Chapter 19: Zero-Knowledge Techniques

Chapter 19 of Trappe & Washington: proving knowledge of a secret while revealing nothing reusable. Covers the Quisquater-Guillou-Berson tunnel and the commit-challenge-respond skeleton, the three properties with the simulator argument for zero-knowledge, the square-root protocol and why answering both challenges is equivalent to knowing the secret, the Feige-Fiat-Shamir identification scheme with its 2^-kt soundness bound and Arthur's identity-derived setup, and the discrete-log and Schnorr schemes from the exercises — including the nonce-reuse algebra that recovers the secret and the Fiat-Shamir transform that turns any of them into a signature.

Subject: Cryptography · 62 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Zero-Knowledge Techniques

Title

Cryptography · Chapter 19

Proving that you know a secret while revealing nothing an eavesdropper could reuse

2. What you will be able to do

Objectives

Every identification scheme so far has had the same weakness: to prove who you are, you hand over the thing that proves it. This chapter removes that.

Figure (svg): The three defining properties of a zero-knowledge proof arranged as three separate guarantees.

Three properties, three different kinds of argument — and the third is what makes the chapter's title honest.

3. The fake teller machine

Warm-up

The book opens with a real case. Thieves set up a counterfeit ATM in a shopping mall. It read each card, recorded the PIN typed in, and then reported politely that it could not accept the card. The thieves made duplicate cards and withdrew cash from real machines.

Discussion prompt

What exactly is the flaw, stated as a property of the protocol rather than of the criminals?

Hint: Think about what the card and the PIN are, and what the machine does with them.

Answer:

The secret is transmitted in order to be used. The PIN goes across the wire in full, so anyone who sees it once can replay it forever.

And the verifier is unauthenticated. Peggy has no way to check that the machine is a real machine before she gives it her secret — the flaw runs in both directions.

So the requirement is: use the secret without transmitting anything that can be reused. Not encrypt it — encryption still sends something that a fake machine could capture and replay — but arrange matters so that everything sent is worthless afterwards.

That is what a zero-knowledge protocol delivers, and it is a stronger requirement than it first sounds: Victor must end up certain that Peggy knows the secret, while holding nothing he could not have manufactured himself.

Those two demands look contradictory, and the fact that they are not is the content of this chapter.

4. The Basic Setup

Section

Section 19.1 · pp. 357-361

5. Challenge-Response and the tunnel

Concept

The clearest illustration is due to Quisquater, Guillou and Berson. A ring-shaped tunnel has a locked door at the far side. Peggy claims she can pass through it and wants to convince Victor without revealing how — or even which direction she can pass.

  1. Peggy enters the tunnel and walks down the left or the right side, her choice
  2. Victor waits outside, then comes in and stands at the entrance
  3. He calls out “Left” or “Right”, at random
  4. Peggy emerges from the side he named
  5. Repeat until Victor is satisfied

The ordering is what makes it work. Peggy must commit to a side before she hears the challenge. If she cannot open the door, she is stuck on whichever side she chose, and can only comply when Victor happens to name it — which is half the time.

Figure (svg): The ring-shaped tunnel with a locked door at the far side, Victor waiting at the entrance and calling out a side.

Quisquater, Guillou and Berson's tunnel: the picture that explains the whole chapter before any algebra appears.

6. Why ten rounds are enough

Worked example

There is never a proof in the mathematical sense. There is accumulated evidence, and the accumulation is exponential.

A cheating Peggy survives one round with probability 1/2

Why: She picked a side blind, and Victor's challenge matches it half the time.

The rounds are independent, because Victor chooses afresh each time

Why: Nothing Peggy observes in one round tells her anything about the next challenge, so the probabilities multiply.

After t rounds she survives with probability 2⁻ᵗ

Why: Ten rounds gives 1/1024; twenty gives about one in a million; forty is below any threshold anyone cares about.

\[ \Pr[\text{cheat survives } t \text{ rounds}] = 2^{-t} \]

Verify: Victor sets his own confidence level by choosing t

Why: Which is a genuinely useful property: the same protocol serves a low-value transaction and a high-value one, at a cost that is linear in the number of rounds while the security is exponential in it.

Figure (svg): A bar chart of the probability a cheating prover survives, halving with each round.

Soundness is not proved once; it is accumulated, and the accumulation is exponential.

7. How many rounds for one in a million?

Prediction

Predict first

Roughly how many rounds does Victor need for a soundness error below one in a million?

  • About 6
  • About 20
  • About 100
  • About 1000

Correct: About 20

Compare a key search, where doubling the security costs one more bit and the work doubles. Here doubling the confidence costs one more round and the work grows by a fixed increment. Both are exponential, but the resource being spent is different: time in one case, communication in the other.

Which is exactly what Section 19.2 attacks. Twenty round trips is a lot of latency for an ATM, and Feige-Fiat-Shamir gets the same 2⁻²⁰ in four.

Why: 2⁻²⁰ is about one in a million, so twenty rounds. The linear-cost, exponential-security trade is what makes challenge-response practical — doubling the confidence costs one more round, forever.

8. The three properties

Concept

A zero-knowledge proof must satisfy three separate conditions, and they are proved by three different kinds of argument.

Completeness — If Peggy really knows the secret, an honest Victor is always convinced. This is usually a one-line calculation — the verification equation holds identically.

Soundness — If Peggy does not know the secret, Victor rejects except with small probability. This is an argument about what a cheat would have to be able to compute, and it is where the hard problem enters.

Zero-knowledge — Victor learns nothing beyond the fact that Peggy knows the secret. This is proved by exhibiting a simulator: a program that produces transcripts indistinguishable from real ones without the secret.

The simulator argument is the subtle one, and it is worth pausing on. If a transcript can be manufactured by someone who knows nothing, then the transcript cannot contain any information about the secret — because a thing that could have been made up carries no evidence.

Figure (svg): The three defining properties of a zero-knowledge proof arranged as three separate guarantees.

Three properties, three different kinds of argument — and the third is what makes the chapter's title honest.

9. Why does Eve's video convince nobody?

Socratic

Suppose Eve watches the whole tunnel protocol on a monitor Victor is carrying, and records it.

Discussion prompt

Why can she not use the recording to convince anyone that Peggy can pass the door — and why might she not even be convinced herself?

Hint: What would a faked recording look like?

Answer:

Because Peggy and Victor could have agreed the sequence in advance. If Peggy knows that the challenges will be left, left, right, left, ... she simply walks down each named side and never touches the door. The recording is identical.

So the recording is consistent with both hypotheses, and consistency with both means it distinguishes neither. It has zero evidential value to a third party.

What convinced Victor was not the recording but the randomness of his own challenges, which he knows Peggy could not predict. That knowledge is his alone and is not in the video.

This is the simulator argument in plain form. Anyone can produce a convincing-looking transcript by choosing the challenges first and staging the responses. Since fakes are indistinguishable from the real thing, the real thing carries no transferable information.

And it is a feature, not a limitation. It is precisely why the fake ATM gains nothing: everything it records is something it could have generated itself.

Figure (svg): A simulator producing a convincing transcript without the secret, by choosing the challenge before the commitment.

The simulator argument, which is why a video of the tunnel convinces nobody: anyone could have shot it.

10. Square Root Zero-Knowledge Proof: the protocol

Concept

Now the algebraic version. Let n = pq with p, q large primes, and let y be a square mod n with gcd(y, n) = 1. Peggy claims to know a square root s of y. Section 3.9 says finding square roots mod n is equivalent to factoring, so the claim is substantial.

