February 19, 2002
Practical Aspects of Modern Cryptography
77
An Non-Interactive ZK Proof
Y
Y1
Y3
Y2
Y4
Y5
Y100
0
0
1
1
1
0
where the bit string is computed as
xxx = SHA-1(Y1, Y2,…, Y100)