable communication of a RSA secret <i>d</i>. Let <i>g</i> be a generator of a group <i>G</i> of order <i>o</i> for which DLP is hard where <i>o</i> := (<i>p</i> - 1)(<i>q</i> - 1), <i>n</i> := <i>pq</i> for <i>p, q</i> large primes of similar bit length, let (<i>d, n</i>)<i>,</i> (<i>e</i>, <i>n</i>) be a RSA key pair known to Alice, and let e, <i>n, g, G</i> be public. Alice commits to <i>y</i> := <i>g<sup>d</sup></i> mod <i>n</i> and <i>t</i> := <i>g<sup>r</sup></i> mod <i>n</i> for <maths id="math0492"><math display="inline"><mi>r</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msubsup><mi>ℤ</mi><mi>n</mi><mo>*</mo></msubsup></math><img file="EP4040713A1_D0504.tif" /></maths>. Given a challenge <i>c</i>, Alice posts <i>s</i> := <i>r</i> + <i>cd.</i> Now it can be verified that y<i><sup>e</sup></i> = <i>g</i> mod <i>n</i> and that <i>g<sup>s</sup></i> = <i>ty<sup>c</sup></i> mod <i>n</i> or <i>g<sup>se</sup></i> = <i>t<sup>e</sup>g<sup>c</sup></i> mod <i>n.</i> Finally, Alice verifiably communicates <i>r</i> for <i>g<sup>r</sup></i> mod <i>n</i> to Bob.
0264A twenty-third example of embodiments with verifiable communication is described. This example involves commitments with selected openings. Groups <i>G</i><sub>1</sub>, <i>G</i><sub>2</sub><i>,</i> with corresponding generators <i>g</i><sub>1</sub>, <i>g</i><sub>2</sub> of large prime order <i>o</i> of bit length /, are set up such that DLP is hard in <i>G</i><sub>1</sub><i>,G</i><sub>2</sub> Let E : <i>G</i><sub>1</sub> × <i>G</i><sub>2</sub> → <i>G<sub>T</sub></i> be a pairing, for which <maths id="math0493"><math display="inline"><msub><mo>∀</mo><mrow><mi>a</mi><mo>,</mo><mi>b</mi></mrow></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0505.tif" /></maths> : <maths id="math0494"><math display="inline"><mi>E</mi><mfenced><msubsup><mi>g</mi><mn>1</mn><mi>a</mi></msubsup><msubsup><mi>g</mi><mn>2</mn><mi>b</mi></msubsup></mfenced><mo>=</mo><mi>E</mi><msup><mfenced><msub><mi>g</mi><mn>1</mn></msub><msub><mi>g</mi><mn>2</mn></msub></mfenced><mi mathvariant="italic">ab</mi></msup></math><img file="EP4040713A1_D0506.tif" /></maths> and <i>E</i>(<i>g</i><sub>1</sub><i>, g</i><sub>2</sub>) generates <i>G<sub>T</sub>,</i> such that DLP is hard in <i>G<sub>T</sub>.</i> Let <i>n</i> ∈ <img file="EP4040713A1_D0507.tif" /> , let <i>i</i> range over [<i>n</i>]<i>,</i> and let <maths id="math0495"><math display="inline"><msub><mi>a</mi><mi>i</mi></msub><mo>∈</mo><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0508.tif" /></maths> be public.
