Zero-Knowledge Proofs and Proofs of Knowledge
1. Lecture 22: Interactive Proofs and Zero Knowledge
1.1. Languages, statements, witnesses, and NP relations
Before defining zero knowledge, the lecture introduced the language used to describe proof systems. A language is a set of strings
\[ L \subseteq \{0,1\}^{*}. \]
For a language in NP, there is a polynomial-time recognizable witness relation \(R_L\). The language can be written as
\[ L = \left\{ x : \exists w\text{ such that }|w|=\operatorname{poly}(|x|) \text{ and }R_L(x,w)=1 \right\}. \]
Here \(x\) is called the statement or problem instance, while \(w\) is a witness or solution. Membership in NP means that, once a suitable witness is given, its validity can be checked in polynomial time. It does not say that a witness can necessarily be found efficiently, nor does it imply that every problem in NP is hard.
For example, consider the language of semiprimes. A statement is an integer \(N\), a witness is a pair of primes \((p,q)\), and the relation verifies that
\[ N=pq. \]
Thus a claim such as ``\(N\) is a semiprime’’ can be checked efficiently when the factors are supplied. The number \(18=2\cdot 3\cdot 3\) is not a product of exactly two primes and is therefore not in this language. One may refine the language by requiring, for example, that \(p\) and \(q\) are both 1024-bit primes.
Another example is the language of quadratic residues:
\[ L_{\mathsf{QR}} = \left\{ (r,N):\exists y\in\mathbb Z_N^{*} \text{ such that }y^2=r\pmod N \right\}. \]
The statement is \((r,N)\), the witness is a square root \(y\), and the witness relation checks \(y^2=r\bmod N\).
Graph 3-colorability is another NP language. A witness assigns one of three colors to every vertex, and verification checks that the endpoints of every edge have different colors. The importance of this example will become clear in Lecture 23: 3-coloring is NP-complete, so a proof system for 3-coloring can be combined with reductions to obtain proof systems for all NP languages.
The relation may be viewed either mathematically, as a set of valid pairs \((x,w)\), or algorithmically, as a polynomial-time verification procedure. The latter viewpoint is especially convenient in cryptography.
The language of prime numbers is a useful contrast. Primality itself can be decided in polynomial time, so a verifier can check such a statement without help. This reinforces that languages and proof systems are not restricted to problems believed to be hard; a proof may also be used to reduce the work done by a resource-constrained verifier.
1.2. Why proofs are useful
Proofs are useful in at least two rather different situations.
First, the verifier may be unable to find the witness itself. For an RSA modulus, for example, the prover may know the factorization while the verifier is assumed to be unable to compute it. A proof can convince the verifier that the modulus was generated in the desired form.
Second, the underlying computation may be possible for the verifier but too expensive in a particular setting. A cryptocurrency light client on a mobile device could in principle check a large collection of transactions and signatures one by one. Instead, another party may perform the full computation and provide a short proof that the result is valid. The light client verifies the short proof rather than repeating the entire computation. This is the motivation from verifiable computation: a witness need not be secret for a proof to be useful.
1.3. Interactive proof systems
A pair of algorithms \((P,V)\) is an interactive proof system for a language \(L\) when the verifier \(V\) runs in polynomial time and the following properties hold.
1.3.1. Completeness
For every true statement \(x\in L\), an honest prover convinces the honest verifier with high probability:
\[ \Pr[\langle P,V\rangle(x)=1]\geq \frac{2}{3}. \]
Modern presentations often give protocols with perfect completeness, meaning that this probability is \(1\).
1.3.2. Soundness
For every false statement \(x\notin L\) and every potentially malicious prover \(P^{*}\),
\[ \Pr[\langle P^{*},V\rangle(x)=1]\leq \frac{1}{3}. \]
The verifier is required to remain safe even against a computationally unbounded prover. This models the strong requirement that no amount of computing power should let a prover establish a false mathematical statement.
The constants \(2/3\) and \(1/3\) are conventional rather than fundamental. They merely give a constant gap between completeness and soundness. Repetition can amplify this gap and reduce the soundness error to a negligible value.
1.4. The trivial proof for an NP language and its limitations
Since the prover in the definition may be unbounded, it can search for a witness and send the witness directly. The verifier then runs \(R_L(x,w)\). This immediately shows that every NP language has an interactive proof, even a one-message proof.
In practical protocols, the prover is not really unbounded; it is normally assumed to possess the witness already. More importantly, sending the witness reveals it. For quadratic residuosity it reveals \(y\), and for a semiprime it reveals \((p,q)\).
Revealing the factors of an RSA modulus would destroy the cryptosystem. Given \(N=pq\), the verifier could compute
\[ \varphi(N)=(p-1)(q-1) \]
and recover the secret exponent
\[ d=e^{-1}\pmod{\varphi(N)}. \]
The goal is therefore to prove that a statement is true without disclosing the witness or any other unintended information.
The formal study of zero-knowledge proofs was initiated by Shafi Goldwasser, Silvio Micali, and Charles Rackoff. Interaction is the feature that makes it possible to gain confidence in a statement while avoiding the direct witness transmission used by the trivial NP proof.
