Schnorr identification
Prove you know x without sending x.
The verifier sees y = gˣ = 18. The secret x stays with the prover.
With x, the prover can answer either challenge after committing.
1. Commit
Prover fixes t before c exists.
2. Challenge
Verifier draws c = 0 or 1.
3. Response
Prover returns s.
4. Check
Verifier tests one equation.
Prover
P
Verifier
V
READY: THE VERIFIER HAS NO COMMITMENT TO CHECK YET
Accepted rounds: 0Evidence against guessing: 0.00%
After n accepted independent binary challenges, a guessing prover passes every round with probability 2⁻ⁿ. A rejection resets the count.
The prover must commit before learning the challenge.