0265For the commitment, Peter chooses secrets <i>r</i>, <maths id="math0496"><math display="inline"><mi>x</mi><msub><mo>∈</mo><mi>R</mi></msub><mspace width="1ex" /><msub><mi>ℤ</mi><mi>o</mi></msub></math><img file="EP4040713A1_D0509.tif" /></maths>, sets <maths id="math0497"><math display="inline"><mi>t</mi><mo>:</mo><mo>=</mo><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup></math><img file="EP4040713A1_D0510.tif" /></maths>, <maths id="math0498"><math display="inline"><mi>y</mi><mo>:</mo><mo>=</mo><msubsup><mi>g</mi><mn>2</mn><mi>x</mi></msubsup></math><img file="EP4040713A1_D0511.tif" /></maths>, <i>z</i> := <i>E</i>(<i>t, y</i>)<i>,</i> and posts <i>t, z.</i> This commits to <i>rx</i>/<i>a<sub>i</sub></i> mod <i>o</i> for <i>i</i> ∈ [<i>n]</i> and to <i>r</i>. For the openings, given <i>I</i> ⊆ [<i>n</i>], Peter reveals <maths id="math0499"><math display="inline"><msub><mi>y</mi><mi>i</mi></msub><mo>:</mo><mo>=</mo><msubsup><mi>g</mi><mn>2</mn><msub><mi>x</mi><mi>i</mi></msub></msubsup></math><img file="EP4040713A1_D0512.tif" /></maths> where <i>x<sub>i</sub></i> := <i>rx</i>/<i>a<sub>i</sub></i> mod <i>o</i> for <i>i</i> ∈ <i>I.</i> Victor verifies this opening by checking that <maths id="math0500"><math display="inline"><mi>E</mi><mfenced><msub><mi>g</mi><mn>1</mn></msub><msubsup><mi>y</mi><mi>i</mi><msub><mi>a</mi><mi>i</mi></msub></msubsup></mfenced><mo>=</mo><mi>z</mi></math><img file="EP4040713A1_D0513.tif" /></maths>. For verifiable communication of the openings, Peter verifiably communicates the DL of <i>t</i> to base <i>g</i><sub>1</sub>, namely r<i>,</i> and of <i>z</i> to base <i>E</i>(<i>g</i><sub>1</sub><i>, g</i><sub>2</sub>), namely <i>x'</i> := <i>rx</i> mod <i>o</i>, to Robert using available methods. Robert recovers <i>x</i> as <i>x'</i>/<i>r</i> mod <i>o</i> and, on commitment opening, <i>x<sub>i</sub></i> as <i>x'</i>/<i>a<sub>i</sub></i> mod <i>o</i> for <i>i</i> ∈ <i>I</i>.
0266This method may be enhanced as follows. It may be iterated, parallelized or distributed, in any order or incrementally, over the independent steps of <i>i</i>. Hash commitments <i>h</i>(<i>y<sub>i</sub></i>) may be used at the time of commitment and checked at the time of opening, using the revealed <i>y<sub>i</sub></i>, whence <i>h</i>(<i>y<sub>i</sub></i>) may be used to effectively limit <i>rx</i>/<i>a<sub>i</sub></i> mod <i>o</i> to one solution for a non-prime <i>o</i>. Random <i>a<sub>i</sub></i>, e.g. from a public random number generator such that one seed number suffices for recovering all <i>a<sub>i</sub></i>, may be used.
0267In the embodiments described here, unless explicitly stated otherwise, a message to-be-delivered may be identified with its possibly padded binary form and a corresponding number <i>M</i>. If <i>M</i> is no greater than the cardinality of the set <i>G</i> of a given embodiment, then <i>M</i> is identified with the <i>M</i>th element of <i>G</i>. Otherwise, standard techniques apply, including applying the system to each small enough part of the message, as well as using a hybrid cryptosystem where the present system is used for key encapsulation and a standard symmetric cryptosystem for data encapsulation. The same techniques apply if <i>M</i> is used in an exponent of a group generator and <i>M</i> is greater than the cardinality of the group.
0268In certain embodiments a well-known message is used. In this case, unless explicitly stated otherwise, the well-known message is identified with a number <i>Q</i> and the <i>Q</i>th element of <i>G</i> similarly. Other standard techniques apply for choosing the well-known message, including using a trusted party to choose it. For security of arguments, specifically <i>S</i>, the well-known message is chosen in an unpredictable manner only after the setup part is complete, such as by applying a cryptographic hash function to data including pk. Unless stated otherwise, a random choice means a draw with uniform probability from a set that is understood from the context.