1.5. The intuition of zero knowledge: Ali Baba’s cave
The lecture used the standard cave example. A cave has two paths, \(A\) and \(B\), connected by a locked door. Alice claims to know the PIN for the door but does not want to reveal the PIN to Bob.
Alice enters the cave and secretly chooses one path. Bob then asks her to return through either \(A\) or \(B\), chosen uniformly at random. If Alice knows the PIN, she can always obey: when necessary, she opens the door and crosses to the requested side. Completeness is therefore \(1\).
If Alice does not know the PIN, she can answer only when Bob happens to request the path she originally chose. Her success probability in one round is \(1/2\). Repeating the experiment twice lowers it to \(1/4\), and repeating it \(k\) times lowers it to \(2^{-k}\).
The example conveys the main idea: Bob gains confidence that Alice knows how to open the door, but the PIN itself is never sent. The formal definition must say more, however, because a malicious verifier might deviate from the stated procedure in an attempt to obtain additional information.
1.6. Computational zero knowledge
Let \((P,V)\) be an interactive proof system for \(L\). It is computational zero knowledge if, for every probabilistic polynomial-time verifier \(V^{*}\), there exists a probabilistic polynomial-time simulator \(\mathsf{SIM}\) such that
\[ \left\{ \mathsf{view}^{P}_{V^{*}}(x) \right\}_{x\in L} \;\approx_c\; \left\{ \mathsf{SIM}^{V^{*}}(x) \right\}_{x\in L}. \]
The real view includes the verifier’s randomness, the messages it receives, and its final output. The simulator receives the statement \(x\), but not the witness. Its output must nevertheless be computationally indistinguishable from the verifier’s view of a real interaction.
This formalizes the assertion that the verifier learns nothing beyond the truth of the statement. Anything efficiently obtainable from a real interaction could instead be generated from the public statement alone. In particular, the verifier does not need access to the witness-holder to obtain that information.
The simulator is not an ordinary online prover. It runs \(V^{*}\) internally and may use proof techniques such as restarting or rewinding it. Consequently, the existence of a simulator does not violate soundness: the simulator is not an external party that convinces an independently running verifier about a false statement.
The quantification covers malicious verifiers. Formally, for every \(V^{*}\) there must be a suitable efficient simulator; equivalently, one often gives a generic simulator construction with black-box access to \(V^{*}\).
1.6.1. Honest-verifier zero knowledge
Honest-verifier zero knowledge (HVZK) is weaker. It requires simulation only for the prescribed verifier, which samples its randomness and sends its messages exactly as the protocol specifies. A protocol may be HVZK and still leak information to a verifier that deliberately sends a malformed or correlated challenge.
1.7. A zero-knowledge proof for quadratic residuosity
Let the common statement be \((r,N)\), and suppose the prover knows \(y\in\mathbb Z_N^{*}\) satisfying
\[ y^2=r\pmod N. \]
One execution of the protocol is as follows.
- The prover samples \(t\xleftarrow{\$}\mathbb Z_N^{*}\), computes \[ s=t^2\pmod N, \] and sends \(s\).
- The verifier samples a challenge bit \[ b\xleftarrow{\$}\{0,1\} \] and sends \(b\).
- The prover computes \[ z=t\,y^b\pmod N \] and sends \(z\).
- The verifier accepts exactly when \[ z^2=s\,r^b\pmod N. \]
The first message \(s\) is often called a commitment in the three-message structure, although it should not be confused with the general commitment primitive introduced in Lecture 23.
1.7.1. Completeness
If \(b=0\), then \(z=t\), and
\[ z^2=t^2=s=s r^0\pmod N. \]
If \(b=1\), then \(z=ty\), and
\[ z^2=t^2y^2=sr\pmod N. \]
Thus an honest prover with a valid witness is accepted for either challenge, so completeness is perfect.
1.7.2. Soundness and the one-half cheating probability
A prover without a square root can prepare a first message that answers one chosen challenge, but it cannot answer both challenges for the same \(s\). To see the latter fact, suppose there were accepting responses \(z_0,z_1\) for \(b=0\) and \(b=1\). Then
\[ z_0^2=s, \qquad z_1^2=sr, \]
so
\[ \left(z_1z_0^{-1}\right)^2=r\pmod N. \]
The ratio \(z_1z_0^{-1}\) would be a witness, contradicting the assumption that the statement is false.
The lecture also gave the two explicit one-challenge strategies. To prepare for \(b=0\), choose \(t\), send \(s=t^2\), and later answer \(z=t\). To prepare for \(b=1\), choose \(t\), send
\[ s=t^2r^{-1}\pmod N, \]
and later answer \(z=t\). In the latter case,
\[ z^2=t^2=sr\pmod N. \]
Since the prover must guess the verifier’s bit before sending \(s\), its best success probability is \(1/2\). This is larger than the conventional \(1/3\) soundness bound and is far from negligible, so repetition is needed.
1.7.3. The simulator and full zero knowledge
The simulator has only \((r,N)\) and black-box access to an arbitrary verifier \(V^{*}\). It proceeds as follows.
- Guess \(\hat b\xleftarrow{\$}\{0,1\}\) and choose \(t\xleftarrow{\$}\mathbb Z_N^{*}\).
