On emulating interactive proofs with public coins

Oded Goldreich, Maya Leshkowitz

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

The Goldwasser-Sipser emulation of general interactive proof systems by public-coins interactive proof systems proceeds by selecting, at each round, a verifier-message such that each message is selected with probability that is at most polynomially larger than its probability in the original protocol. Specifically, the possible messages are essentially clustered according to the probability that they are selected in the original protocol, and the emulation selects a message at random among those that belong to the heaviest cluster. We consider the natural alternative in which, at each round, if the parties play honestly, then each verifier-message is selected with probability that approximately equals the probability that it is selected in the original (private coins) protocol. This is done by selecting a cluster with probability that is proportional to its weight, and picking a message at random in this cluster. The crux of this paper is showing that, essentially, no matter how the prover behaves, it cannot increase the probability that a message is selected by more than a constant factor (as compared to the original protocol). We also show that such a constant loss is inevitable.

Original languageEnglish
Title of host publicationLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
EditorsOded Goldreich
PublisherSpringer Verlag
Chapter12
Pages178-198
Number of pages21
DOIs
StatePublished - 4 Apr 2020

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12050 LNCS

All Science Journal Classification (ASJC) codes

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'On emulating interactive proofs with public coins'. Together they form a unique fingerprint.

Cite this