SLIDE 25 NON-INTERACTIVE PROOF SYSTEMS GROTH-SAHAI PROOFS CORRECTED GROTH-SAHAI NIWI PROOFS GROTH-SAHAI PROOFS IN TYP
GS PROOFS UNDER THE SDLIN ASSUMPTION We base the security of the proofs on the SDLIN assumption (i.e. requiring the DLIN holds in both G1 and G2). Motivation: ◮ SXDH assumption only works in Type-3 pairings. ◮ DLIN assumption(as presented in GS) only works in Type-1 pairings. ◮ SDLIN assumption works in Type-1,2 and 3 pairings. Efficiency: We set B1 = G3
1, B2 = G3 2 and BT = G9 T, and we have:
F : B1 × B2 → BT (X1, Y1, Z1), (X2, Y2, Z2) → e(X1, X2) e(X1, Y2) e(X1, Z2) e(Y1, X2) e(Y1, Y2) e(Y1, Z2) e(Z1, X2) e(Z1, Y2) e(Z1, Z2)
GROTH-SAHAI PROOFS REVISITED 14 / 18