Interactive Proofs and Zero-Knowledge
y QRn
Pr($a, a2 mod n=w•yb mod n)1/2