Interactive Proofs and Zero-Knowledge
y ’àâ QRn
Pick rand bit b
Pr($a, a2 mod n=w•yb mod n)’â§1/2