CDLS: Proving Knowledge of Committed Discrete Logarithms with Soundness
摘要
The works of CRYPTO ’18 [1] and SAC ’21 [15] exist in the \(\varSigma \) -protocol setting in order to prove knowledge that a commitment to a scalar is the discrete logarithm of the commitment to an elliptic curve point. While the former, original work [1] is inadequately specified so that detailed analysis can be performed, we show that the latter follow up work, the \(\varSigma \) -protocol of ZKAttest [15], suffers from soundness issues that invalidate its security proof. Further, we also provide a practical attack on ZKAttest’s public implementation, and point out other flaws in it that differ from the paper’s specification. Lastly, we introduce two new protocols, \(\textsf{CDLSS}\) and \(\textsf{CDLSD}\) , which are sound, provably secure, have concrete security bounds, and perform favourably in comparison to the prior works when the soundness issue is taken into account.