Conversation

OK, now I get it: the alpha terms force the prover to define {v,w,y}(s) as some linear combination of the pre-arranged {v,w,y}_k secrets; and the beta terms force the constants used in that linear combination to be the same for each. Really gorgeous.
6
Show replies