- If \(\hat b=0\), set \(s=t^2\bmod N\). If \(\hat b=1\), set \[ s=t^2r^{-1}\pmod N. \]
- Run \(V^{*}\) on first message \(s\) and obtain its challenge \(b\). If \(b\neq\hat b\), rewind or restart \(V^{*}\) and try again.
- When \(b=\hat b\), set \(z=t\) and output the transcript \((s,b,z)\) together with the corresponding verifier view.
The two distributions used for \(s\) are the same on a true statement because \(r=y^2\):
\[ t^2r^{-1}=(ty^{-1})^2\pmod N, \]
and multiplication by \(y^{-1}\) permutes \(\mathbb Z_N^{*}\). Hence the guessed bit is hidden from \(V^{*}\), and the probability of a matching challenge is \(1/2\). The simulator therefore needs two attempts in expectation and remains polynomial-time. Its successful transcript has the same distribution as an accepting real transcript.
This proof illustrates why rewinding is legitimate in a simulation even though a real network client could not erase a failed interaction from an external server’s memory.
1.8. Soundness amplification: parallel versus sequential repetition
Running \(n\) copies in parallel sends \((s_1,\ldots,s_n)\), receives one challenge vector \((b_1,\ldots,b_n)\), and returns \((z_1,\ldots,z_n)\). It keeps the number of message rounds unchanged and reduces the soundness error to
\[ \left(\frac12\right)^n. \]
For the simulator just described, however, parallel repetition is problematic. It must guess the entire challenge vector in advance. Its chance of success per attempt is \(2^{-n}\), so it needs \(2^n\) attempts in expectation. When \(n\) grows with the security parameter, this simulator is not polynomial-time. Thus the simple zero-knowledge argument does not survive parallel repetition; parallel amplification requires additional care.
Sequential repetition also gives soundness error \(2^{-n}\), but it increases the number of rounds by a factor of \(n\). Its advantage is that each execution can be simulated separately. Each round costs only two attempts in expectation, so all \(n\) executions cost \(O(n)\) expected attempts and zero knowledge is preserved by this sequential composition.
1.9. Why honest-verifier zero knowledge is weaker
The lecture modified the protocol so that the honest verifier still samples \(b\in\{0,1\}\), but the prover is instructed to send the witness \(y\) if it ever receives \(b=-1\). An honest verifier never sends \(-1\), so its view is unchanged and the protocol retains HVZK. A malicious verifier can send \(b=-1\) and immediately learn \(y\). The protocol is therefore not zero knowledge against arbitrary verifiers.
This artificial example captures the exact distinction: full zero knowledge must handle every verifier behavior, including challenges outside the honest distribution. Merely enlarging a challenge set also does not automatically improve soundness; the protocol equations and response rules must be designed for that larger set.
2. Lecture 23: Commitment Schemes and Zero Knowledge for 3-Coloring
2.1. From an NP-complete problem to proofs for all NP
The lecture first recalled that NP contains problems whose proposed solutions are efficiently verifiable. Membership in NP alone does not assert hardness. An NP-complete problem is, informally, one of the hardest problems in NP: every other NP problem can be reduced to it in polynomial time.
Graph 3-colorability is NP-complete. Therefore, once a zero-knowledge proof is constructed for 3-coloring, reductions let one prove arbitrary NP statements in zero knowledge. The construction needs a cryptographic commitment scheme, so the resulting general theorem is understood under the assumptions needed to build such commitments.
2.2. Commitment schemes: the locked-box intuition
A commitment is the digital analogue of placing a message in a locked box and handing the box to somebody else. Before opening, the receiver should not learn the message. After handing over the box, the sender should not be able to replace its contents.
At a later point, the sender reveals the message and opening information. The receiver checks that this message is exactly what was committed earlier. This separation creates two phases:
- the commit phase, in which the sender fixes a hidden value; and
- the open phase, in which the sender reveals and proves that value.
Two motivating applications were mentioned. A person may commit today to a prediction about 2027 and open it in 2028, demonstrating that the prediction was fixed in advance. Commitments also enable coin tossing over a network: one party commits to a random bit \(a\), the other announces a bit \(b\), the first opens \(a\), and the outcome is \(a\oplus b\). Neither party can choose its bit after learning the other’s bit.
2.3. Syntax and correctness
A commitment scheme consists of three probabilistic polynomial-time algorithms
\[ (\mathsf{Setup},\mathsf{Commit},\mathsf{Open}). \]
The setup algorithm produces a commitment key:
\[ ck\xleftarrow{\$}\mathsf{Setup}(1^\lambda). \]
Commitment is randomized and returns both a public commitment and private opening information:
\[ (c,o)\xleftarrow{\$}\mathsf{Commit}(ck,m). \]
Opening is deterministic:
\[ \mathsf{Open}(ck,c,m,o)\in\{0,1\}. \]
Correctness requires that an honestly produced commitment always opens to its original message:
\[ \Pr\left[ \mathsf{Open}(ck,c,m,o)=1 \right]=1. \]
Randomization normally means that two commitments to the same message need not be identical and usually use different opening information.