  1. Peggy picks a random r₁ and sets r₂ ≡ s r₁⁻¹ (mod n), so that r₁r₂ ≡ s
  2. She sends x₁ ≡ r₁² and x₂ ≡ r₂²
  3. Victor checks x₁x₂ ≡ y, then asks for a square root of x₁ or of x₂
  4. Peggy sends r₁ or r₂; Victor squares it and checks
  5. Repeat with a fresh r₁ each time

Note the assumption gcd(r₁, n) = 1, needed for the inverse to exist. If it fails, Peggy has stumbled on a factor of n and has larger news to report.

Figure (svg): One round of the square-root zero-knowledge protocol, with Peggy splitting her secret into two random factors.

Peggy factors her secret into two random halves and surrenders one — never both.

11. One round with n = 77

Worked example

Small enough to check by hand.

n = 77 = 7 · 11, Peggy's secret is s = 13, and y ≡ 13² ≡ 169 ≡ 15 (mod 77)

Why: y = 15 is public; s = 13 is Peggy's alone.

She picks r₁ = 5 and computes r₂ ≡ 13 · 5⁻¹ (mod 77)

Why: 5⁻¹ ≡ 31, since 5 · 31 = 155 = 2 · 77 + 1. So r₂ ≡ 13 · 31 ≡ 403 ≡ 18.

Check the split: 5 · 18 = 90 ≡ 13 = s ✓

Why: The two random halves multiply to the secret, which is the point of the construction.

She sends x₁ = 5² = 25 and x₂ = 18² = 324 ≡ 16

Why: Both are squares of numbers she knows.

Victor checks x₁x₂ = 25 · 16 = 400 ≡ 15 = y ✓

Why: The check is what ties this round to the actual claim rather than to two unrelated squares.

Verify: Victor asks for one root; Peggy sends 5 or 18, and he squares it

Why: Either answer is a random number as far as he is concerned. Both answers together would be 5 · 18 = 13 — the secret itself — which is why he only ever gets one.

Figure (svg): A numeric round of the square-root protocol modulo 77, showing the split and the two squares.

The split is the whole idea: two random numbers whose product is the secret, and Victor may see either one.

12. Why a cheating Peggy is caught

Concept

Suppose Peggy does not know a square root of y. She can still send some x₁ and x₂ with x₁x₂ ≡ y; that requires no secret at all.

But if she knew a square root of x₁ and a square root of x₂, she would know one of y — because the product of the two roots squares to x₁x₂ = y. Since she does not know a root of y, she must be missing a root of at least one of them.

So at least half the time Victor asks for the root she does not have, and computing it would mean taking a square root mod n, which is as hard as factoring.

\[ \sqrt{x_1} \cdot \sqrt{x_2} = \sqrt{x_1 x_2} = \sqrt{y} \;\Longrightarrow\; \text{knowing both roots is knowing } s \]

Note how tight this argument is. It does not say a cheat is unlikely to succeed; it says success at both challenges is logically equivalent to knowing the secret. Soundness follows immediately, with no further assumptions.

Figure (svg): Two branches for a prover who does not know the secret: she can answer one challenge or the other, never both.

Soundness in one line: answering both challenges is knowing the secret, so a cheat can answer at most one.

13. Peggy guesses the challenge in advance

Anomaly

Suppose Peggy correctly predicts that Victor will ask for a root of x₂.

Predict first

Can she pass the round without knowing s?

  • No — the check x₁x₂ ≡ y stops her
  • Yes — she picks r₂ at random, sets x₂ ≡ r₂², and defines x₁ ≡ y x₂⁻¹
  • Only if she can factor n
  • Only if y is a perfect square

Correct: Yes — she picks r₂ at random, sets x₂ ≡ r₂², and defines x₁ ≡ y x₂⁻¹

So each round really is a coin flip, not a proof. Peggy's chance of surviving is exactly the chance of guessing the challenge, which is 1/2.

As soon as she guesses wrong she is exposed, and Victor learns definitively that she does not know s. That asymmetry — a cheat is caught permanently, while an honest prover never fails — is what makes repetition worth doing.

And notice that this cheat is the simulator. Choosing the challenge first and working backwards is exactly how a fake transcript is manufactured, which is why the protocol leaks nothing: the honest transcript and the cheat's transcript have the same distribution.

The one thing she cannot do is guess right twenty times. Which is the whole security argument.

Why: She chooses the half she will be asked for and derives the other half backwards. x₁x₂ ≡ y holds by construction, and she answers with r₂. Everything checks out — she simply cannot do it for x₁, and she does not have to.

14. Reusing r destroys everything

Concept

The protocol works only because Victor sees one root of each pair. If Peggy repeats a round with the same r₁, that stops being true.

Same x₁, x₂ in two rounds, different challenges. Victor gets r₁ from one round and r₂ from the other, multiplies them, and has s. The protocol has handed him the secret.

So a fresh random r₁ per round is not a recommendation; it is the security. The book says Peggy “should be careful in her choice of random numbers,” which understates it.

The same rule protects against Eve. She hears square roots of random squares, which are useless to her. If she tries to replay Peggy's transcript to masquerade, she needs Victor to ask for exactly the same sides in exactly the same order — probability 2⁻ᵗ, which is the soundness bound again.

This failure mode recurs across the chapter and the course: reuse a nonce in Schnorr and the secret exponent falls out; reuse a one-time pad and Chapter 4's attack applies; reuse a DSA nonce and Chapter 13's does. The name changes, the arithmetic changes, the lesson does not.

Figure (svg): Reusing the commitment exponent across two challenges, and the two-equation system that recovers the secret.

One reused nonce turns a zero-knowledge proof into a broadcast of the secret.

15. Reading the two checks

Notation

Victor performs two verifications each round, and they do different jobs.

Annotate

On: \( x_1 x_2 \equiv y \pmod n \qquad \text{and} \qquad r_i^2 \equiv x_i \pmod n \)

  • Ties this round to the actual claim. Without it Peggy could send any two squares she liked and answer either challenge honestly, proving nothing about y.
  • Verifies that the answer really is a root of the challenged value. One multiplication.
  • The first alone allows an unanswerable pair; the second alone allows a pair unrelated to y. Together they force x₁x₂ = y with a root known for the challenged half.
  • That Peggy knows both roots — he cannot, and if he could the protocol would leak the secret. The gap between what he verifies and what he concludes is bridged by repetition.
  • Two modular multiplications for Victor per round, and one modular inversion plus two squarings for Peggy. Cheap on both sides.

A recurring design shape: each verification is trivial, and the security lives in the fact that Peggy could not have prepared for both challenges.

16. Why does Victor learn nothing reusable?

Explain it to yourself

Over twenty rounds Victor collects twenty square roots.

Discussion prompt

Explain why none of them helps him impersonate Peggy.

Hint: What are those roots roots of?

Answer:

They are square roots of random squares, not of y. Each r₁ was chosen fresh and uniformly, so each x₁ is a uniformly random square and its root tells him nothing about s.

He could have generated every one himself. Pick a random r, publish r², reveal r — no secret required. That is the simulator, and it produces the same distribution.

To impersonate Peggy he would need to answer challenges he has not seen in advance, and his collected transcripts give him no ability to do that: a new verifier will ask about new commitments.

The one thing he does learn is the fact he came for — that Peggy knows s. That is not nothing, and it is not transferable: he cannot convince a third party, because his transcripts are indistinguishable from fakes.

Which resolves the apparent paradox in the chapter's premise. Conviction and information are different things. Victor's certainty comes from his own private knowledge that his challenges were unpredictable, and that knowledge does not travel.

Figure (svg): A simulator producing a convincing transcript without the secret, by choosing the challenge before the commitment.

The simulator argument, which is why a video of the tunnel convinces nobody: anyone could have shot it.

