x-only just makes it more confusing, but it's a separate thing right. The general pattern for DLEQ is:

proving P_1 and P_2 have same DL for A,B:

s = r + ex, where e = H(R_1,R_2,P_1, P_2) where R_1 = rA and R_2 = rB and P_1 = xA and P_2=xB.

Then return s, e, R_1, R_2

Then verify with

sA =?= R_1 + eP_1, sB =?= R_2 + eP_2, with e calculated as above.

Reply to this note

Please Login to reply.

Discussion

thank you!