{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T01:55:35Z","timestamp":1778291735434,"version":"3.51.4"},"reference-count":33,"publisher":"Elsevier BV","issue":"1","license":[{"start":{"date-parts":[[1991,7,1]],"date-time":"1991-07-01T00:00:00Z","timestamp":678326400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2013,7,17]],"date-time":"2013-07-17T00:00:00Z","timestamp":1374019200000},"content-version":"vor","delay-in-days":8052,"URL":"https:\/\/www.elsevier.com\/open-access\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Theoretical Computer Science"],"published-print":{"date-parts":[[1991,7]]},"DOI":"10.1016\/0304-3975(91)90259-5","type":"journal-article","created":{"date-parts":[[2002,7,26]],"date-time":"2002-07-26T03:47:37Z","timestamp":1027655257000},"page":"23-52","source":"Crossref","is-referenced-by-count":34,"title":["Constant-round perfect zero-knowledge computationally convincing protocols"],"prefix":"10.1016","volume":"84","author":[{"given":"Gilles","family":"Brassard","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Claude","family":"Cr\u00e9peau","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Moti","family":"Yung","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/0304-3975(91)90259-5_BIB1","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1103\/PhysRevLett.49.91","article-title":"Experimental realization of the Einstein-Podolsky-Rosen-B\u00f6hm Gedankenexperiment: A new violation of Bell's inequalities","volume":"49","author":"Aspect","year":"1982","journal-title":"Phys. Rev. Lett."},{"key":"10.1016\/0304-3975(91)90259-5_BIB2","first-page":"482","article-title":"Perfect zero-knowledge in constant rounds","author":"Bellare","year":"1990","journal-title":"Proc. 22nd ACM Symp. on Theory of Computing"},{"key":"10.1016\/0304-3975(91)90259-5_BIB3","series-title":"Advances in Cryptology: CRYPTO '86 Proc.","first-page":"213","article-title":"Cryptographic capsules: A disjunctive primitive for interactive protocols","author":"Benaloh","year":"1987"},{"issue":"3","key":"10.1016\/0304-3975(91)90259-5_BIB4","article-title":"Experimental quantum cryptography","volume":"4","author":"Bennett","year":"1991","journal-title":"J. Cryptology"},{"key":"10.1016\/0304-3975(91)90259-5_BIB5","first-page":"175","article-title":"Quantum cryptography: Public-key distribution and coin-tossing","author":"Bennett","year":"1984","journal-title":"Proc. Internat. Conf. on Computers, Systems and Signal Processing"},{"key":"10.1016\/0304-3975(91)90259-5_BIB6","doi-asserted-by":"crossref","first-page":"850","DOI":"10.1137\/0213053","article-title":"How to generate cryptographically strong sequences of pseudo-random bits","volume":"13","author":"Blum","year":"1984","journal-title":"SIAM J. Comput."},{"issue":"2","key":"10.1016\/0304-3975(91)90259-5_BIB7","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1007\/BF00204448","article-title":"A discrete logarithm implementation of zero-knowledge blobs","volume":"2","author":"Boyar","year":"1990","journal-title":"J. Cryptology"},{"issue":"1","key":"10.1016\/0304-3975(91)90259-5_BIB8","doi-asserted-by":"crossref","DOI":"10.1145\/122413.122414","article-title":"Cryptology column: How convincing is your protocol?","volume":"22","author":"Brassard","year":"1991","journal-title":"Sigact News"},{"issue":"2","key":"10.1016\/0304-3975(91)90259-5_BIB9","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1016\/0022-0000(88)90005-0","article-title":"Minimum disclosure proofs of knowledge","volume":"37","author":"Brassard","year":"1988","journal-title":"J. Comput. System Sci."},{"key":"10.1016\/0304-3975(91)90259-5_BIB10","series-title":"Advances in Cryptology: CRYPTO '86 Proc.","first-page":"224","article-title":"Zero-knowledge simulation of Boolean circuits","author":"Brassard","year":"1987"},{"key":"10.1016\/0304-3975(91)90259-5_BIB11","first-page":"188","article-title":"Non-transitive transfer of confidence: A perfect zero-knowledge interactive protocol for SAT and beyond","author":"Brassard","year":"1986","journal-title":"Proc. 27th IEEE Symp. on Foundations of Computer Science"},{"key":"10.1016\/0304-3975(91)90259-5_BIB12","series-title":"Advances in Cryptology: EUROCRYPT '89 Proc.","first-page":"181","article-title":"Sorting out zero-knowledge","author":"Brassard","year":"1990"},{"key":"10.1016\/0304-3975(91)90259-5_BIB13","series-title":"Proc. 8th. Symp. on Theoretical Aspects of Computer Science","first-page":"251","article-title":"Computationally convincing proofs of knowledge","author":"Brassard","year":"1991"},{"key":"10.1016\/0304-3975(91)90259-5_BIB14","series-title":"Proc. 16th Internat. Coll. on Automata, Languages and Programming","first-page":"123","article-title":"Everything in NP can be argued in perfect zero-knowledge in a bounded number of rounds","author":"Brassard","year":"1989"},{"key":"10.1016\/0304-3975(91)90259-5_BIB15","doi-asserted-by":"crossref","unstructured":"G. Brassard and M. Yung, One-way group actions, in: Advances in Cryptology: CRYPTO '90 Proc. (Springer, Berlin, to appear).","DOI":"10.1007\/3-540-38424-3_7"},{"key":"10.1016\/0304-3975(91)90259-5_BIB16","series-title":"Advances