2.4. Binding
Binding protects the receiver against a sender who changes its mind. In the binding experiment, the challenger generates \(ck\), and the adversary returns
\[ (c,m_0,o_0,m_1,o_1), \qquad m_0\neq m_1. \]
The adversary wins if the same commitment opens successfully in both ways:
\[ \mathsf{Open}(ck,c,m_0,o_0)=1 \quad\text{and}\quad \mathsf{Open}(ck,c,m_1,o_1)=1. \]
A scheme is computationally binding if every PPT adversary wins with only negligible probability. It is perfectly binding if even an unbounded adversary has probability zero of producing two different valid openings. Changing even one bit of the committed message counts as a binding violation.
An encryption ciphertext gives useful intuition. Treat encryption randomness as opening information and verify an opening by recomputing the ciphertext. With perfect decryption correctness, one ciphertext cannot decrypt to two different messages, so the construction is perfectly binding. Its hiding is normally only computational and follows from encryption security.
2.5. Hiding
Hiding protects the sender. Its experiment resembles IND-CPA security.
- The challenger generates \(ck\) and a random bit \(b\xleftarrow{\$}\{0,1\}\).
- The adversary submits equal-length messages \(m_0,m_1\).
- The challenger computes \[ (c^{*},o^{*})\xleftarrow{\$}\mathsf{Commit}(ck,m_b) \] and sends only \(c^{*}\). The opening information \(o^{*}\) must remain secret, since otherwise the adversary could simply test an opening.
- The adversary outputs a guess \(b'\).
The scheme is computationally hiding if
\[ \left| \Pr[b'=b]-\frac12 \right| \]
is negligible for every PPT adversary. It is perfectly hiding if the advantage is exactly zero even for an unbounded adversary.
Perfect binding and perfect hiding cannot both hold for a nontrivial commitment scheme. Informally, perfect hiding requires the commitment distributions for different messages to overlap completely, whereas perfect binding says that a commitment cannot possess valid openings to two different messages. One may choose which property should be information-theoretic and which should rely on computational hardness.
This distinction matters for long-term security. If secrecy must survive future advances in computing, perfect hiding is attractive. If the main risk is that the committer may later obtain vastly greater computing power and change the committed value, perfect binding may be preferable.
2.6. The Pedersen commitment scheme
Let \(\mathbb G\) be a cyclic group of prime order \(p\approx 2^\lambda\) with generator \(g\). Setup chooses a nonzero
\[ x\xleftarrow{\$}\mathbb Z_p^{*} \]
and defines
\[ h=g^x. \]
The commitment key is
\[ ck=(g,h), \]
together with the description of \(\mathbb G\) and its order. The discrete logarithm \(x=\log_g h\) must not be known to the committer.
To commit to \(m\in\mathbb Z_p\), choose fresh opening randomness
\[ o\xleftarrow{\$}\mathbb Z_p \]
and compute
\[ c=g^m h^o. \]
To open, reveal \((m,o)\); the receiver accepts exactly when
\[ c=g^m h^o. \]
Writing \(h=g^x\) gives the useful exponent representation
\[ c=g^{m+xo}. \]
2.6.1. Relation to ElGamal ciphertexts
If exponent-encoded ElGamal encrypts \(g^m\) using randomness \(o\), the ciphertext is
\[ (g^o,h^o g^m). \]
The second component alone is exactly the Pedersen commitment \(g^m h^o\). The full ElGamal ciphertext is perfectly binding but only computationally hiding, whereas discarding its first component produces the dual behavior: Pedersen commitments are perfectly hiding but only computationally binding.
2.6.2. Who generates the commitment key?
The committer must not choose \(h=g^x\) while retaining \(x\). If it knows \(x\), then from one opening \((m_0,o_0)\) it can choose another message \(m_1\) and solve
\[ m_0+xo_0=m_1+xo_1\pmod p \]
for \(o_1\), thereby opening the same commitment to \(m_1\).
The key may instead be generated by a trusted party or by a transparent setup. For a transparent setup, all parties agree on a deterministic hash-to-group procedure, for example
\[ h=H_{\mathbb G}(1). \]
If the hash output behaves like a random group element, nobody knows \(\log_g h\). This avoids both a trusted setup ceremony and the possibility that the committer selected a trapdoor. The lecture compared this with costly multi-party setup ceremonies in which participants generate parameters and destroy the machines or secrets used during the ceremony.
2.6.3. Computational binding under discrete-logarithm hardness
Assume an adversary finds two openings of the same commitment:
\[ g^{m_0}h^{o_0}=c=g^{m_1}h^{o_1}, \qquad m_0\neq m_1. \]
Substituting \(h=g^x\) gives
\[ m_0+xo_0=m_1+xo_1\pmod p. \]
Therefore,
\[ x=(m_0-m_1)(o_1-o_0)^{-1}\pmod p. \]
The denominator is nonzero: if \(o_0=o_1\), the equality would imply \(m_0=m_1\). A reduction given a discrete-log challenge \((g,h=g^x)\) can use it as the commitment key, run the binding adversary, and recover \(x\) from the adversary’s two openings. Thus breaking binding would solve the discrete logarithm problem.
2.6.4. Perfect hiding
For a fixed message \(m\),
\[ c=g^{m+xo}. \]
Because \(x\neq 0\), the map
\[ o\longmapsto m+xo\pmod p \]
is a permutation of \(\mathbb Z_p\). Uniform \(o\) therefore makes \(c\) uniform in \(\mathbb G\), independently of \(m\). Commitments to any two messages have exactly the same distribution.
