<<  >> (p.13)
    Author Topic: Deterministic wallets  (Read 48531 times)
    thanke
    Member
    **
    Offline Offline

    Activity: 104
    Merit: 10


    View Profile
    May 12, 2013, 03:55:20 PM
     #241

    You can prove that you know c_par such that both (I_L,I_R)=hash(c_par, K_par, i) and K_i=I_L*K_par, without revealing c_par itself, via zero-knowledge computational integrity (PCP) proofs.

    Really, you can zero-knowledge prove that you know a preimage of a hash?
Page 12
Viewing Page: 13