diff options
author  Florian Dold <florian.dold@gmail.com>  20180925 16:56:00 +0200 

committer  Florian Dold <florian.dold@gmail.com>  20180925 16:56:00 +0200 
commit  e5e5df3d72eb6b1d9e4681e2a22c057ed8fb8e76 (patch)  
tree  27f7cd859513a364fe1408eeb80ecd4bb082d60b  
parent  74f745bb854ad16f10b1f9dc9b3bef55236e32e8 (diff)  
download  paperse5e5df3d72eb6b1d9e4681e2a22c057ed8fb8e76.tar.gz paperse5e5df3d72eb6b1d9e4681e2a22c057ed8fb8e76.tar.bz2 paperse5e5df3d72eb6b1d9e4681e2a22c057ed8fb8e76.zip 
hash instead of commitment
rwrr  talerfc19/paper.tex  7 
1 files changed, 4 insertions, 3 deletions
diff git a/talerfc19/paper.tex b/talerfc19/paper.tex index 3778c63..5fcc910 100644  a/talerfc19/paper.tex +++ b/talerfc19/paper.tex @@ 1241,9 +1241,10 @@ Our instantiation satisfies {weak income transparency}. We show these to be exhaustive by assuming their converses all hold: As the
commitment is signed by $\V{skCoin}_0$, our key exchange completeness
 assumption of $\textsc{CoinSignKx}$ applies to the coin public key. Any
 commitments that match were computed honestly, thanks to our commitment
 scheme $(\algo{Setup}_C, H_{pk})$ being computationally binding. We assumed
+ assumption of $\textsc{CoinSignKx}$ applies to the coin public key.
+ Any revealed values must match our honestly computed commitments,
+ as otherwise a collision in $H$ would have been found.
+ We assumed
the revealed $\gamma$th transfer public key is honest. Hence our key
exchange completeness assumption of $\textsc{CoinSignKx}$ yields
$\algo{Kex}_{CSK}(t,C') = \algo{Kex}_{CSK}(c',T)$ where $T =
