Question: Non - interactive Commitment Scheme. [ 1 0 points ] Consider the following variant of Blum s commitment scheme introduced in the class: To commit

Non-interactive Commitment Scheme. [10 points] Consider the following
variant of Blums commitment scheme introduced in the class: To commit to a message m in {0,1},
the committer samples a random seed s in {0,1}n and sets the commitment string c as follows:
c =
(
G(s)03n if m =0
G(s)13n if m =1.(1)
Intuitively, c is the stream cipher encryption of the message bit m using G(s) as the key. It is well-
known that PRGs cannot imply secure non-interactive commitment schemes. So, which security
property among hiding and binding does not hold for the above variant of Blums scheme. Justify.
3

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!