Advances in Cryptology - CRYPTO 2009

Volume 5677 of the series Lecture Notes in Computer Science pp 160-176

On the Composition of Public-Coin Zero-Knowledge Protocols

  • Rafael PassAffiliated withCornell University
  • , Wei-Lung Dustin TsengAffiliated withCornell University
  • , Douglas WikströmAffiliated withKTH Royal Institute of Technology


We show that only languages in BPP have public-coin, black-box zero-knowledge protocols that are secure under an unbounded (polynomial) number of parallel repetitions. This result holds both in the plain model (without any set-up) and in the Bare Public-Key Model (where the prover and the verifier have registered public keys). We complement this result by showing the existence of a public-coin black-box zero-knowledge proof that remains secure under any a-priori bounded number of concurrent executions.