0269In certain embodiments a traditional cryptographic protocol may be used to communicate a secret between users so that the secret is shared between the users. In this case, both traditional encryption and secret sharing methods may be used to establish such a shared secret. A challenge <i>c</i> to a communicating user includes an element in a specified set, not chosen or feasibly predictable by this user, derived from possibly random data, and provided by a user or a third-party. This definition includes challenges computed as a cryptographic hash function applied to data. The set <i>C</i>[<i>l</i>] is often used for challenges, where <i>C</i>[<i>l</i>] is a large enough range of large integers that is designed to ensure a challenge chosen from it effectively introduces sufficient randomization into formulas where the challenge appears. <i>C</i>[<i>l</i>] may be set to the range of integers having a leading 1 bit followed by <i>k</i> bits, for some <i>k</i> > log<sub>2</sub>(<i>l</i>), and (unless otherwise stated) <i>l</i> may be set to the group order <i>o</i> if the challenge provider knows <i>o</i> and otherwise to a number known to be significantly higher than <i>o</i>. Such a number can typically be determined. For example, for RSA, with public parameter <i>n, l</i> = <i>n</i> may be set.
0270In some embodiments described below c is inverted modulo <i>o</i>, and for this inversion to be well-defined, <i>c</i> must be co-prime to <i>o</i>. The probability c is not co-prime to <i>o</i> is extremely small, comparable to the probability of factoring <i>o</i> or of breaking the RSA cryptosystem simply by guessing a secret parameter. In some case, such as when elements of <i>C</i>[<i>l</i>] are operated on with XOR (⊕ notation), <i>C</i>[<i>l</i>] may be set to {1, 2,..., 2<i><sup>k</sup></i>}. It should be understood that protocols are intended to be followed if they would pass verification and otherwise may be aborted. In this description, DL stands for discrete-logarithm and DLP for discrete-logarithm problem.
0271Some embodiments here are constructed by using one cryptographic primitive for each of the arguments <i>S</i> and <i>T</i>. Each cryptographic primitive has its own advantages, which often carry over to the embodiment using it. As a first example, the Schnorr primitive used in some embodiments has the advantage of computational zero-knowledge, i.e. it is infeasible for a computationally bounded adversary to learn anything about <i>M</i>, under a standard assumption that DLP is hard in <i>G</i>. As a second example, the ElGamal primitive used in some embodiments has security advantages under the Decisional Diffie-Helman (DDH) assumption. In practice, selecting an embodiment to use, out of the many available ones, is often driven at least in part by such considerations.
0272Some embodiments here are constructed as interactive protocols. These protocols may be converted to non-interactive ones using well-known techniques, such as Fiat-Shamir transform and signatures of knowledge.
0273The description of each embodiment details explicit realizations of the system elements. These are <i>G</i>, sk, pk, <i>M, S, T.</i> Taken together, <i>S</i> and <i>T</i> verify the communication of <i>M</i>. Other embodiment-specific elements may also appear. Though the descriptions refer to "user <i>A</i>", "user <i>B</i>", or similar in singular form, that should not be interpreted to limit the number of parties playing the role of the described user.
0274Mathematical writing follows standard cryptography notation. Letters, possibly with primes, denote variables, so <i>A, A', A", a, a', a"</i> are distinct. Usually, small letters denote numbers or set elements and capital letters denote objects, pk and sk, possibly tuples, denote public and secret key respectively. Subscript denotes an index, which is part of a variable notation. Superscript denotes an exponent of a power. Curly braces denote a set description. Brackets denote indexing or dependencies, as will be understood from the context. Parentheses with commas denote a tuple or a function application as will be understood from the context. mod <i>n</i> denotes arithmetics modulo <i>n.</i> The notation <i>a</i>∥<i>b</i> denotes concatenation of string representations of <i>a</i> and <i>b</i>. The notation ∈<i><sub>R</sub></i> denotes drawing an element with uniform probability from a set. For <i>n</i> ∈ <img file="EP4040713A1_D0514.tif" /> , the notation [<i>n</i>] denotes the set {1,..., <i>n</i>}. Other symbols have standard mathematical interpretation.