17. Sort what crosses the wire

Definition probe

In one round of the square-root protocol, several values are exchanged.

Sort into buckets

Sort each by whether an eavesdropper gains anything from it.

Reveals nothing about s
x₁ and x₂; The single root Peggy reveals; Victor's challenge bit
Reveals s
Both roots of the same pair, across two rounds
safe
x₁ and x₂ are random squares whose product is the public y; a single root is a random number; and the challenge bit is Victor's own coin. Every one of them can be manufactured without the secret, which is the definition of leaking nothing.
fatal
r₁ and r₂ multiply to s exactly. Any circumstance that lets Victor or Eve see both — a reused r₁, a replayed round, a Peggy who answers twice about the same commitment — hands over the secret in one multiplication.

18. Complete the square-root protocol

Faded example

Five steps, four blanks.

Fill in the blanks

Peggy picks a random r₁ and sets r₂ ≡ s r₁⁻¹ (mod n), so that r₁r₂ ≡ s. She sends the two squares x₁ and x₂. Victor checks that x₁x₂ ≡ y, then asks for a root of one of them. If Peggy could answer both, she would know s — which is why she can answer at most one when she does not.

Why: The multiplicative split is the construction, the product check ties the round to y, and the impossibility of answering both is the soundness argument. Three sentences contain the entire protocol.

19. What does one round cost?

Estimation

n is 2048 bits.

Predict first

Roughly how many bits cross the wire in one round of the square-root protocol?

  • About 100
  • About 4000
  • About 100 000
  • About a million

Correct: About 4000

The bandwidth is tolerable; the round trips are not. Twenty sequential exchanges over a network with 50 ms latency is a full second of waiting before the ATM decides anything.

Hence two optimisations in the next section: challenge k bits at once so one round is worth k, and send a hash of x rather than x itself, cutting 2048 bits to 256.

Why: x₁ and x₂ are each about 2048 bits, the challenge is one bit, and the response is another 2048 — so about 6000 bits, or a few kilobytes. Multiply by twenty rounds and it is around 15 KB with twenty round trips, which is the latency problem Feige-Fiat-Shamir exists to solve.

20. The Feige-Fiat-Shamir Identification Scheme

Section

Section 19.2 · pp. 361-367

21. Feige-Fiat-Shamir Identification Scheme: parallel verification

Concept

The same idea, with k challenges packed into one exchange. Again n = pq. Peggy has secret numbers s₁, …, s_k with gcd(sᵢ, n) = 1, and the public values are vᵢ ≡ sᵢ⁻² (mod n).

  1. Peggy chooses a random r and sends x ≡ r² (mod n)
  2. Victor sends challenge bits b₁, …, b_k, each 0 or 1
  3. Peggy sends y ≡ r · s₁^b₁ s₂^b₂ ⋯ s_k^b_k (mod n)
  4. Victor checks x ≡ y² v₁^b₁ v₂^b₂ ⋯ v_k^b_k (mod n)
  5. Repeat t times, with a fresh r each round

With k = 1 this is the earlier protocol in disguise, with quotients in place of products: Peggy is asked for either r or rs₁, two random numbers whose quotient is a square root of v₁.

Figure (svg): One round of the Feige-Fiat-Shamir scheme: a single commitment, k challenge bits, and a single response.

The same idea as the square-root protocol, with k independent challenges packed into one round trip.

22. Why the verification congruence holds

Worked example

Completeness first, since it is a one-line calculation and it shows why the vᵢ are defined with a negative exponent.

Peggy sends y ≡ r · ∏ sᵢ^bᵢ

Why: The product runs over the indices where bᵢ = 1.

Victor computes y² ∏ vᵢ^bᵢ

Why: Substituting: y² = r² · ∏ sᵢ^(2bᵢ).

And vᵢ ≡ sᵢ⁻², so vᵢ^bᵢ ≡ sᵢ^(−2bᵢ)

Why: This is the reason for the inverse square in the definition — it is exactly what cancels the sᵢ² terms.

\[ y^2 \prod v_i^{b_i} \equiv r^2 \prod s_i^{2b_i} \cdot \prod s_i^{-2b_i} \equiv r^2 \equiv x \pmod n \]

Verify: so an honest Peggy always passes

Why: Every secret cancels, leaving r² = x. Victor never sees r, and y is r multiplied by a product of secrets — a uniformly random-looking value, since r is uniform.

Figure (svg): One round of the Feige-Fiat-Shamir scheme: a single commitment, k challenge bits, and a single response.

The same idea as the square-root protocol, with k independent challenges packed into one round trip.

23. One round with k = 3, modulo 77

Worked example

Concrete numbers, small enough to verify.

n = 77, secrets s = (13, 5, 9)

Why: So v₁ ≡ 13⁻² ≡ 15⁻¹ ≡ 36, v₂ ≡ 5⁻² ≡ 25⁻¹ ≡ 37, and v₃ ≡ 9⁻² ≡ 4⁻¹ ≡ 58. The vᵢ are public.

Peggy picks r = 6 and sends x = 36

Why: 6² = 36, and 36 is under 77 so no reduction is needed.

Victor sends b = (1, 0, 1)

Why: He wants the first and third secrets involved, and not the second.

Peggy sends y ≡ 6 · 13 · 9 = 702 ≡ 9 (mod 77)

Why: 702 = 9 · 77 + 9.

Victor checks y² v₁ v₃ = 81 · 36 · 58

Why: 81 ≡ 4, then 4 · 36 = 144 ≡ 67, then 67 · 58 = 3886 ≡ 36.

Verify: 36 = x, so the round succeeds

Why: And notice what Victor holds afterwards: x = 36 and y = 9, with r never revealed. To extract s₁s₃ he would need r, and to get r he would need a square root of x.

Figure (svg): A numeric Feige-Fiat-Shamir round modulo 77 with three secrets, showing both sides of the verification.

Small enough to check by hand, and it shows exactly which quantities cross the wire.

24. Why the odds are one in 2ᵏ

Concept

Soundness. Suppose Peggy knows none of the sᵢ — the realistic case when someone is impersonating her.

She can prepare for one guess. If she predicts the bit string before sending x, she picks y at random and defines x ≡ y² ∏ vᵢ^bᵢ. The verification then holds by construction.

But she is locked in. Suppose she prepared for b₁ = b₂ = b₄ = 1 and Victor sends b₁ = b₃ = 1 instead. She is ready to supply a square root of x v₁⁻¹v₂⁻¹v₄⁻¹ and is asked for one of x v₁⁻¹v₃⁻¹. Combining the two is equivalent to knowing a square root of v₂⁻¹v₃v₄⁻¹, which she cannot compute.

In general, a wrong guess requires the square root of a nonempty product of vᵢ's. Only one of the 2ᵏ strings lets her through, so one round has soundness error 2⁻ᵏ, and t rounds give 2⁻ᵏᵗ.

\[ \Pr[\text{impostor succeeds}] = 2^{-kt} \]

Figure (svg): Two branches for a prover who does not know the secret: she can answer one challenge or the other, never both.

Soundness in one line: answering both challenges is knowing the secret, so a cheat can answer at most one.

25. What do the recommended parameters give?

Prediction

Predict first

What soundness error does that give, and how does it compare with the earlier protocol?

  • 2⁻⁹, worse than the earlier scheme
  • 2⁻²⁰, the same as twenty rounds of the earlier scheme but in four exchanges
  • 2⁻⁵, since only k matters
  • 2⁻¹⁰⁰, since the effects multiply across parameters

Correct: 2⁻²⁰, the same as twenty rounds of the earlier scheme but in four exchanges

**What is given up is precision about which secret.** Victor becomes very confident that the person is Peggy, but he gains only weak evidence that she knows any particular sᵢ. For identification that is exactly the right trade.

