One-out-of-Many Proofs: Or How to Leak a Secret and Spend a Coin

  title={One-out-of-Many Proofs: Or How to Leak a Secret and Spend a Coin},
  author={Jens Groth and Markulf Kohlweiss},
  journal={IACR Cryptology ePrint Archive},
We construct a 3-move public coin special honest verifier zero-knowledge proof, a so-called Sigma-protocol, for a list of commitments having at least one commitment that opens to 0. It is not required for the prover to know openings of the other commitments. The proof system is efficient, in particular in terms of communication requiring only the transmission of a logarithmic number of commitments. We use our proof system to instantiate both ring signatures and zerocoin, a novel mechanism for… CONTINUE READING


Publications citing this paper.
Showing 1-10 of 31 extracted citations


Publications referenced by this paper.
Showing 1-10 of 35 references

Similar Papers

Loading similar papers…