0275Implementations of the various techniques described herein may be implemented in digital electronic circuitry, or in computer hardware, firmware, software, or in combinations of them. Implementations may implemented as a computer program product, i.e., a computer program tangibly embodied in an information carrier, e.g., in a machine readable storage device (computer-readable medium) for processing by, or to control the operation of, data processing apparatus, e.g., a programmable processor, a computer, or multiple computers. A computer program, such as the computer program(s) described above, can be written in any form of programming language, including compiled or interpreted languages, and can be deployed in any form, including as a stand alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program can be deployed to be processed on one computer or on multiple computers at one site or distributed across multiple sites and interconnected by a communication network.
0276Method steps may be performed by one or more programmable processors executing a computer program to perform functions by operating on input data and generating output. Method steps also may be performed by, and an apparatus may be implemented as, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application specific integrated circuit).
0277Processors suitable for the processing of a computer program include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer. Generally, a processor will receive instructions and data from a read only memory or a random access memory or both. Elements of a computer may include at least one processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer also may include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto optical disks, or optical disks. Information carriers suitable for embodying computer program instructions and data include all forms of non volatile memory, including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks, e.g., internal hard disks or removable disks; magneto optical disks; and CD ROM and DVD-ROM disks. The processor and the memory may be supplemented by, or incorporated in special purpose logic circuitry.
0278To provide for interaction with a user, implementations may be implemented on a computer having a display device, e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor, for displaying information to the user and a keyboard and a pointing device, e.g., a mouse or a trackball, by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including acoustic, speech, or tactile input.
0279Implementations may be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a client computer having a graphical user interface or a Web browser through which a user can interact with an implementation, or any combination of such back end, middleware, or front end components. Components may be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN) and a wide area network (WAN), e.g., the Internet.
0280While certain features of the described implementations have been illustrated as described herein, many modifications, substitutions, changes and equivalents will now occur to those skilled in the art. It is, therefore, to be understood that the appended claims are intended to cover all such modifications and changes as fall within the scope of the embodiments. It should be understood that they have been presented by way of example only, not limitation, and various changes in form and details may be made. Any portion of the apparatus and/or methods described herein may be combined in any combination, except mutually exclusive combinations. The embodiments described herein can include various combinations and/or sub-combinations of the functions, components and/or features of the different embodiments described.