Equivalently, for every commitment \(c\) and every candidate message \(m'\), there exists opening information \(o'\) satisfying
\[ c=g^{m'}h^{o'}. \]
Someone who knows \(x\) can compute such alternate openings, but the openings exist whether or not anybody can find them. Since the hiding experiment never reveals \(o\), the commitment alone contains no information that selects one message over another. This is why the hiding property is perfect even though the binding property is only computational.
2.7. Zero knowledge for graph 3-coloring
Let
\[ G=(V,E) \]
be a graph. A valid witness is a coloring
\[ \pi:V\longrightarrow\{0,1,2\} \]
such that
\[ \pi(a)\neq\pi(b) \qquad\text{for every }(a,b)\in E. \]
The prover wants to convince the verifier that such a coloring exists without revealing the coloring. Coloring an \(n\)-vertex graph with \(n\) available colors is trivial because every vertex can receive its own color. Restricting the palette to three colors makes the general problem NP-complete. For example, the complete graph on four vertices cannot be 3-colored, because every pair of vertices is joined and all four vertices would need different colors.
2.7.1. One protocol iteration
- The prover chooses a uniformly random permutation \[ \sigma:\{0,1,2\}\longrightarrow\{0,1,2\} \] and defines the permuted coloring \[ \phi(v)=\sigma(\pi(v)). \] It commits separately to \(\phi(v)\) for every \(v\in V\) and sends all commitments to the verifier.
- The verifier chooses a uniformly random edge \[ e=(a,b)\xleftarrow{\$}E \] and sends it as the challenge.
- The prover reveals \(\phi(a),\phi(b)\) and the opening information for the two corresponding commitments.
- The verifier checks both openings and verifies \[ \phi(a)\neq\phi(b). \] It rejects if an opening is invalid or the two colors are equal.
Fresh commitments and a fresh random color permutation are generated in every iteration. Although the verifier learns two permuted colors, it learns only that they differ. It cannot infer the original color names because the random permutation changes them from one iteration to the next.
2.7.2. Completeness
If \(\pi\) is a valid coloring, every edge has differently colored endpoints. A permutation preserves inequality, honest commitments open correctly, and the verifier accepts every iteration.
2.7.3. Soundness
Suppose the graph is not 3-colorable. Once the prover sends perfectly binding commitments, it is fixed to some assignment of three colors. Every such assignment has at least one bad edge whose endpoints share a color. A uniformly chosen edge catches the prover with probability at least
\[ \frac{1}{|E|}\geq\frac{1}{n^2}, \qquad n=|V|. \]
Consequently, one iteration is accepted with probability at most
\[ 1-\frac{1}{n^2}. \]
After \(k\) independent sequential iterations, the acceptance probability is bounded by
\[ \left(1-\frac{1}{n^2}\right)^k \leq e^{-k/n^2}, \]
using \(1+x\leq e^x\). Choosing \(k\approx n^3\) gives
\[ e^{-k/n^2}\approx e^{-n}, \]
which is negligible as the graph size grows with the security parameter.
Perfect binding is important for this information-theoretic soundness argument: the prover must not be able to wait for the challenged edge and then change the colors hidden in its commitments. This is why the lecture suggested using an encryption-based commitment with perfect binding and computational hiding rather than Pedersen’s perfectly hiding, computationally binding commitment when the classical soundness definition quantifies over unbounded provers.
2.7.4. Zero-knowledge simulation
For one iteration, a simulator with black-box access to \(V^{*}\) works as follows.
- Guess an edge \(\hat e=(a,b)\in E\).
- Choose a uniformly random ordered pair of different colors for \(a\) and \(b\), and commit honestly to them.
- Commit to arbitrary dummy values, such as \(0\), for every other vertex.
- Give all commitments to \(V^{*}\) and obtain its challenged edge \(e'\).
- If \(e'\neq\hat e\), rewind and try again. If \(e'=\hat e\), open the two commitments and output the resulting verifier view.
In a real interaction, a random permutation maps the two distinct endpoint colors to a uniformly random ordered pair of distinct colors. The simulator creates exactly that distribution on the opened edge. Commitments on unopened vertices can be replaced by commitments to dummy values because hiding makes the two collections computationally indistinguishable.
The probability of guessing the challenged edge is \(1/|E|\), so the expected number of attempts is \(|E|\leq n^2\), which is polynomial. The protocol is repeated sequentially \(k\approx n^3\) times; simulating each iteration in sequence still takes polynomial expected time. Thus the complete repeated protocol is computational zero knowledge when the commitments are computationally hiding. With perfectly hiding commitments, the analogous simulation can give perfect rather than merely computational indistinguishability, but then the corresponding binding and soundness guarantees must be adjusted.
This construction establishes the central result of the lecture: under the commitment assumption, every language in NP has a zero-knowledge proof.
2.8. Proofs versus proofs of knowledge
The lecture ended by previewing a stronger notion. Soundness says that a prover cannot establish a false statement. It does not itself say that a successful prover knows a witness.
