[CFRG] Re: Incorporating OR Proofs in Sigma Protocol Draft
Michele Orrù <michele.orru@ens.fr> Fri, 12 September 2025 17:19 UTC
Return-Path: <michele.orru@ens.fr>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 683DD61B9EDD for <cfrg@mail2.ietf.org>; Fri, 12 Sep 2025 10:19:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.394
X-Spam-Level:
X-Spam-Status: No, score=-4.394 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=ens.fr
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gcKbzuQpS8GF for <cfrg@mail2.ietf.org>; Fri, 12 Sep 2025 10:19:23 -0700 (PDT)
Received: from nef.ens.fr (nef2.ens.fr [129.199.96.40]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 74C9261B9EB7 for <cfrg@irtf.org>; Fri, 12 Sep 2025 10:19:23 -0700 (PDT)
X-ENS-nef-client: 129.199.99.32 ( name = mail.di.ens.fr )
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ens.fr; s=default; t=1757697562; bh=+LeoMmb23WR1MFCGbR8zIFaVitxtaKFvjoII5RwTHCM=; h=References:In-Reply-To:From:Date:Subject:To:Cc:From; b=XL+aF2WAlupVx0zrusPBwC8ld9pYZhUlymwwXVGhJd8qI0oRfPSvIFhx5tkJF28f9 tMxZdNqH5dfN/2Dedfab1nWgFTBtIhsz25+RZfaD+7If4SENwm81pd1ABiIYkktCOj aO5Exe05F9qXV9r+XvJE7Xs6+2vLhYLlL4nAe0NE=
Received: from mail.di.ens.fr (mail.di.ens.fr [129.199.99.32]) by nef.ens.fr (8.14.4/1.01.28121999) with ESMTP id 58CHJM4v030595 for <cfrg@irtf.org>; Fri, 12 Sep 2025 19:19:22 +0200
Received: from mail-qv1-f48.google.com using smtps by mail.di.ens.fr (8.15.2/jb-1.1) id 58CHJLqS014874 for <cfrg@irtf.org>; Fri, 12 Sep 2025 19:19:21 +0200 (authenticated user morru)
X-Envelope-To: <cfrg@irtf.org>
Received: by mail-qv1-f48.google.com with SMTP id 6a1803df08f44-722d5d8fa11so17777146d6.3 for <cfrg@irtf.org>; Fri, 12 Sep 2025 10:19:21 -0700 (PDT)
X-Forwarded-Encrypted: i=1; AJvYcCUwXdn2Mr8TUjyGTU8hGTu6mzHox8nJDJpzTfiWShdL8WbbbgDbRAYMT4C5zVidN7NaAnPx@irtf.org
X-Gm-Message-State: AOJu0YyNHOSYAupETgTdXGdIBBGbKMH/t3mTjB35M7zFSUrQZxZCJJAY WXjjQ5SWNv7UVfttQHpuc0YG9QlTcizFnbUDuPsWFXGM5x1+YoGGZYV7NHvKC3wjKY+7QcQ/nN5 PJ7VGOYJnuu0QEAU9/9ZlE5MxgWli8AnSrwEr97Q4nA==
X-Google-Smtp-Source: AGHT+IFeDv+nN54c8APTen9aEbDU6pccXLNQCmeBsJzfWaAb5CnARINtEy3T/dR7LXuT4SR8SxfoPnTIfWEB4zfnin4=
X-Received: by 2002:ad4:5cae:0:b0:725:cd10:3d1d with SMTP id 6a1803df08f44-767bc5e525dmr51019816d6.16.1757697555863; Fri, 12 Sep 2025 10:19:15 -0700 (PDT)
MIME-Version: 1.0
References: <CANWAzd4kL8Dhs4rDV62CX96PBksOvzWm1+xAVQnFJVdJ2Gd0tw@mail.gmail.com> <CAOyO2_+SURo_rxs8MDiY-mMnumS6k3frJrcGL8kaP31mTmeScA@mail.gmail.com> <CAG2Zi22mnnsnjJOA9V4eXNYH25RUf1BPs_FBuXnd70j4DWDw4A@mail.gmail.com> <CACsn0cnsL0JXiUp_wtfWVHJ7G3na9rXEh=Hs4=Ai=S6oWW_RpA@mail.gmail.com> <CADhumskG=OUzzBQUe1XkkRpZg2NCLhQZizpUM2YfDfhjkFxL9g@mail.gmail.com> <aLcmHQpG0KhGgmhu@yoink.cs.uwaterloo.ca> <CAG2Zi204Oi4Opuaj72wh8S+O+5zMFHPNxKC-g5uLnxX-fmF2vw@mail.gmail.com> <CACsn0cmc68b4vG=Dy30qUdDM454h682td_m7+K-0wJNiavXcPQ@mail.gmail.com> <CAG2Zi220UNW6HN=zFt241gpN1cZj=7QcjVsubU8UF-WuQgKQbA@mail.gmail.com> <CAOyO2_LQ5_bavoRS6p1q9z=47yDOd51W6gB=08S9ksf+yBrzaQ@mail.gmail.com> <CADhumsnyHKoBHnuTxFQOxAE6ZLOQp1tenj=+b5MVizJf136==A@mail.gmail.com> <CAOyO2_KE6qyxi1tDBCnGvqGmWQpyGYQZRGTd5C+f8gfuLyt_WQ@mail.gmail.com> <CACZapPrZP6L6_eyNZxZr9Vpaoca7J57VMSf_dLWad_FSggfOmA@mail.gmail.com> <CADhumske-Ft=UJQH-yYC5rpYO5AY6p0xxDOJ8sfR56Y=YZOFyg@mail.gmail.com>
In-Reply-To: <CADhumske-Ft=UJQH-yYC5rpYO5AY6p0xxDOJ8sfR56Y=YZOFyg@mail.gmail.com>
From: Michele Orrù <michele.orru@ens.fr>
Date: Fri, 12 Sep 2025 19:18:59 +0200
X-Gmail-Original-Message-ID: <CAOyO2_JcxHZXMpixeAup2rVPxwZEo2ua3uEsTUnPrvA+G39N0g@mail.gmail.com>
X-Gm-Features: AS18NWCcVIbznQZNM9CK97GWkgAr13_-slZQNu8s0kAD0Rjf-vxh8uYykNgcp5w
Message-ID: <CAOyO2_JcxHZXMpixeAup2rVPxwZEo2ua3uEsTUnPrvA+G39N0g@mail.gmail.com>
To: Jonathan Katz <jkcrypto@google.com>
Content-Type: multipart/alternative; boundary="00000000000070c8f4063e9ddaab"
X-Virus-Scanned: by amavisd-milter (http://amavis.org/)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.4.3 (nef.ens.fr [129.199.96.32]); Fri, 12 Sep 2025 19:19:22 +0200 (CEST)