And k costs storage rather than time. Peggy stores k secrets and the public directory stores k values, but each round is one exchange regardless of k. Making k large is cheap, which is why the parameters are shaped this way.

Why: kt = 20, so the error is 2⁻²⁰ — about one in a million, identical to twenty rounds of the sequential protocol. The saving is entirely in communication: four round trips instead of twenty, which for an interactive device is the difference between snappy and sluggish.

26. Hashing x to save bandwidth

Concept

A neat detail in how steps 1 and 4 are arranged. Peggy need not send x at all — she can send H(x) for a collision-resistant hash H.

Victor computes y² ∏ vᵢ^bᵢ himself in step 4, hashes the result, and compares with what Peggy sent. Collision resistance means a match implies the congruence held.

The saving is real: 256 bits instead of 2048, for the largest message in the protocol. With t = 4 rounds that is about 900 bytes saved on a channel that may be a smart card reader.

And notice the structural reason it works: Victor recomputes x rather than receiving it, so the commitment only has to be binding, not recoverable. A hash is the cheapest binding commitment there is — Section 10.3 again.

This trick generalises. Any protocol in which the verifier can reconstruct the committed value can commit to its hash instead, and the same observation is what makes Schnorr signatures short.

Figure (svg): One round of the Feige-Fiat-Shamir scheme: a single commitment, k challenge bits, and a single response.

The same idea as the square-root protocol, with k independent challenges packed into one round trip.

27. Arthur's setup: identity as a public key

Concept

The scheme becomes an identification system with one more idea. Let I be a string containing Peggy's name, birth date and whatever else is appropriate, and let H be a public hash function.

  1. A trusted authority Arthur — a bank, a passport agency — chooses n = pq
  2. He computes H(I ‖ j) for small values of j, and uses p and q to find which of them are squares mod n
  3. The first k that are squares become v₁ = H(I ‖ j₁), …, v_k = H(I ‖ j_k), and he computes their roots s₁, …, s_k
  4. I, n, j₁, …, j_k are published; the sᵢ go to Peggy alone

The elegance is that the public values are derived from the identity itself. A verifier does not look up Peggy's public key — it computes it, from her name and a handful of small integers on her card.

Figure (svg): Arthur's one-time setup: hashing an identity string, keeping the hashes that are squares, and handing Peggy their roots.

The public values are derived from the identity itself, so nothing about Peggy needs to be stored to check her.

28. Why about a quarter of the hashes are squares

Worked example

Arthur needs enough j's to find k squares, so it matters how often a random value is a square mod n.

Mod a prime p, exactly half the nonzero residues are squares

Why: The squaring map is two-to-one, so its image is half the group.

Same mod q

Why: Half again.

By CRT, a residue mod n corresponds to a pair (mod p, mod q), and it is a square mod n exactly when both components are

Why: Independent conditions, each with probability 1/2.

\[ \Pr[\text{random } v \text{ is a square mod } pq] = \tfrac{1}{2} \cdot \tfrac{1}{2} = \tfrac{1}{4} \]

Verify: so Arthur expects to try about 4k values of j to find k squares

Why: For k = 5 that is around twenty hash computations and twenty Legendre-symbol tests — trivial. And this is exactly the same 1/4 that made a cheating Bob's non-square detectable in Chapter 18.

Figure (svg): Arthur's one-time setup: hashing an identity string, keeping the hashes that are squares, and handing Peggy their roots.

The public values are derived from the identity itself, so nothing about Peggy needs to be stored to check her.

29. Why Arthur destroys everything afterwards

Concept

Two lines in the setup carry most of the system's practical security.

The primes p and q are discarded once the roots are computed. Nobody needs them again — verification uses only n and the public values.

And Arthur does not store the sᵢ once Peggy has them. He has no reason to.

So breaking into Arthur's computer yields nothing. There is no database of secrets to steal, which is precisely the failure mode that makes stolen password files catastrophic. Compare Chapter 11: a password file must store something, and the whole art is making that something useless. Here the answer is to store nothing.

A different n can be used for each person, so compromising one individual — even by factoring their n — compromises nobody else. The blast radius of any single failure is one user.

This is a design pattern worth naming: the most reliable way to protect stored secrets is to arrange that there are none. It appears again in forward secrecy, in Chapter 16's discarded setup exponents, and in every system that derives keys rather than storing them.

Figure (svg): Arthur's one-time setup: hashing an identity string, keeping the hashes that are squares, and handing Peggy their roots.

The public values are derived from the identity itself, so nothing about Peggy needs to be stored to check her.

30. Who holds what after setup?

Definition probe

Arthur has finished, Peggy has her card, and the directory is published.

Sort into buckets

Sort each value by where it lives.

Public or computable by anyone
n and the indices j₁ … j_k; The public values v₁ … v_k
Peggy alone
The secrets s₁ … s_k
Destroyed
The primes p and q
public
n and the j's are published, and the vᵢ are H(I ‖ jᵢ) — anyone with Peggy's identity string can compute them. That is the point: the verifier reconstructs the public key rather than looking it up.
peggy
The square roots are the whole secret, and they exist in exactly one place. If Peggy loses her card, Arthur cannot reissue the same secrets — he would have to pick a new n and start again.
gone
Deliberately. Once the roots are computed the primes have no further use, and keeping them would make Arthur's machine worth attacking.

31. Where challenge-response actually runs

Real world

The specific schemes here are not widely deployed, but the shape is everywhere.

Discussion prompt

Name four systems built on prove-you-know-it-without-sending-it.

Hint: Bank cards, web logins, wireless, and the modern replacement for passwords.

Answer:

EMV chip cards. The chip signs a challenge from the terminal rather than revealing a key, which is why cloning a chip card is hard and cloning a magnetic stripe was trivial. This is precisely the fake-ATM problem, solved.

FIDO2 and passkeys. The authenticator holds a private key and signs a server challenge; the server stores only a public key. A breached server database contains nothing worth stealing — Arthur's design principle, deployed at scale.

Kerberos and every mutual-authentication handshake, where both sides prove possession of a key by responding to nonces rather than transmitting it.

And zk-SNARKs, the modern descendants: non-interactive zero-knowledge proofs used for private blockchain transactions and for proving that a computation was performed correctly without revealing its inputs. Those are far more powerful than anything in this chapter, and they rest on the same three properties.

What almost nothing uses is Feige-Fiat-Shamir itself. Its value is pedagogical and historical — it is the clearest place to see soundness, completeness and the simulator argument all at once, and Fiat-Shamir's name survives in the transform that made non-interactive proofs possible.

32. Find the flaws in this login scheme

Error analysis

From a design document for a challenge-response login.

Annotate

  • So a breach hands over every user's secret directly. The whole point of the schemes in this chapter is that the verifier holds only a public value — v, not s.
  • The client must know the next ten challenges to pre-compute, so the challenges are predictable, and a predictable challenge is no challenge: an eavesdropper prepares the same responses.
  • Fatal. A replaying attacker chooses a challenge they have already seen answered. The challenge must come from the verifier, and its unpredictability to the prover is the entire security.
  • Concatenation without a delimiter allows collisions between different (s, c) splits, and with a Merkle-Damgård hash it invites the extension attack of Chapter 11. HMAC exists for this.

Three of the four flaws are the same mistake in different clothes: something that must be unpredictable to the prover has been made predictable, or something that should never be stored has been stored.

33. Sequential versus parallel challenges

Trade off

Two ways to reach the same soundness error. Fill the blanks.