For 3-coloring, an ordinary proof establishes that a valid coloring exists. A proof of knowledge additionally formalizes that a prover who convinces the verifier must know such a coloring. The distinction becomes even clearer for discrete logarithms. If \(g\) generates \(\mathbb G\), every \(h\in\mathbb G\) has some exponent \(x\) satisfying \(h=g^x\), so language membership is automatic. The meaningful claim is that the prover knows the exponent.
3. Lecture 24: Proofs of Knowledge, Fiat–Shamir, and Proof Composition
3.1. The proof-of-knowledge definition
Let \(R_L\) be an NP relation. An interactive proof \((P,V)\) is a proof of knowledge if there exists an efficient extractor \(E\) such that, for every statement \(x\) and every prover \(P^{*}\),
\[ \Pr\left[ w\xleftarrow{\$}E^{P^{*}}(x):R_L(x,w)=1 \right] \geq \Pr[\langle P^{*},V\rangle(x)=1]-\varepsilon. \]
The value \(\varepsilon\) is the knowledge error. Ideally it is negligible. The definition says that whenever a prover convinces the verifier with some noticeable probability, an efficient extractor with black-box access to that prover can recover a valid witness with almost the same probability.
The extractor, like a zero-knowledge simulator, is a conceptual algorithm used in the security argument. It may run and rewind a prover implementation. This does not mean that a user can necessarily rewind a sealed hardware device in the physical world. Rather, the existence of the extractor demonstrates that the prover algorithm must contain enough information to determine a witness. The extractor must be efficient; otherwise it could simply ignore the prover and solve the underlying hard problem by exhaustive search.
Knowledge is strictly stronger than soundness. Soundness rules out convincing proofs of false statements. Knowledge extraction additionally covers settings where every statement is true but possessing a witness is nontrivial.
For example, in a prime-order cyclic group generated by \(g\), consider
\[ L=\left\{h\in\mathbb G:\exists x\in\mathbb Z_p, h=g^x\right\}. \]
Every group element lies in \(L\), so an ordinary membership proof says nothing. A proof of knowledge of \(x\) establishes possession of the secret key associated with public key \(h\).
3.2. Schnorr identification as a proof of knowledge
Let \(\mathbb G\) have prime order \(p\), let \(g\) be a generator, and let
\[ h=g^x \]
be the statement whose discrete logarithm \(x\) the prover claims to know. The Schnorr protocol is
- The prover samples \(k\xleftarrow{\$}\mathbb Z_p\), computes \[ I=g^k, \] and sends \(I\).
- The verifier samples \(r\xleftarrow{\$}\mathbb Z_p\) and sends \(r\).
- The prover returns \[ s=k+rx\pmod p. \]
- The verifier accepts if \[ g^s h^{-r}=I. \]
3.2.1. Completeness
For an honest prover,
\[ g^s h^{-r} =g^{k+rx}(g^x)^{-r} =g^k =I. \]
3.2.2. Extraction by rewinding
The extractor first runs \(P^{*}\) until it receives a commitment \(I\). It then obtains one accepting transcript
\[ (I,r_1,s_1). \]
It rewinds the prover to the point immediately after the same \(I\) was fixed, sends a different challenge \(r_2\neq r_1\), and obtains another accepting transcript
\[ (I,r_2,s_2). \]
Both transcripts satisfy
\[ s_1=k+r_1x\pmod p, \qquad s_2=k+r_2x\pmod p. \]
Subtracting eliminates \(k\):
\[ s_1-s_2=(r_1-r_2)x\pmod p. \]
Because \(p\) is prime and \(r_1\neq r_2\), the difference is invertible, and the extractor recovers
\[ x=(s_1-s_2)(r_1-r_2)^{-1}\pmod p. \]
This two-transcript property is often called special soundness. A prover that knows \(x\) can answer every challenge. A prover that can prepare an answer for only one guessed challenge succeeds with probability \(1/p\), which explains the natural knowledge-error term for the full \(\mathbb Z_p\) challenge space. When a prover succeeds noticeably more often, rewinding and trying fresh challenges yields two accepting transcripts efficiently.
3.3. Honest-verifier zero knowledge of Schnorr
An HVZK simulator chooses
\[ r,s\xleftarrow{\$}\mathbb Z_p \]
and defines
\[ I=g^s h^{-r}. \]
It outputs \((I,r,s)\). This transcript always verifies, and its distribution is identical to a real transcript. In a real execution, \(k,r\) are uniform and \(s=k+rx\); for each fixed \(r\), adding \(rx\) is a permutation of \(\mathbb Z_p\), so \(s\) remains uniform.
This simulator does not need to run the honest verifier internally because it already knows that the verifier samples \(r\) uniformly as prescribed.
3.4. Why the interactive Schnorr protocol is not full zero knowledge
A malicious verifier need not choose \(r\) uniformly. After seeing \(I\), it can choose
\[ r=H(I\mathbin\Vert m) \]
for a message \(m\). The prover’s response
\[ s=k+rx\pmod p \]
then forms a Schnorr signature \((r,s)\) on \(m\). A valid signature is additional information that the verifier could not generate by itself without the secret key. Therefore the interaction is not zero knowledge against every malicious verifier.
