Volume 26, Issue 2, pp 251279
First online:
Mercurial Commitments with Applications to ZeroKnowledge Sets
 Melissa ChaseAffiliated withMicrosoft Research
 , Alexander HealyAffiliated withDivision of Engineering and Applied Sciences, Harvard University
 , Anna LysyanskayaAffiliated withDepartment of Computer Science, Brown University
 , Tal MalkinAffiliated withDepartment of Computer Science, Columbia University
 , Leonid ReyzinAffiliated withDepartment of Computer Science, Boston University Email author
We introduce a new flavor of commitment schemes, which we call mercurial commitments. Informally, mercurial commitments are standard commitments that have been extended to allow for soft decommitment. Soft decommitments, on the one hand, are not binding but, on the other hand, cannot be in conflict with true decommitments.
We then demonstrate that a particular instantiation of mercurial commitments has been implicitly used by Micali, Rabin and Kilian to construct zeroknowledge sets. (A zeroknowledge set scheme allows a Prover to (1) commit to a set S in a way that reveals nothing about S and (2) prove to a Verifier, in zeroknowledge, statements of the form x∈S and x∉S.) The rather complicated construction of Micali et al. becomes easy to understand when viewed as a more general construction with mercurial commitments as an underlying building block.
By providing mercurial commitments based on various assumptions, we obtain several different new zeroknowledge set constructions.
Key words
Commitments Zeroknowledge sets Database privacy Verifiable queries Outsourced databases Title
