February 19, 2002
Practical Aspects of Modern Cryptography
79
An Non-Interactive ZK Proof
Y
Y1
Y3
Y2
Y4
Y5
Y100
0
0
1
1
0
1
√(Y2•Y)
√(Y100•Y)
√(Y3•Y)
√Y1
√Y4
√Y3