6 / 8 · Zero Knowledge

Schnorr identification

Prove you know x without sending x.

The verifier sees y = gˣ = 18. The secret x stays with the prover.

With x, the prover can answer either challenge after committing.

  1. 1. Commit

    Prover fixes t before c exists.

  2. 2. Challenge

    Verifier draws c = 0 or 1.

  3. 3. Response

    Prover returns s.

  4. 4. Check

    Verifier tests one equation.

Prover
P
Verifier
V
READY: THE VERIFIER HAS NO COMMITMENT TO CHECK YET
Accepted rounds: 0Evidence against guessing: 0.00%

After n accepted independent binary challenges, a guessing prover passes every round with probability 2⁻ⁿ. A rejection resets the count.

The prover must commit before learning the challenge.