Comparison matrix

Square-root protocolFeige-Fiat-Shamir
Soundness error2⁻ᵗ2⁻ᵏᵗ
Round trips for 2⁻²⁰204, with k = 5
Secrets stored by Peggy1k
Bits Peggy sends per roundabout 2 log nabout log n, or 256 if hashed
What Victor is convinced ofshe knows sshe is Peggy — weaker evidence about any single sᵢ

The parallel version trades storage and per-user setup for latency, which is the right trade when the verifier is a card reader and the prover is a chip. It also weakens what is proved, in a way that does not matter for identification.

34. Discrete Log Zero-Knowledge Proof

Concept

The exercises give the same construction over a different hard problem. Let p be a large prime, α a primitive root, and β ≡ αᵃ (mod p), with p, α, β public. Peggy wants to prove she knows a.

  1. Peggy picks a random r mod p−1 and sends h₁ ≡ αʳ and h₂ ≡ α^(a−r)
  2. Victor checks h₁h₂ ≡ β
  3. He asks for either r or a − r
  4. Peggy sends it; Victor checks that α to that power gives the right hᵢ
  5. Repeat t times

It is the square-root protocol with addition in the exponent in place of multiplication of roots. The secret is split into two random halves, either of which is a uniformly random number on its own, and both of which together are the secret.

A cheating Peggy has the same 1/2 per round, for the same reason: producing both halves means producing a, and she can prepare for only one challenge.

Figure (svg): The discrete-log zero-knowledge proof: the exponent split additively into two halves, one of which is revealed.

The same construction as the square-root protocol, with addition of exponents in place of multiplication of roots.

35. One round modulo 23

Worked example

Small numbers, and every step checkable.

p = 23 and α = 5, which is a primitive root — its order is 22

Why: So the exponents live mod 22.

Peggy's secret is a = 6, so β ≡ 5⁶ ≡ 8 (mod 23) is public

Why: 5² = 2, 5⁴ = 4, 5⁶ = 4 · 2 = 8.

She picks r = 9 and sends h₁ ≡ 5⁹ ≡ 11

Why: 5⁸ = 16, so 5⁹ = 16 · 5 = 80 ≡ 11.

And h₂ ≡ 5^(6−9 mod 22) = 5¹⁹ ≡ 7

Why: The exponent 6 − 9 = −3 reduces to 19 mod 22.

Victor checks h₁h₂ = 11 · 7 = 77 ≡ 8 = β ✓

Why: The two halves multiply to β because their exponents add to a.

Verify: Victor asks for r = 9 or for a − r = 19, and checks the power

Why: Either number alone is uniform mod 22 and reveals nothing about a = 6. Their sum is a, which is why he only ever gets one.

Figure (svg): The discrete-log zero-knowledge proof: the exponent split additively into two halves, one of which is revealed.

The same construction as the square-root protocol, with addition of exponents in place of multiplication of roots.

36. Schnorr Identification Scheme

Concept

A more efficient variant, and the one whose descendants are still deployed. Same public data: p, α, β ≡ αᵃ.

  1. Peggy picks a random k, computes γ ≡ αᵏ (mod p), and sends γ
  2. Victor sends a random challenge r
  3. Peggy computes y ≡ k − a r (mod p−1) and sends y
  4. Victor checks γ ≡ αʸ βʳ (mod p)

\[ \alpha^y \beta^r = \alpha^{k - ar} \alpha^{ar} = \alpha^k = \gamma \]

One round suffices, because the challenge r ranges over a large set rather than two values: a cheat must guess r in advance, and the chance is 1 in the size of the challenge space, not 1 in 2.

In practice p is chosen so that p−1 has a large prime factor q, with α satisfying αᑫ ≡ 1, the exponent arithmetic done mod q, and r drawn from 1 to 2ᵗ with t around 40. Small challenges keep Peggy's work down while leaving the cheat's odds at 2⁻⁴⁰.

Figure (svg): One round of the Schnorr identification scheme: commitment, random challenge, and a response checked against the public key.

Commit, challenge, respond — the shape that later becomes a signature scheme when the challenge is a hash.

37. One round of Schnorr modulo 23

Worked example

The same p, α, β as before: 23, 5, and β = 8 with a = 6.

Peggy picks k = 9 and sends γ ≡ 5⁹ ≡ 11

Why: Exactly the commitment from the previous protocol, reused here as the first message.

Victor sends the challenge r = 4

Why: Random, and Peggy could not have known it.

Peggy computes y ≡ 9 − 6 · 4 = −15 ≡ 7 (mod 22)

Why: Exponent arithmetic is mod p−1 = 22.

Victor checks αʸβʳ = 5⁷ · 8⁴

Why: 5⁷ = 5⁶ · 5 = 8 · 5 = 40 ≡ 17, and 8⁴ = 4096 ≡ 2. Then 17 · 2 = 34 ≡ 11.

Verify: 11 = γ ✓, in three messages rather than twenty

Why: And y = 7 tells Victor nothing: k was uniform, so y = k − ar is uniform too, whatever a is. That is the zero-knowledge property in one sentence.

Figure (svg): One round of the Schnorr identification scheme: commitment, random challenge, and a response checked against the public key.

Commit, challenge, respond — the shape that later becomes a signature scheme when the challenge is a hash.

38. Peggy reuses k

Anomaly

Peggy runs Schnorr twice with the same k, against challenges r₁ and r₂. Eve hears both transcripts.

Predict first

What can Eve compute?

  • Nothing — y is uniform in both rounds
  • The secret a, from the two response equations
  • Only the value of k
  • The factorisation of p−1

Correct: The secret a, from the two response equations

Each transcript alone is genuinely uniform — that is why the scheme is zero-knowledge. It is the pair that is fatal, because two equations in two unknowns have one solution.

This is the identical failure that leaked the Sony PlayStation 3 signing key and drained Bitcoin wallets with a broken random number generator, both in Chapter 13. The algebra there is ECDSA rather than Schnorr, and the structure is the same.

The defence used in practice is deterministic nonces: derive k as a hash of the secret key and the message, so it is unpredictable to everyone else and unrepeatable across different messages. RFC 6979 specifies exactly this, and it exists because the random-per-signature requirement was violated too often to trust.

And the same reasoning covers r₁ in the square-root protocol. Different scheme, different arithmetic, one rule: a commitment randomiser is used once.

Why: y₁ = k − ar₁ and y₂ = k − ar₂. Subtracting eliminates k: y₁ − y₂ = a(r₂ − r₁), so a = (y₁ − y₂)(r₂ − r₁)⁻¹ mod p−1. Two transcripts, one subtraction, one inversion, and the secret is out.

Figure (svg): Reusing the commitment exponent across two challenges, and the two-equation system that recovers the secret.

One reused nonce turns a zero-knowledge proof into a broadcast of the secret.

39. From Schnorr to signatures: the Fiat-Shamir transform

Concept

One more step turns an identification scheme into a signature scheme, and it is the most consequential idea in the chapter's neighbourhood.

The verifier's only job is to supply an unpredictable challenge. So replace them with a hash function: set r = H(γ ‖ m) where m is the message being signed.

Peggy cannot control r any more than she could control Victor, because changing γ changes r unpredictably. So she cannot prepare for a challenge in advance, and the soundness argument survives.

The result is non-interactive. Peggy publishes (γ, y) and anyone can recompute r and check the verification equation. That is a Schnorr signature, and it is what EdDSA and Ed25519 are.

And it explains a naming curiosity: the Fiat of Fiat-Shamir identification and the Fiat of the Fiat-Shamir transform are the same person, and the transform is why the name survives even though the identification scheme is not deployed.

