Interactive Proofs
and Zero-Knowledge
y
’àâ
QR
n
Pick rand bit b
Pr(
$
a, a
2
mod n=w•y
b
mod n)
’â§
1/2