The guess-and-rewind method from the quadratic-residuosity protocol does not solve this problem. There the challenge space had size two, so a simulator guessed correctly with probability \(1/2\). Schnorr’s challenge space has size \(p\approx 2^\lambda\), so guessing the verifier’s chosen challenge would take about \(p\) attempts, which is exponential. This is why the protocol provides HVZK rather than full interactive zero knowledge.
3.5. Fiat–Shamir and non-interactive proofs
Fiat–Shamir removes the verifier’s random challenge by deriving it from a random oracle. For Schnorr, the prover computes
\[ k\xleftarrow{\$}\mathbb Z_p, \qquad I=g^k, \qquad r=H(I\mathbin\Vert h\mathbin\Vert\mathsf{context}), \qquad s=k+rx\pmod p. \]
Hashing the entire statement and the relevant context binds the proof to the claim for which it was produced. The prover can send the compressed proof
\[ \pi=(r,s). \]
The verifier reconstructs
\[ I'=g^s h^{-r} \]
and accepts if
\[ r=H(I'\mathbin\Vert h\mathbin\Vert\mathsf{context}). \]
Thus a Schnorr signature is also a non-interactive proof of knowledge of the secret exponent, with the signed message included in the context. Signature unforgeability alone did not explicitly say that a signer knows the secret key; the proof-of-knowledge interpretation supplies that stronger statement for this construction in the random-oracle model.
The transformation applies to the public-coin three-message proofs discussed in the lectures: the verifier’s challenge is public randomness and verification uses no verifier secret. It cannot be applied blindly when the verifier uses a secret. For example, if the verifier supplies an encryption public key and the prover encrypts its response, only the verifier can decrypt and determine acceptance. An outside observer cannot publicly verify the transcript, so the simple Fiat–Shamir replacement is not available.
For 3-coloring, the non-interactive version commits to all vertex colors and hashes the commitments and statement to derive the edge challenge. The proof then includes openings for the derived edge. Appropriate repetition yields a non-interactive proof for 3-coloring, and reductions extend the idea to NP. More efficient general-purpose non-interactive zero-knowledge systems also exist.
In the random-oracle model, the simulator can program the oracle, so the Fiat–Shamir version can obtain full zero knowledge rather than merely HVZK. This guarantee is model-dependent. Real implementations instantiate the oracle with SHA-2, SHA-3, or another concrete hash function. There are deliberately contrived schemes that are secure with an ideal random oracle but insecure under a particular concrete instantiation. Such examples show that the random- oracle proof is meaningful evidence, but not an unconditional proof about every real hash function.
3.6. Proof of equality of discrete logarithms
Suppose
\[ h_1=g_1^x, \qquad h_2=g_2^x, \]
where \(g_1\) and \(g_2\) are group generators or suitable group elements. The prover wants to show that the same exponent \(x\) relates both pairs, without revealing \(x\). This is often called a proof of discrete-logarithm equality or a Chaum–Pedersen proof.
The interactive protocol is
- Choose \(k\xleftarrow{\$}\mathbb Z_p\) and send \[ I_1=g_1^k, \qquad I_2=g_2^k. \]
- Receive \(r\xleftarrow{\$}\mathbb Z_p\).
- Return \[ s=k+rx\pmod p. \]
- The verifier checks \[ g_1^s h_1^{-r}=I_1 \quad\text{and}\quad g_2^s h_2^{-r}=I_2. \]
The same nonce \(k\), challenge \(r\), and response \(s\) are used in both equations. This coupling proves that the exponent is shared.
After Fiat–Shamir, the prover may again send only \((r,s)\). The verifier computes
\[ I_1'=g_1^s h_1^{-r}, \qquad I_2'=g_2^s h_2^{-r} \]
and checks
\[ r=H(I_1'\mathbin\Vert I_2'\mathbin\Vert g_1\mathbin\Vert g_2\mathbin\Vert h_1\mathbin\Vert h_2). \]
Even if the statement contains many pairs \((g_i,h_i)\), the proof can still contain only the two scalars \((r,s)\); the verifier reconstructs all commitments. The statement itself must of course still contain the group elements.
3.6.1. Proving that a tuple is Diffie–Hellman
For a tuple
\[ (g,g^a,g^b,g^{ab}), \]
set
\[ g_1=g, \quad h_1=g^a, \quad g_2=g^b, \quad h_2=g^{ab}. \]
Both pairs have the same exponent \(x=a\):
\[ h_1=g_1^a, \qquad h_2=g_2^a. \]
A discrete-logarithm equality proof therefore demonstrates that the fourth element has the correct Diffie–Hellman relation without revealing \(a\) or \(b\).
3.7. OR composition
Let
\[ h_0=g^{x_0}, \qquad h_1=g^{x_1}. \]
The prover knows \(x_b\) for one hidden index \(b\in\{0,1\}\) and wants to prove
\[ \text{``I know }x_0\text{ or I know }x_1\text{''} \]
without revealing which witness it knows.