Contents5
535 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84 Sheet 85 Sheet 86 Sheet 87 Sheet 88 Sheet 89 Sheet 90 Sheet 91 Sheet 92 Sheet 93 Sheet 94 Sheet 95 Sheet 96 Sheet 97 Sheet 98 Sheet 99 Sheet 100 Sheet 101 Sheet 102 Sheet 103 Sheet 104 Sheet 105 Sheet 106 Sheet 107 Sheet 108 Sheet 109 Sheet 110 Sheet 111 Sheet 112 Sheet 113 Sheet 114 Sheet 115 Sheet 116 Sheet 117 Sheet 118 Sheet 119 Sheet 120 Sheet 121 Sheet 122 Sheet 123 Sheet 124 Sheet 125 Sheet 126 Sheet 127 Sheet 128 Sheet 129 Sheet 130 Sheet 131 Sheet 132 Sheet 133 Sheet 134 Sheet 135 Sheet 136 Sheet 137 Sheet 138 Sheet 139 Sheet 140 Sheet 141 Sheet 142 Sheet 143 Sheet 144 Sheet 145 Sheet 146 Sheet 147 Sheet 148 Sheet 149 Sheet 150 Sheet 151 Sheet 152 Sheet 153 Sheet 154 Sheet 155 Sheet 156 Sheet 157 Sheet 158 Sheet 159 Sheet 160 Sheet 161 Sheet 162 Sheet 163 Sheet 164 Sheet 165 Sheet 166 Sheet 167 Sheet 168 Sheet 169 Sheet 170 Sheet 171 Sheet 172 Sheet 173 Sheet 174 Sheet 175 Sheet 176 Sheet 177 Sheet 178 Sheet 179 Sheet 180 Sheet 181 Sheet 182 Sheet 183 Sheet 184 Sheet 185 Sheet 186 Sheet 187 Sheet 188 Sheet 189 Sheet 190 Sheet 191 Sheet 192 Sheet 193 Sheet 194 Sheet 195 Sheet 196 Sheet 197 Sheet 198 Sheet 199 Sheet 200 Sheet 201 Sheet 202 Sheet 203 Sheet 204 Sheet 205 Sheet 206 Sheet 207 Sheet 208 Sheet 209 Sheet 210 Sheet 211 Sheet 212 Sheet 213 Sheet 214 Sheet 215 Sheet 216 Sheet 217 Sheet 218 Sheet 219 Sheet 220 Sheet 221 Sheet 222 Sheet 223 Sheet 224 Sheet 225 Sheet 226 Sheet 227 Sheet 228 Sheet 229 Sheet 230 Sheet 231 Sheet 232 Sheet 233 Sheet 234 Sheet 235 Sheet 236 Sheet 237 Sheet 238 Sheet 239 Sheet 240 Sheet 241 Sheet 242 Sheet 243 Sheet 244 Sheet 245 Sheet 246 Sheet 247 Sheet 248 Sheet 249 Sheet 250 Sheet 251 Sheet 252 Sheet 253 Sheet 254 Sheet 255 Sheet 256 Sheet 257 Sheet 258 Sheet 259 Sheet 260 Sheet 261 Sheet 262 Sheet 263 Sheet 264 Sheet 265 Sheet 266 Sheet 267 Sheet 268 Sheet 269 Sheet 270 Sheet 271 Sheet 272 Sheet 273 Sheet 274 Sheet 275 Sheet 276 Sheet 277 Sheet 278 Sheet 279 Sheet 280 Sheet 281 Sheet 282 Sheet 283 Sheet 284 Sheet 285 Sheet 286 Sheet 287 Sheet 288 Sheet 289 Sheet 290 Sheet 291 Sheet 292 Sheet 293 Sheet 294 Sheet 295 Sheet 296 Sheet 297 Sheet 298 Sheet 299 Sheet 300 Sheet 301 Sheet 302 Sheet 303 Sheet 304 Sheet 305 Sheet 306 Sheet 307 Sheet 308 Sheet 309 Sheet 310 Sheet 311 Sheet 312 Sheet 313 Sheet 314 Sheet 315 Sheet 316 Sheet 317 Sheet 318 Sheet 319 Sheet 320 Sheet 321 Sheet 322 Sheet 323 Sheet 324 Sheet 325 Sheet 326 Sheet 327 Sheet 328 Sheet 329 Sheet 330 Sheet 331 Sheet 332 Sheet 333 Sheet 334 Sheet 335 Sheet 336 Sheet 337 Sheet 338 Sheet 339 Sheet 340 Sheet 341 Sheet 342 Sheet 343 Sheet 344 Sheet 345 Sheet 346 Sheet 347 Sheet 348 Sheet 349 Sheet 350 Sheet 351 Sheet 352 Sheet 353 Sheet 354 Sheet 355 Sheet 356 Sheet 357 Sheet 358 Sheet 359 Sheet 360 Sheet 361 Sheet 362 Sheet 363 Sheet 364 Sheet 365 Sheet 366 Sheet 367 Sheet 368 Sheet 369 Sheet 370 Sheet 371 Sheet 372 Sheet 373 Sheet 374 Sheet 375 Sheet 376 Sheet 377 Sheet 378 Sheet 379 Sheet 380 Sheet 381 Sheet 382 Sheet 383 Sheet 384 Sheet 385 Sheet 386 Sheet 387 Sheet 388 Sheet 389 Sheet 390 Sheet 391 Sheet 392 Sheet 393 Sheet 394 Sheet 395 Sheet 396 Sheet 397 Sheet 398 