Question: Non - interactive Commitment Scheme. [ 1 0 points ] Consider the following variant of Blum s commitment scheme introduced in the class: To commit
Noninteractive Commitment Scheme. points Consider the following
variant of Blums commitment scheme introduced in the class: To commit to a message m in
the committer samples a random seed s in n and sets the commitment string c as follows:
c
Gsn if m
Gsn if m
Intuitively, c is the stream cipher encryption of the message bit m using Gs as the key. It is well
known that PRGs cannot imply secure noninteractive commitment schemes. So which security
property among hiding and binding does not hold for the above variant of Blums scheme. Justify.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