Figure (svg): The Fiat-Shamir transform: replacing the verifier's random challenge with a hash of the commitment.

Remove the verifier by letting a hash function play their part — one of the most consequential tricks in the subject.

40. Naive Nelson's non-proof

Socratic

Exercise 2 ends with a variant. Nelson wants to prove he knows a, so he picks a random r as usual — but does not send h₁ and h₂. Victor asks for rᵢ and Nelson sends it. They repeat several times.

Discussion prompt

Why is Victor convinced of nothing, and what exactly is missing?

Hint: What did h₁ and h₂ do in the real protocol?

Answer:

Nelson never commits to anything. In the real protocol h₁ and h₂ are sent before the challenge, so Peggy is locked in — she has already fixed the split, and Victor's check ties it to β.

Without them Nelson can answer anything. Asked for r, he invents a number. Asked for a − r, he invents another. Nothing constrains the two answers to be consistent with each other or with β.

So the missing element is the commitment, and its ordering relative to the challenge. Commit, then challenge, then respond — the order is the protocol.

It is the tunnel again. Peggy must choose her side before Victor calls. A Peggy who could decide after hearing the challenge proves nothing at all, and Nelson has built exactly that.

Every scheme in this chapter has the same three-move shape — commitment, challenge, response — and it is not decoration. It is the minimum structure that manufactures the simultaneity the warm-up identified as the core difficulty.

41. Nelson proves he can factor

Anomaly

Exercise 3. Nelson wants to prove he knows the factorisation of n. Victor picks a random x, sends y ≡ x², and Nelson returns a square root s. Victor checks s² ≡ y. Repeat twenty times.

Predict first

What is wrong?

  • Nothing — Nelson never reveals p or q
  • Victor learns the factorisation, because Nelson is acting as a square-root oracle
  • Nelson cannot compute s
  • Eve learns the factorisation from the transcript

Correct: Victor learns the factorisation, because Nelson is acting as a square-root oracle

The structural fault: the verifier chooses the value whose root is revealed. In a real zero-knowledge proof the prover chooses her own randomness, and the verifier only chooses which of the prover's own values to see.

Nelson computes s using p ≡ q ≡ 3 (mod 4), taking roots mod p and mod q by the (p+1)/4 formula and recombining by CRT — the mechanics of Chapter 18's protocol, in an unsafe wrapper.

Eve, by contrast, learns nothing useful. She hears y and s but not x, and a square root of a random square is a random number. The leak is specific to Victor because it is his x that pairs with Nelson's s — which is a sharp illustration that a protocol can be safe against eavesdroppers and catastrophic against its own counterparty.

And that is the Chapter 9 discipline restated: never act as a decryption or square-root oracle on inputs someone else chose. Nelson volunteered to be one.

Why: Victor knows x. Nelson returns some root s of x², and half the time s ≢ ±x — at which point gcd(x − s, n) is a nontrivial factor. Twenty rounds and Victor has p and q with overwhelming probability. Nelson has proved his claim by giving away the thing he was proving he knew.

Figure (svg): Naive Nelson's broken protocol, in which Victor chooses the challenge value and thereby extracts a factorisation.

The difference from a real proof: here the verifier chooses the value whose root is revealed.

42. Which of these are zero-knowledge?

Discrimination

Four protocols in which Peggy demonstrates knowledge of a secret.

Sort into buckets

Sort each.

Zero-knowledge
The tunnel protocol; The Schnorr identification scheme
Not zero-knowledge
Peggy sends s encrypted with Victor's public key; Nelson returning roots of Victor's chosen squares
zk
In both, the transcript can be simulated by someone who knows nothing: choose the challenge first and work backwards. Victor's conviction comes from his own knowledge that his challenges were unpredictable, and that does not transfer.
no
Sending s encrypted gives Victor the secret outright — he can now impersonate Peggy anywhere. Nelson's protocol is subtler and just as bad: Victor extracts the factorisation from responses to values he chose.

43. Match each scheme to the problem its soundness rests on

Matching

Every protocol here is a shell around a hard problem.

Match the pairs

  • m1. Square-root protocol
  • m2. Feige-Fiat-Shamir
  • m3. Schnorr identification
  • m4. The tunnel
  • n1. Taking square roots mod n, equivalent to factoring
  • n2. Square roots mod n, with k of them at once
  • n3. The discrete logarithm problem
  • n4. No computational problem — a physical door

Why: The first three are the same protocol skeleton wrapped around different hard problems, which is why swapping the problem changes nothing structural. The fourth has no hard problem at all, and that is what makes it a good teaching example: the three-move structure is doing the work, and the algebra is interchangeable.

44. What if Victor is not honest?

Edge cases

The soundness argument assumes Victor picks his challenges at random. Suppose he does not.

Discussion prompt

What can a dishonest verifier try, and does the protocol survive?

Hint: He wants information, not to be convinced.

Answer:

He can choose challenges adaptively, hoping to extract something. For the schemes here it gains him nothing: whichever bit he sends, he receives a uniformly random value he could have generated himself.

He can ask the same commitment twice, which is the real attack — if Peggy answers both challenges on one x, her secret falls out. So Peggy must refuse, and the rule 'one challenge per commitment' is her responsibility, not Victor's.

He can try to make Peggy an oracle, as Victor does to Nelson. The defence is structural: in a correct protocol Peggy only ever reveals functions of her own randomness, so a verifier-chosen value never enters her computation directly.

The formal distinction is honest-verifier zero-knowledge versus the full property. The schemes in this chapter are provably zero-knowledge against an honest verifier, and the stronger statement needs more work — which is why the literature is careful to say which one it has proved.

And a note in the other direction: none of this authenticates Victor to Peggy. The fake ATM cannot steal her PIN any more, but it can still refuse her card and waste her afternoon. Mutual authentication needs the protocol run in both directions.

45. Order these by soundness error, worst first

Ranking

Five parameter choices.

Put in order

  1. Tunnel protocol, 1 round
  2. Square-root protocol, 5 rounds
  3. Feige-Fiat-Shamir, k = 5, t = 2
  4. Feige-Fiat-Shamir, k = 5, t = 4
  5. Schnorr with 40-bit challenges

Why: 2⁻¹, then 2⁻⁵, then 2⁻¹⁰, then 2⁻²⁰, then 2⁻⁴⁰. Note that the last is a single round: Schnorr gets its security from the size of the challenge space rather than from repetition, which is why it needs three messages where the others need eighty.

46. Design a password-free login

Constraint

A web service wants users to log in without the server ever storing anything worth stealing, and without a password crossing the wire.

Discussion prompt

Design the protocol, and say what a database breach yields.

Hint: Commitment, challenge, response — and think about what the server stores.

Answer:

Enrolment: the client generates a key pair and sends only the public value. The server stores a username and that public value. No secret is ever transmitted or stored server-side.

Login: the server sends a random challenge; the client responds with a signature or a Schnorr-style proof of knowledge of the private key; the server verifies against the stored public value.

The challenge must be server-generated, unpredictable, and single-use. All three of the flaws in the earlier error-hunt slide were violations of this one requirement.

A breach yields public keys, which are useless for impersonation — an attacker can verify proofs but cannot produce them. Contrast a password file, where even hashed entries are attackable offline.

The private key must live somewhere the user cannot leak it, which in practice means a secure element or a TPM, and the operational hard part becomes recovery: no secret on the server means no reset link. Passkeys handle this with multiple enrolled devices and account recovery flows, and that machinery is larger than the cryptography.

Which is exactly Arthur's trade from earlier, met again in a modern setting: destroying the secrets removes the breach risk and moves the whole problem to enrolment and recovery.

47. Reading the soundness bound

Cost model

One expression governs every parameter choice in the chapter.