Sheet 399 Sheet 400 Sheet 401 Sheet 402 Sheet 403 Sheet 404 Sheet 405 Sheet 406 Sheet 407 Sheet 408 Sheet 409 Sheet 410 Sheet 411 Sheet 412 Sheet 413 Sheet 414 Sheet 415 Sheet 416 Sheet 417 Sheet 418 Sheet 419 Sheet 420 Sheet 421 Sheet 422 Sheet 423 Sheet 424 Sheet 425 Sheet 426 Sheet 427 Sheet 428 Sheet 429 Sheet 430 Sheet 431 Sheet 432 Sheet 433 Sheet 434 Sheet 435 Sheet 436 Sheet 437 Sheet 438 Sheet 439 Sheet 440 Sheet 441 Sheet 442 Sheet 443 Sheet 444 Sheet 445 Sheet 446 Sheet 447 Sheet 448 Sheet 449 Sheet 450 Sheet 451 Sheet 452 Sheet 453 Sheet 454 Sheet 455 Sheet 456 Sheet 457 Sheet 458 Sheet 459 Sheet 460 Sheet 461 Sheet 462 Sheet 463 Sheet 464 Sheet 465 Sheet 466 Sheet 467 Sheet 468 Sheet 469 Sheet 470 Sheet 471 Sheet 472 Sheet 473 Sheet 474 Sheet 475 Sheet 476 Sheet 477 Sheet 478 Sheet 479 Sheet 480 Sheet 481 Sheet 482 Sheet 483 Sheet 484 Sheet 485 Sheet 486 Sheet 487 Sheet 488 Sheet 489 Sheet 490 Sheet 491 Sheet 492 Sheet 493 Sheet 494 Sheet 495 Sheet 496 Sheet 497 Sheet 498 Sheet 499 Sheet 500 Sheet 501 Sheet 502 Sheet 503 Sheet 504 Sheet 505 Sheet 506 Sheet 507 Sheet 508 Sheet 509 Sheet 510 Sheet 511 Sheet 512 Sheet 513 Sheet 514 Sheet 515 Sheet 516 Sheet 517 Sheet 518 Sheet 519 Sheet 520 Sheet 521 Sheet 522 Sheet 523 Sheet 524 Sheet 525 Sheet 526 Sheet 527 Sheet 528 Sheet 529 Sheet 530 Sheet 531 Sheet 532 Sheet 533 Sheet 534 Sheet 535
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2007235517A1 | Cites | United States of America | Search report |
| US2013339730A1 | Cites | United States of America | Applicant |
| US6396928B1 | Cites | United States of America | Search report |
14 members in 3 offices
Members14
| Document | Office | Kind | |
|---|---|---|---|
| US2017149796A1 | United States of America | A1 | |
| WO2017091801A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP3381151A1 | European Patent Office (EPO) | A1 | |
| EP3381151A4 | European Patent Office (EPO) | A4 | |
| US10791123B2 | United States of America | B2 | |
| EP3381151B1 | European Patent Office (EPO) | B1 | |
| US2021021606A1 | United States of America | A1 | |
| EP3783831A1 | European Patent Office (EPO) | A1 | |
| EP3783831B1 | European Patent Office (EPO) | B1 | |
| EP4040713A1This record | European Patent Office (EPO) | A1 | |
| US11558398B2 | United States of America | B2 | |
| US2023336567A1 | United States of America | A1 | |
| US12284191B2 | United States of America | B2 | |
| US2025267152A1 | United States of America | A1 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| First examination report despatched17Q | 17Q | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | |
| Request for examination filed17P | 17P | |
| Designated contracting states (corrected)RBV | RBV | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | |
| Divisional application: reference to earlier applicationAC | AC | |
| Divisional application: reference to earlier applicationAC | AC | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN PUBLISHEDSTAA | STAA |
Numbers
- Publication
- 4040713
- Application
- 221644156
Titles3
- German
- VERSCHLÜSSELUNGSGATEWAY-SYSTEM
- English
- CYPHER GATEWAY SYSTEM
- French
- SYSTÈME DE PASSERELLE DE CHIFFREMENT
Classification
- CPC, 5
- H04L63/123
- H04L9/085
- H04L9/3239
- H04L63/0428
- H04L9/0625
- IPC, 4
- H04L9 00
- H04L9 08
- H04L9 32
- H04L9 40
Designated states38
- Contracting states, 38
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
and 14 moreShow fewer
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye