形式陈述
对三步公开币协议,把验证者随机挑战替换为
证明者输出
直觉
哈希值被当作不可由证明者预先控制的公共随机挑战,从而省去在线验证者。
例子与边界
直接把挑战写成
推论与应用
它支撑 Schnorr 类签名、非交互知识证明和大量区块链证明系统中的 transcript 压缩。
参考资料
- Amos Fiat, Adi Shamir, How to Prove Yourself: Practical Solutions to Identification and Signature Problems (1986), original transform.
- Dan Boneh, Victor Shoup, A Graduate Course in Applied Cryptography (2023/2026 draft), Fiat–Shamir and signatures.