Merkle Puzzles Are Optimal Boaz Barak Mohammad Mahmoody-Ghidary TexPoint fonts used in EMF. Read the...

Preview:

Citation preview

• • ’•

Alice Bob

sA sB

Pr[sA = sB ] > 0:99

sEPr[sE = sA]< 0:51

H01n01n

H

H

8n9On²

PrsEsAPrsAsB²

Alice

sA sB

HBob

q201nqH

8n9On²

Pr’1²

sAsB

8n9On²

Pr’1–O²

Alice

sA sB

HBob

’·On²

8iqiqjji·²n

’’

8iqiqjji·10²n

’ithqqi

••

’’’

¹ (¸10²n

’A= rAhA10²n

>²nq

• • ’

“”

8iqiqjji·²n

’ithqqi

••

’’’

’A=rAhA10²n

¹>5²n

8AB

“”

Thus theorem follows from:

Depends only on A,A

Depends only on B,B

Cor: Probabilities in product and non-product are same up to mult factor of 0.99

N

M

®M

8n9On²

Pr’1–O²

Alice

sA sB

HBob

’·On²

8iqiqjji·10²n

·10²

’·On²’·On²

• ’

“”

• !

• “”