Module short_group_sig::weak_bb_sig_pok_kv
source · Expand description
Proofs of knowledge of weak-BB signature with keyed-verification, i.e. the verifier needs to know the secret key to verify the proof.
g1
is generator of group G1, secret key = x
, message = m
, signature = A = g1 * 1/(x + m)
- Prover chooses random
r
from Z_p. - Prover creates
A' = A * r
andA_bar = g1 * r - A' * m
. Note thatA_bar = A' * x
- Prover creates proof of knowledge
pi
, ofr
andm
inA_bar
and sendspi, A', A_bar
to the verifier. - Verifier checks if
A_bar = A' * x
and then verifies proofpi
Structs§
- Proof of knowledge of weak-BB signature in the keyed-verification model
- Protocol to prove knowledge of weak-BB signature in the keyed-verification model