Question: In the non - interactive version of Schnorr's protocol ( see ZK lecture - slide 4 2 ) the challenge is computed as c :

In the non-interactive version of Schnorr's protocol (see ZK lecture - slide 42) the challenge is computed as c := H(h||y), where y is the first message of the prover and
h the prover's public key. Let the variation with c := H(y), i.e. without including the public key of the prover. Prove that this version does not have the property
of correctness.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!