Statistical Zero-Knowledge Languages can be Recognized in Two Rounds
نویسندگان
چکیده
Recently, a hierarchy of probabilistic complexity classes generalizing NP has emerged in the work of Babai [B], and Goldwasser, Micali, and Racko [GMR1], and Goldwasser and Sipser [GS]. The class IP is de ned through the computational model of an interactive prover-veri er pair. Both Turing machines in a pair receive a common input and exchange messages. Every move of the veri er as well as its nal determination of whether to accept or reject w are the result of random polynomial time computations on the input and all messages sent so far. The prover has no resource bounds. A language, L, is in IP if there is a prover-veri er pair such that: 1.) when w 2 L, the veri er accepts with probability at least 1 2 jwj and, 2.) when w 62 L, the veri er interacting with any prover accepts with probability at most 2 jwj. Such a prover-veri er pair is called an interactive proof for L. In addition to de ning interactive proofs, Goldwasser, Micali, and Racko [GMR1] further de ned zero-knowledge interactive proofs. Informally, an interacting pair is a zero-knowledge proof for a language, L, if it is an interactive proof for L with the additional constraint that the prover reveals \nothing" (except language membership) to any veri er that the veri er could not have computed itself. There are three formal de nitions for \nothing" which lead to three types of zero-knowledge: perfect, statistical, and computational, each more restrictive than the next. We show that the rst and second de nitions are very restrictive. Speci cally, any language, L, that has a statistical zero-knowledge interactive proof with an unbounded number of interactions has an interactive proof with two interactions. This complements a result by Fortnow [F] who showed that under the same hypothesis, the complement of L has an interactive proof with two interactions. Warning: Essentially this paper has been published in Journal of Computer and System Sciences and is hence subject to copyright restrictions. It is for personal use only.
منابع مشابه
Concurrent Zero - Knowledge in Poly - logarithmic
A proof is concurrent zero-knowledge if it remains zero-knowledge when run in an asynchronous environment, such as the Internet. It is known that zero-knowledge is not necessarily preserved in such an environment; Kilian, Petrank and Rackoff have shown that any 4 rounds zero-knowledge interactive proof (for a non-trivial language) is not concurrent zero-knowledge. On the other hand, Richardson ...
متن کاملConcurrent Zero Knowledge Proofs with Logarithmic Round-Complexity
We consider the problem of constructing Concurrent Zero Knowledge Proofs [6], in which the fascinating and useful “zero knowledge” property is guaranteed even in situations where multiple concurrent proof sessions are executed with many colluding dishonest verifiers. Canetti et al. [3] show that blackbox concurrent zero knowledge proofs for non-trivial languages require Ω̃(log k) rounds where k ...
متن کاملA Note on the Round-Complexity of Concurrent Zero-Knowledge
We present a lower bound on the number of rounds required by Concurrent Zero-Knowledge proofs for languages in NP. It is shown that in the context of Concurrent Zero-Knowledge, at least eight rounds of interaction are essential for black-box simulation of non-trivial proof systems (i.e., systems for languages that are not in BPP). This improves previously known lower bounds, and rules out sever...
متن کاملResettable Statistical Zero Knowledge
Two central notions of Zero Knowledge that provide strong, yet seemingly incomparable security guarantees against malicious verifiers are those of Statistical Zero Knowledge and Resettable Zero Knowledge. The current state of the art includes several feasibility and impossibility results regarding these two notions separately. However, the question of achieving Resettable Statistical Zero Knowl...
متن کاملComputational Complexity and Knowledge Complexity
We study the computational complexity of languages which have interactive proofs of logarithmic knowledge complexity. We show that all such languages can be recognized in BPPNP . Prior to this work, for languages with greater-than-zero knowledge complexity only trivial computational complexity bounds were known. In the course of our proof, we relate statistical knowledge complexity to perfect k...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- J. Comput. Syst. Sci.
دوره 42 شماره
صفحات -
تاریخ انتشار 1991