T1 - Low communication 2-prover zero-knowledge proofs for NP

AU - Dwork, Cynthia

AU - Feige, Uri

AU - Kilian, Joe

AU - Naor, Moni

AU - Safra, Muli

PY - 1993

N2 - We exhibit a two-prover perfect zero-knowledge proof system for 3-SAT. In this protocol, the verifier asks a single message to each prover, whose size grows logarithmically in the size of the 3-SAT formula. Each prover’s answer consists of only a constant number of bits. The verifier will always accept correct proofs. Given an unsatisfiable formula 5 the verifier will reject with probability at least Ω((|S|— max-sat (S))/|S|, where max-sat (S) denotes the maximum number of clauses of S that may be simultaneously satisfied, and |S| denotes the total number of clauses of S. Using a recent result by Arora et al [2], we can construct for any language in NP a protocol with the property that any non-member of the language be rejected with constant probability.

BT - Advances in Cryptology — CRYPTO 1992 - 12th Annual International Cryptology Conference, Proceedings

T2 - 12th Annual International Cryptology Conference, CRYPTO 1992

