4 ms·
But it's a simplification: One iteration is enough to detect lying. In a real ZK proof the probability of the prover lying reduces after each iteration but nev
by nroets 2y ago
But it's a simplification: One iteration is enough to detect lying.
In a real ZK proof the probability of the prover lying reduces after each iteration but never reached 0.
- deleted 2y ago[deleted]
- pxx 2y agothere is a probabilistic interactive component. this protocol allows the prover to fake it by just using a book where they know where Waldo is. in each iteration you choose whether to confirm it's the original book and page under the paper or see Waldo (but not both). a cheating prover has p = .5 of fooling a verifier. but your concern is invalid to begin with. nothing in the definition of a zkp requires them to be multi-round interactive. there exist non-interactive zkp.