in Cryptology: CRYPTO '86 Proc.","first-page":"195","article-title":"Demonstrating that a public predicate can be satisfied without revealing any information about how","author":"Chaum","year":"1987"},{"key":"10.1016\/0304-3975(91)90259-5_BIB17","series-title":"Advances in Cryptology: CRYPTO '87 Proc.","first-page":"87","article-title":"Multiparty computations ensuring privacy of each party's input and correctness of the result","author":"Chaum","year":"1988"},{"key":"10.1016\/0304-3975(91)90259-5_BIB18","series-title":"Advances in Cryptology: EUROCRYPT '87 Proc.","first-page":"127","article-title":"An improved protocol for demonstrating possession of discrete logarithms and some generalizations","author":"Chaum","year":"1988"},{"key":"10.1016\/0304-3975(91)90259-5_BIB19","series-title":"Advances in Cryptology: CRYPTO '86 Proc.","first-page":"200","article-title":"Demonstrating possession of a discrete logarithm without revealing it","author":"Chaum","year":"1987"},{"issue":"2","key":"10.1016\/0304-3975(91)90259-5_BIB20","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/BF02351717","article-title":"Zero knowledge proofs of identity","volume":"1","author":"Feige","year":"1988","journal-title":"J. Cryptology"},{"key":"10.1016\/0304-3975(91)90259-5_BIB21","series-title":"Advances in Cryptology: CRYPTO '89 Proc.","first-page":"526","article-title":"Zero knowledge proofs of knowledge in two rounds","author":"Feige","year":"1990"},{"key":"10.1016\/0304-3975(91)90259-5_BIB22","first-page":"204","article-title":"The complexity of perfect zero-knowledge","author":"Fortnow","year":"1987","journal-title":"Proc. 19th ACM Symp. on Theory of Computing"},{"key":"10.1016\/0304-3975(91)90259-5_BIB23","unstructured":"O. Goldreich and A. Kahn, Using claw-free permutations to construct zero-knowledge proofs for NP, In preparation."},{"key":"10.1016\/0304-3975(91)90259-5_BIB24","series-title":"Proc. 17th Internat. Coll. on Automata, Languages and Programming","first-page":"268","article-title":"On the composition of zero-knowledge proof systems","author":"Goldreich","year":"1990"},{"key":"10.1016\/0304-3975(91)90259-5_BIB25","first-page":"174","article-title":"Proofs that yield nothing but their validity and a methodology of cryptographic protocol design","author":"Goldreich","year":"1986","journal-title":"Proc. 27th IEEE Symp. on Foundations of Computer Science"},{"issue":"1","key":"10.1016\/0304-3975(91)90259-5_BIB26","doi-asserted-by":"crossref","first-page":"186","DOI":"10.1137\/0218012","article-title":"The knowledge complexity of interactive proof systems","volume":"18","author":"Goldwasser","year":"1989","journal-title":"SIAM J. Comput."},{"key":"10.1016\/0304-3975(91)90259-5_BIB27","series-title":"Advances in Cryptology: CRYPTO '87 Proc.","first-page":"40","article-title":"Direct minimum-knowledge computations","author":"Impagliazzo","year":"1988"},{"key":"10.1016\/0304-3975(91)90259-5_BIB28","series-title":"Primality and Cryptography","author":"Kranakis","year":"1986"},{"key":"10.1016\/0304-3975(91)90259-5_BIB29","series-title":"Advances in Cryptology: EUROCRYPT '89 Proc.","first-page":"636","article-title":"Fast generation of secure RSA-moduli with almost maximal diversity","author":"Maurer","year":"1990"},{"key":"10.1016\/0304-3975(91)90259-5_BIB30","first-page":"33","article-title":"Universal one-way hash functions and their cryptographic applications","author":"Naor","year":"1989","journal-title":"Proc. 21st ACM Symp. on Theory of Computing"},{"key":"10.1016\/0304-3975(91)90259-5_BIB31","doi-asserted-by":"crossref","first-page":"106","DOI":"10.1109\/TIT.1978.1055817","article-title":"An improved algorithm for computing logarithms over GF(p) and its cryptographic significance","volume":"24","author":"Pohlig","year":"1978","journal-title":"IEEE Trans. Inform. Theory"},{"key":"10.1016\/0304-3975(91)90259-5_BIB32_1","doi-asserted-by":"crossref","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","article-title":"A mathematical theory of communications","volume":"27","author":"Shannon","year":"1948","journal-title":"Bell System Tech. J."},{"key":"10.1016\/0304-3975(91)90259-5_BIB32_2","doi-asserted-by":"crossref","first-page":"623","DOI":"10.1002\/j.1538-7305.1948.tb00917.x","article-title":"A mathematical theory of communications","volume":"27","author":"Shannon","year":"1948","journal-title":"Bell System Tech. J."}],"container-title":["Theoretical Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:0304397591902595?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:0304397591902595?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2019,4,13]],"date-time":"2019-04-13T03:54:22Z","timestamp":1555127662000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/0304397591902595"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1991,7]]},"references-count":33,"journal-issue":{"issue":"1","published-print":{"date-parts":[[1991,7]]}},"alternative-id":["0304397591902595"],"URL":"https:\/\/doi.org\/10.1016\/0304-3975(91)90259-5","relation":{},"ISSN":["0304-3975"],"issn-type":[{"value":"0304-3975","type":"print"}],"subject":[],"published":{"date-parts":[[1991,7]]}}}