Message-ID-Hash: D2LUCSXTQBUQWPX7YEMS2KQ7CEMEP4FT
X-Message-ID-Hash: D2LUCSXTQBUQWPX7YEMS2KQ7CEMEP4FT
X-MailFrom: michele.orru@ens.fr
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Ian Goldberg <iang@uwaterloo.ca>, cfrg@irtf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Incorporating OR Proofs in Sigma Protocol Draft
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/F5eCRmcLd_CT_8yL_CLbG-BAd6U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
hah, thanks Jonathan and Nirvan for correcting me! Reading back Ivan's paper, he wrote literally the opposite of what I said: > It is interesting to note that even though POR is WH, this does not have to be the case for the protocol P we start from. Thus the OR construction is a very economic way of producing extra security: the complexity is only about twice that of P. I’m not sure whether we’re still considering adding an OR proof spec, but I hope this is useful regardless—thanks! On Fri, Sep 12, 2025 at 6:57 PM Jonathan Katz <jkcrypto@google.com> wrote: > Yes, if the original protocols are each HVZK then the OR-protocol obtained > by combining the two is also HVZK. > > On Fri, Sep 12, 2025 at 12:52 PM Nirvan Tyagi <nirvan.tyagi@gmail.com> > wrote: > >> I believe the "standard" OR composition that I'm aware of also provides >> special HVZK. The Boneh-Shoup book is a reference ( >> https://toc.cryptobook.us/book.pdf , Sec 19.7.2, Theorem 19.19). >> >> Best, >> Nirvan >> >> On Fri, Sep 12, 2025 at 9:39 AM Michele Orrù <michele.orru@ens.fr> wrote: >> >>> Hi Jonathan, >>> >>> My knowledge of OR composition comes mostly from Damgård, in >>> https://www.cs.au.dk/~ivan/Sigma.pdf >>> There, OR composition seems to guarantee only witness >>> indistinguishability, and if the relation is hard witness hiding. >>> What I meant in my message is: right now we can talk only about a >>> special honest-verifier zero-knoweldge protocol; would we have to talk >>> about witness indistinguishability in the case of OR proofs? >>> >>> On a separate note, thank you so much for your feedback on the spec, >>> I'll go over it soon! >>> _______________________________________________ >>> CFRG mailing list -- cfrg@irtf.org >>> To unsubscribe send an email to cfrg-leave@irtf.org >>> >>
- [CFRG] Incorporating OR Proofs in Sigma Protocol … Lena Heimberger
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Cathie Yun
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Michele Orrù
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Ian Goldberg
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Watson Ladd
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Christopher Patton
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Watson Ladd
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Watson Ladd
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Jonathan Katz
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Ian Goldberg
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Christopher Patton
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Watson Ladd
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Christopher Patton
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Michele Orrù
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Christopher Patton
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Michele Orrù
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Ian Goldberg
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Christopher Patton
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Jonathan Katz
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Michele Orrù
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Nirvan Tyagi
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Jonathan Katz
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Michele Orrù
- [CFRG] Re: Incorporating OR Proofs in Sigma Proto… Cathie Yun