Annotate

On: \( \Pr[\text{impostor accepted}] = 2^{-kt} \)

  • How many bits Victor challenges at once. Costs Peggy k stored secrets and the directory k public values, but nothing in round trips.
  • Costs a full round trip each — the expensive resource when the verifier is a terminal and the prover is a card.
  • Rounds are independent and challenges within a round are independent, so all kt bits multiply. There is no interaction term.
  • The size of n. Soundness here is combinatorial, not computational — a bigger modulus does not improve these odds. It only ensures the underlying square roots stay hard.
  • Buy security with k, which is nearly free, and spend t only as far as latency allows. k = 5, t = 4 is that calculation made.

Two knobs with very different costs and identical effect on the exponent — which is why knowing where a bound comes from is worth more than memorising the recommended values.

48. What zero-knowledge does not promise

Missing information

The term is used loosely in marketing material.

Discussion prompt

List what a zero-knowledge proof leaves undetermined.

Hint: Consider what is proved, to whom, and under what assumptions.

Answer:

That Peggy is authorised, as opposed to knowing the secret. The proof establishes knowledge of s and nothing about whether the holder should have it. A stolen card proves knowledge perfectly well.

That Victor is who he claims. These protocols are one-directional. The fake ATM can no longer harvest secrets, but it is still a fake ATM.

That the transcript is unlinkable. Peggy's public values are derived from her identity string, so every session identifies her — zero-knowledge about the secret, fully identifying about the person. Anonymity is a separate property, and Chapter 16's blind signatures are what provide it.

That nothing leaks through side channels. Timing of Peggy's response can reveal the Hamming weight of the challenge bits she processed, and Chapter 14's fault attacks apply directly to a smart card computing these products.

That the implementation used fresh randomness. Every scheme here collapses completely on nonce reuse, and that failure is invisible from outside until someone collects two transcripts.

49. What Victor knows at the end

Two truths and a lie

Two of these overstate the guarantee.

Eliminate the wrong options

Which statement is correct?

  • a. Victor is convinced Peggy knows s, and holds nothing that would convince a third party
  • b. Victor has a mathematical proof that Peggy knows s
  • c. Victor could replay the transcript to a third party as evidence

Survives elimination: a

Why: The two clauses are the point of the whole chapter, and they sit oddly together until you separate conviction from information. Victor's certainty rests on private knowledge — that his own challenges were unpredictable — and private knowledge does not travel with the transcript.

50. Which failure would you actually expect?

Commit first

A bank deploys Feige-Fiat-Shamir on smart cards, with k = 5, t = 4, and a 2048-bit n.

Predict first

What is the realistic failure?

  • An impostor guesses all twenty challenge bits
  • A weak random number generator in the card repeats r
  • Someone factors the 2048-bit n
  • The hash function used for the vᵢ is broken

Correct: A weak random number generator in the card repeats r

This is the chapter's most transferable warning. The mathematics assumes a uniform, unrepeated random value on every run, and the assumption is invisible in the protocol description while being the first thing an embedded implementation gets wrong.

The fix is the same as for signatures: derive the randomness deterministically from the secret and the session data, so that it is unpredictable to outsiders and unrepeatable by construction rather than by luck.

And note where the vulnerability is not. The parameters, the modulus size and the hash are all fine. The failure sits in an implementation detail that no amount of parameter tuning addresses — Chapter 14's lesson, one more time.

Why: A repeated r hands over the secrets to any verifier who challenges the same commitment twice — and smart cards are exactly the devices with poor entropy sources, no clock, and no operating system to seed from. Guessing twenty bits happens once in a million impersonation attempts, and 2048-bit factoring is not on the table.

51. Explain zero-knowledge to a sceptic

Explain it

Someone objects: if Victor ends up certain, he must have learned something, and if he learned nothing, he cannot be certain.

Discussion prompt

Answer the objection.

Hint: Separate what he is certain of from what he could tell someone else.

Answer:

Distinguish two things: learning that Peggy knows the secret, and learning anything about the secret. Only the second is forbidden.

Victor's certainty comes from a fact he supplied himself — that his challenges were unpredictable to Peggy. Nothing Peggy sent carries that fact; it lives in his own head.

The test is whether he could have produced the same transcript alone. He could: choose the challenges first, work the responses backwards. Something anyone can fabricate cannot be evidence of anything.

So the transcript is worthless and the experience is not, and the difference between them is who chose the challenges. That asymmetry is the whole trick.

Concretely, in the square-root protocol: he collects twenty square roots of twenty random squares. Every single one he could have generated by squaring a random number. He is holding a stack of numbers he could have written himself — and yet he watched Peggy produce them on demand for values he chose, which she could not have prepared for.

Figure (svg): A simulator producing a convincing transcript without the secret, by choosing the challenge before the commitment.

The simulator argument, which is why a video of the tunnel convinces nobody: anyone could have shot it.

52. The scheme at the teller machine

Concept

Putting the pieces together into the transaction the chapter opened with.

  1. The machine reads I from Peggy's card
  2. It downloads n, j₁, …, j_k from a database
  3. It computes vᵢ = H(I ‖ jᵢ) for each i — the public values, derived rather than stored
  4. It runs the four Feige-Fiat-Shamir steps t times
  5. After a few iterations it is convinced and dispenses cash

The book is candid about the naive version: a person typing all this by hand would be typing a very long time. The real implementation puts the sᵢ in a chip on the card, arranged so they cannot be extracted, and the chip does the arithmetic.

But the security property survives either way, and it is the one the fake machine defeated: a counterfeit terminal recording the entire exchange learns nothing it can reuse. It sees a commitment, a challenge it chose, and a response — a transcript it could have fabricated.

Figure (svg): Arthur's one-time setup: hashing an identity string, keeping the hashes that are squares, and handing Peggy their roots.

The public values are derived from the identity itself, so nothing about Peggy needs to be stored to check her.

53. What the fake ATM would capture now

Worked example

Worth running explicitly, because it is the chapter's original question answered in full.

The fake machine reads I from the card

Why: Public information. It could have looked this up.

It sends challenge bits and records Peggy's x and y

Why: One transcript per round, t rounds.

It later approaches a real machine and presents a cloned card

Why: The real machine sends its own challenge bits, chosen at random.

The recorded responses match only if the challenge strings match

Why: Probability 2⁻ᵏᵗ = 2⁻²⁰ with the recommended parameters.

Verify: so the recording is worth about one chance in a million

Why: Compare the original attack, where a recorded PIN worked every time forever. The difference is not that the secret is better protected — it is that nothing the machine could record was ever the secret.

Figure (svg): Arthur's one-time setup: hashing an identity string, keeping the hashes that are squares, and handing Peggy their roots.

The public values are derived from the identity itself, so nothing about Peggy needs to be stored to check her.

54. Could the fake machine record more rounds?

Prediction

Predict first

Does the extra data help it impersonate Peggy?

  • Yes — more transcripts narrow down the secrets
  • No — every transcript is a value it could have generated itself, and the real machine's challenges are still unpredictable
  • Yes, after about 2ᵏ rounds
  • Only if it also knows n

Correct: No — every transcript is a value it could have generated itself, and the real machine's challenges are still unpredictable

The one thing the fake machine could try is asking the same commitment twice — which is why Peggy's device must never answer two challenges on one x. That rule is the prover's responsibility and it is the only way this attack succeeds.

This is the practical payoff of the simulator argument. 'Victor learns nothing' is not a statement about one session; it composes across arbitrarily many, which is what makes the property worth proving in that form.

