RFC 8235
Schnorr Non-interactive Zero-Knowledge Proof, September 2017
- File formats:
- Status:
- INFORMATIONAL
- Author:
- F. Hao, Ed.
- Stream:
- INDEPENDENT
Cite this RFC: TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC8235
Discuss this RFC: Send questions or comments to the mailing list rfc-ise@rfc-editor.org
Other actions: View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 8235
Abstract
This document describes the Schnorr non-interactive zero-knowledge (NIZK) proof, a non-interactive variant of the three-pass Schnorr identification scheme. The Schnorr NIZK proof allows one to prove the knowledge of a discrete logarithm without leaking any information about its value. It can serve as a useful building block for many cryptographic protocols to ensure that participants follow the protocol specification honestly. This document specifies the Schnorr NIZK proof in both the finite field and the elliptic curve settings.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.