For the unknown branch \(1-b\), the prover runs the HVZK simulator. It samples
\[ r_{1-b},s_{1-b}\xleftarrow{\$}\mathbb Z_p \]
and sets
\[ I_{1-b}=g^{s_{1-b}}h_{1-b}^{-r_{1-b}}. \]
For the known branch \(b\), it chooses
\[ k_b\xleftarrow{\$}\mathbb Z_p \]
and sets
\[ I_b=g^{k_b}. \]
It sends \((I_0,I_1)\) and receives one global verifier challenge \(r\xleftarrow{\$}\mathbb Z_p\). It then defines
\[ r_b=r-r_{1-b}\pmod p \]
and, using the known witness, computes
\[ s_b=k_b+r_bx_b\pmod p. \]
The prover sends \((r_0,r_1,s_0,s_1)\). The verifier accepts exactly when
\[ I_0=g^{s_0}h_0^{-r_0}, \qquad I_1=g^{s_1}h_1^{-r_1}, \]
and
\[ r=r_0+r_1\pmod p. \]
The global challenge is the essential constraint. The prover may freely simulate one branch and thereby fix one subchallenge, but the other subchallenge is then forced. It can answer that forced challenge only on the branch for which it knows a witness. At the same time, the two branches have symmetric transcript distributions, so the verifier cannot tell which one was simulated.
The method extends to \(n\) public keys by requiring
\[ r=\sum_{i=1}^{n}r_i\pmod p. \]
The prover simulates all branches except one and uses its witness to complete the remaining branch.
3.7.1. Ring signatures
Applying Fiat–Shamir to an OR proof yields the core idea of a ring signature. A signer selects a collection of public keys and proves that it knows the secret key corresponding to at least one of them, while hiding which one. The message is included in the hash challenge, turning the proof into a signature.
The lecture used whistleblowing as an example. A member of a group of officials can sign leaked information with respect to the ring of all officials’ public keys. A journalist learns that one member of the listed group authenticated the message but does not learn which member did so. Ring signatures were presented as an application of OR composition rather than as a separately examined construction; the lecturer explicitly said that the ring-signature details themselves were not part of the exam material.
3.8. Proving that an ElGamal ciphertext encrypts a bit
Let
\[ pk=g^x \]
and let an ElGamal ciphertext be
\[ (c_0,c_1)=\left(g^r,pk^rM\right). \]
Encode a bit \(m\in\{0,1\}\) in the exponent as
\[ M=g^m. \]
If \(m=0\), then \(M=g^0=1\), so
\[ c_1=pk^r. \]
Consequently,
\[ (g,c_0,pk,c_1) \]
is a Diffie–Hellman tuple, or equivalently
\[ \log_g c_0=\log_{pk}c_1=r. \]
If \(m=1\), then \(M=g\), and removing that known factor gives
\[ c_1g^{-1}=pk^r. \]
Hence
\[ (g,c_0,pk,c_1g^{-1}) \]
is a Diffie–Hellman tuple.
The prover combines two discrete-logarithm equality proofs with OR composition to prove
\[ \left[ (g,c_0,pk,c_1)\text{ is a DH tuple} \right] \lor \left[ (g,c_0,pk,c_1g^{-1})\text{ is a DH tuple} \right]. \]
This proves that the ciphertext encrypts either \(0\) or \(1\), while zero knowledge hides which bit it encrypts.
3.9. Homomorphic tallying and electronic voting
ElGamal is multiplicatively homomorphic in its group-message representation. For exponent-encoded messages,
\begin{equation*} \begin{aligned} &\left(g^{r_1},pk^{r_1}g^{m_1}\right) \cdot \left(g^{r_2},pk^{r_2}g^{m_2}\right) \\[2mm] &\qquad= \left(g^{r_1+r_2},pk^{r_1+r_2}g^{m_1+m_2}\right). \end{aligned} \end{equation*}Thus componentwise multiplication of ciphertexts adds the plaintext exponents. This is useful in voting: encryptions of individual votes can be aggregated, and decryption of the product reveals an encoding of the total rather than each individual vote. Since the final tally lies in a small known range, its discrete logarithm can be recovered by a bounded search.
The bit proof is essential for ballot validity. Without it, a malicious voter could encrypt \(g^5\), for example, and effectively contribute five votes. Each voter instead proves in zero knowledge that its encrypted value belongs to the allowed set \(\{0,1\}\). More elaborate OR proofs and relations can also enforce constraints across several candidates, such as casting exactly one vote, while the homomorphic aggregation keeps the individual choices private.
3.10. Final perspective and exam boundary
The three lectures established the following chain of ideas.
- Interactive proofs exist for every NP language because a witness can be sent and checked.
- Zero knowledge requires a simulator and ensures that the verifier learns no information beyond the truth of the statement.
- Given suitable commitment schemes, the 3-coloring construction yields zero-knowledge proofs for all NP languages.
- Proofs of knowledge strengthen soundness by requiring an efficient extractor for the witness.
- Schnorr identification is a proof of knowledge of a discrete logarithm and is honest-verifier zero knowledge.
- Public-coin three-message proofs of the form used in the lectures can often be made non-interactive with Fiat–Shamir in the random-oracle model.
- Discrete-logarithm equality proofs and OR composition allow expressive claims about Diffie–Hellman tuples, encrypted values, commitments, and possession of one among many secret keys.
The lecturer stated that the material through proofs of knowledge and these compositions was the final material included in the exam. The subsequent lecture on additional signature material was announced as optional and outside that exam boundary.