[cryptography] Proving knowledge of a message with a given SHA-1 without disclosing it?

Jon Callas jon at callas.org
Wed Feb 1 15:09:12 EST 2012


On Feb 1, 2012, at 1:49 AM, Francois Grieu wrote:

> The talk does not give much details, and I failed to locate any article
> with a similar claim.
> I would find that result truly remarkable, and it is against my intuition.
> 
> Any info on the Hal Finney protocol, or a protocol giving a similar
> result, or the (in)feasibility of such a protocol?

As I remember Hal's protocol, it requires about eight megabytes of data to be transferred back and forth to prove that you know the SHA1 hash. It's not so much to be obviously absurd, but not efficient enough to be something you'd want to do often.

	Jon




More information about the cryptography mailing list