Questions tagged [pedersen-commitment]

9 questions
2
votes
0 answers

Can ElGamal public key be reused for Pedersen commitment's key?

I encrypt data using ElGamal public key $y=g^x$, so nobody knows $x$, being a private key. Also during my service lifetime I perform many Pedersen commitment operations. It is known that Pedersen commitment key is a tuple $(g, h)$. For $g$ I use…
2
votes
0 answers

Proof of Pedersen VSS

How to proof Pedersen Verifiable secret sharing using a game-based proof and reduct to the discrete logarithm problem? Are there any papers that can be referenced?
2
votes
1 answer

Equality check with Pedersen commitments

Does the Pedersen commitment scheme allow for checking whether two commitments are made - say by different people - for the same value?
1
vote
1 answer

Zero knowlede proof of linear relations

Suppose a prover publishes two perfectly hiding commitments for $s_1,s_2$, i.e. two Pedersen commitments $C_1=g^{s_1}h^{r_1}$ and $C_2=g^{s_2}h^{r_2}$ such that $s_1,s_2,r_1,r_2$ are secret field elements. Suppose that there two public field…
1
vote
0 answers

Simulating physical envelops: Will commitments work in this case?

I want to simulate following physical activity in cryptography. Person X has written integers 1, 2, ..., 10 in seperate paper slips. He needs to distribute these slips to 10 people without knowing which slip is given to whom. So, he purchase 10…
1
vote
0 answers

A problem involving Commitments

Suppose there is a set $P=\{p_1, p_2, ..,p_l\}$ of stock buyers who can make commitments to a share $s_i$ in a set $S=\{s_1,s_2,...,s_m\}$ of shares for an amount $a_i$ in a set $A=\{a_1,a_2,...,a_n\}$. They can make commitments only till a certain…
1
vote
1 answer

Cheating in a Pedersen-based auction

Imagine a simple auction made with Pedersen commitments rather than sealed envelopes. Participant 1 commits their bid, $b_1$, choosing a blinding factor $x_1$ and using publicly known G and H generators. As they do so, the commitment value $C_1$…
A. Darwin
  • 496
  • 8
  • 12
0
votes
1 answer

size of pedersen commitment

May I ask that the parameter requirement of Pedersen commitment? For $g^{x~modq}h^{r~modq}mod p$, does p depends on q? Or does it only depend on the security parameter desired? How large will the p needs to be given q? Thanks!
js wang
  • 381
  • 1
  • 10
0
votes
0 answers

What's the simplest and most instructive polynomial interactive oracle proof?

I'm writing my thesis about Zero-Knowledge Proofs and I'm trying to write a short and instructive introduction to zk-SNARKs at the moment (I have to stay within a certain limit of pages). I introduced the general paradigm that SNARKs are often…