SLIDE 34 Our Protocol
Prove that 𝑙𝑗 is small. Prove that 𝐸
𝑘,𝑗 and 𝐸 𝑘,𝑗 ′ were
computed as prescribed using sm small ll values
Check that 𝜀 = ς𝑘 Δ𝑘
Prove that you use the right 𝑙𝑗.
1. Sample 𝑙𝑗, 𝛿𝑗 ← 𝔾𝑟 and send 𝐿𝑗 = enc𝑗(𝑙𝑗) to all.
𝑗 = 𝛿𝑗 and for each 𝑘 ≠ 𝑗 do
𝑘,𝑗 = 𝐿 𝑘 𝑦𝑗 ⋅ enc𝑘 𝛾𝑗,𝑘 and 𝐺 𝑘,𝑗 = enc𝑗 𝛾𝑗,𝑘
𝑘,𝑗 ′ = 𝐿 𝑘 𝛿𝑗 ⋅ enc𝑘 𝛾𝑗,𝑘 ′
and 𝐺
𝑘,𝑗 ′ = enc𝑗 𝛾𝑗,𝑘 ′
Send Γ𝑗, 𝐸
𝑘,𝑗, 𝐸 𝑘,𝑗 ′ , 𝐺 𝑘,𝑗 , 𝐺 𝑘,𝑗 ′
to 𝒬
𝑘.
𝑘 𝑙𝑗 and send Δ𝑗, 𝜀𝑗 to all
ς𝑘 Γ
𝑘 𝜀−1
and send 𝜏𝑗 = 𝑙𝑗 𝑛 + 𝑠𝜓𝑗 to all
Output (𝑠, 𝜏) if it’s a valid sig