Why: Each round is independently simulatable, so a hundred of them carry exactly as much information about the secrets as zero of them: none. What the impostor needs is the ability to answer a future challenge on a fresh commitment, and no quantity of past transcripts supplies it.

55. Commit, challenge, respond

Pattern

Every protocol in this chapter has the same three-move shape, and recognising it is worth more than any individual scheme.

  1. Commit. Peggy fixes a random value and sends something binding — a square, a power, a side of the tunnel. She cannot change it afterwards.
  2. Challenge. Victor sends something Peggy could not predict. Its unpredictability is the entire security; a predictable challenge makes the protocol vacuous, as Nelson's variants show.
  3. Respond. Peggy reveals a function of her commitment and the challenge — never her secret, and never enough to answer a second challenge on the same commitment.

Soundness comes from the ordering: answering two different challenges on one commitment is equivalent to knowing the secret, so a cheat can answer at most one and must guess in advance.

Zero-knowledge comes from the simulator: reverse the order — pick the challenge first, work backwards — and you get a transcript with the same distribution and no secret. Anything forgeable is not evidence.

And the transform: replace Victor with H(commitment ‖ message) and the proof becomes non-interactive and publicly verifiable. That single substitution turns identification schemes into signature schemes, and it is why this chapter's ideas outlived its protocols.

Figure (svg): The Fiat-Shamir transform: replacing the verifier's random challenge with a hash of the commitment.

Remove the verifier by letting a hash function play their part — one of the most consequential tricks in the subject.

56. A zero-knowledge proof means nothing leaks

Trap

The trap

The trap. The property is proved: Victor's transcript can be simulated without the secret, so it contains no information about it. Therefore a system built on a zero-knowledge protocol leaks nothing about the secret, and no further analysis of the secret's exposure is required.

The theorem is correct and the proofs are real. The conclusion still fails in practice, and it fails in four distinct ways.

The fix

The proof is about the transcript, not the execution. Timing, power draw and electromagnetic emissions from a card computing r · s₁s₃ are outside the model entirely, and Chapter 14 shows they are enough. A protocol can be zero-knowledge and a chip running it still leaks its secrets.

The proof assumes fresh randomness. Reuse r once and the secret is a subtraction away. Nothing in the zero-knowledge theorem covers a repeated nonce, because the theorem's hypothesis is exactly what the reuse violates.

Zero-knowledge about s is not anonymity about Peggy. The public values are derived from her identity string, so every session says unmistakably who is proving. Two different properties, routinely conflated.

And it says nothing about authorisation. A thief holding Peggy's card proves knowledge flawlessly. Proving you hold the secret and being entitled to what it unlocks are separate questions, and only the first is cryptographic.

The accurate claim is narrow: the messages exchanged, in an execution with fresh randomness, could have been generated without the secret. Every word of that is load-bearing, and the gap between it and 'nothing leaks' is where real systems fail.

57. Check: what makes the protocol sound

Check

Work it out before clicking.

Check your understanding

In the square-root protocol, why can a Peggy who does not know s answer at most one of the two challenges?

  • A. Because computing square roots mod n is hard
  • B. Because knowing roots of both x₁ and x₂ would give a root of x₁x₂ = y, which is s (correct)
  • C. Because Victor checks x₁x₂ ≡ y
  • D. Because she cannot factor n

Answer: B

Why: The argument is logical rather than computational: the product of the two roots is a root of y. So being able to answer both is not merely difficult — it is identical to knowing the secret. Anyone who does not know s is missing at least one root, and Victor asks for the missing one half the time.

Why A tempts people
True, and it is why she cannot compute the missing root — but it does not explain why one of the two must be missing. That is the step B supplies.
Why C tempts people
That check ties the round to y and is necessary, but on its own it does not prevent Peggy sending a pair she can half-answer.
Why D tempts people
Equivalent to A by Section 3.9, and it has the same gap: it explains the difficulty, not the exclusivity.

58. Check: the Feige-Fiat-Shamir bound

Check

Consider the recommended parameters.

Check your understanding

With k = 5 secrets and t = 4 rounds, what is an impostor's chance of success?

  • A. 2⁻⁵
  • B. 2⁻⁹
  • C. 2⁻²⁰ (correct)
  • D. 2⁻⁴⁰

Answer: C

Why: Each round challenges k bits, and only one of the 2ᵏ strings lets an impostor through; the rounds are independent, so the exponents add across rounds: 2⁻ᵏᵗ = 2⁻²⁰. That is the same confidence as twenty rounds of the sequential protocol, obtained in four round trips.

Why A tempts people
That is one round only. The point of repeating is that the errors multiply.
Why B tempts people
Adding k and t rather than multiplying them. The bits within a round and the rounds themselves are all independent, so the total number of bits an impostor must guess is kt.
Why D tempts people
Twice the exponent — this would need k = 5, t = 8, or k = 10, t = 4.

59. Check: what breaks Schnorr

Check

Consider an implementation running on a device with a poor entropy source.

Check your understanding

Peggy runs Schnorr twice with the same k against different challenges. What does an eavesdropper get?

  • A. Nothing, since each y is uniformly distributed
  • B. The value of k only
  • C. The secret a, from a subtraction and an inversion (correct)
  • D. The ability to forge one signature

Answer: C

Why: y₁ − y₂ = a(r₂ − r₁) mod p−1, so a = (y₁ − y₂)(r₂ − r₁)⁻¹. Each transcript alone really is uniform — that is the zero-knowledge property — but two of them are two equations in two unknowns, and the secret drops out immediately.

Why A tempts people
True of either transcript in isolation, which is exactly what makes this failure so easy to miss. The pair is what leaks.
Why B tempts people
k falls out too once a is known, but a is the prize and the equations give it directly.
Why D tempts people
It is far worse than one forgery — the attacker has the long-term secret and can impersonate Peggy indefinitely.

60. Write the three-move skeleton out

Connect it up

Four protocols, one shape.

Draw it

Write out the commit-challenge-respond skeleton, then instantiate it four times: the tunnel, the square-root protocol, Feige-Fiat-Shamir, and Schnorr. For each, name the commitment, the challenge space, the response, and the hard problem soundness rests on. Then, beside each, write the one line that would break it — the reuse, the prediction, or the missing commitment. Finish by writing the Fiat-Shamir substitution and saying what it turns each scheme into.

The table is the chapter. Once the skeleton is visible, a new scheme is read by asking four questions rather than by following someone else's algebra.

61. Exit ticket

Exit ticket

One question, on the idea that makes the chapter possible.

Predict first

Why does a zero-knowledge transcript convince Victor but not a third party?

  • Because it is encrypted to Victor
  • Because Victor knows his own challenges were unpredictable, and that knowledge is not in the transcript
  • Because the transcript is deleted afterwards
  • Because a third party cannot verify the arithmetic

Correct: Because Victor knows his own challenges were unpredictable, and that knowledge is not in the transcript

Why: The transcript can be manufactured by choosing the challenges first and working backwards, so it is consistent with both a genuine prover and a fabrication. What separates the two for Victor is a private fact — that his challenges were random and unforeseeable — and that fact does not travel with the messages.

62. What to carry into Chapter 20

Recap

Proving knowledge without transmitting anything reusable.

Chapter 20 next. Information theory: Shannon's framework for measuring how much a ciphertext actually tells an adversary, entropy and unicity distance, and a precise statement of what perfect secrecy costs — the formal apparatus behind claims this course has so far made informally.

Figure (svg): The three defining properties of a zero-knowledge proof arranged as three separate guarantees.

Three properties, three different kinds of argument — and the third is what makes the chapter's title honest.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 19 — Zero-Knowledge Techniques (sections 19.1-19.3) — Trappe & Washington, 3rd edition, pp. 357-368

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108