Documentation

CatCryptCore.Crypto.Assumptions.DL

Discrete Logarithm Assumption #

This file defines the DL (Discrete Logarithm) assumption for pairing groups. The DL assumption is used for the hiding property of KZG.

Main definitions #

Cross-Validation #

PropertyThis fileTextbook
Game structureDL_GameBoneh-Shoup Def. 10.4
AdvantageprTrue(DL_Game)Pr[DLadv]
GroupPairingGroup PCyclic group of prime order

Equivalent formalizations:

References #

Discrete Logarithm Game #

@[reducible, inline]

Type of DL adversary: receives a group element h = g₁^x, must output x

Equations
Instances For

    The discrete log game in G₁: sample x, give g₁^x to adversary, check answer

    Equations
    • One or more equations did not get rendered due to their size.
    Instances For