Interactive proof system

General representation of an interactive proof protocol.

In computational complexity theory, an interactive proof system is an abstract machine that models computation as the exchange of messages between two parties: a prover and a verifier. The parties interact by exchanging messages in order to ascertain whether a given string belongs to a language or not. The prover is assumed to possess unlimited computational resources but cannot be trusted, while the verifier has bounded computation power but is assumed to be always honest. Messages are sent between the verifier and prover until the verifier has an answer to the problem and has "convinced" itself that it is correct.

All interactive proof systems have two requirements:

  • Completeness: if the statement is true, the honest prover (that is, one following the protocol properly) can convince the honest verifier that it is indeed true.
  • Soundness: if the statement is false, no prover, even if it doesn't follow the protocol, can convince the honest verifier that it is true, except with some small probability.

The specific nature of the system, and so the complexity class of languages it can recognize, depends on what sort of bounds are put on the verifier, as well as what abilities it is given—for example, most interactive proof systems depend critically on the verifier's ability to make random choices. It also depends on the nature of the messages exchanged—how many and what they can contain. Interactive proof systems have been found to have some important implications for traditional complexity classes defined using only one machine. The main complexity classes describing interactive proof systems are AM and IP.

Background

Every interactive proof system defines a formal language of strings . Soundness of the proof system refers to the property that no prover can make the verifier accept for the wrong statement except with some small probability. The upper bound of this probability is referred to as the soundness error of a proof system. More formally, for every prover , and every :

for some . As long as the soundness error is bounded by a polynomial fraction of the potential running time of the verifier (i.e. ), it is always possible to amplify soundness until the soundness error becomes negligible function relative to the running time of the verifier. This is achieved by repeating the proof and accepting only if all proofs verify. After repetitions, a soundness error will be reduced to .[1]

Classes of interactive proofs

NP

The complexity class NP may be viewed as a very simple proof system. In this system, the verifier is a deterministic, polynomial-time machine (a P machine). The protocol is:

  • The prover looks at the input and computes the solution using its unlimited power and returns a polynomial-size proof certificate.
  • The verifier verifies that the certificate is valid in deterministic polynomial time. If it is valid, it accepts; otherwise, it rejects.

In the case where a valid proof certificate exists, the prover is always able to make the verifier accept by giving it that certificate. In the case where there is no valid proof certificate, however, the input is not in the language, and no prover, however malicious it is, can convince the verifier otherwise, because any proof certificate will be rejected.

Arthur–Merlin and Merlin–Arthur protocols

Although NP may be viewed as using interaction, it wasn't until 1985 that the concept of computation through interaction was conceived (in the context of complexity theory) by two independent groups of researchers. One approach, by László Babai, who published "Trading group theory for randomness",[2] defined the Arthur–Merlin (AM) class hierarchy. In this presentation, Arthur (the verifier) is a probabilistic, polynomial-time machine, while Merlin (the prover) has unbounded resources.

The class MA in particular is a simple generalization of the NP interaction above in which the verifier is probabilistic instead of deterministic. Also, instead of requiring that the verifier always accept valid certificates and reject invalid certificates, it is more lenient:

  • Completeness: if the string is in the language, the prover must be able to give a certificate such that the verifier will accept with probability at least 2/3 (depending on the verifier's random choices).
  • Soundness: if the string is not in the language, no prover, however malicious, will be able to convince the verifier to accept the string with probability exceeding 1/3.

This machine is potentially more powerful than an ordinary NP interaction protocol, and the certificates are no less practical to verify, since BPP algorithms are considered as abstracting practical computation (see BPP).

Public coin protocol versus private coin protocol

In a public coin protocol, the random choices made by the verifier are made public. They remain private in a private coin protocol.

In the same conference where Babai defined his proof system for MA, Shafi Goldwasser, Silvio Micali and Charles Rackoff[3] published a paper defining the interactive proof system IP[f(n)]. This has the same machines as the MA protocol, except that f(n) rounds are allowed for an input of size n. In each round, the verifier performs computation and passes a message to the prover, and the prover performs computation and passes information back to the verifier. At the end the verifier must make its decision. For example, in an IP[3] protocol, the sequence would be VPVPVPV, where V is a verifier turn and P is a prover turn.

In Arthur–Merlin protocols, Babai defined a similar class AM[f(n)] which allowed f(n) rounds, but he put one extra condition on the machine: the verifier must show the prover all the random bits it uses in its computation. The result is that the verifier cannot "hide" anything from the prover, because the prover is powerful enough to simulate everything the verifier does if it knows what random bits it used. This is called a public coin protocol, because the random bits ("coin flips") are visible to both machines. The IP approach is called a private coin protocol by contrast.

The essential problem with public coins is that if the prover wishes to maliciously convince the verifier to accept a string which is not in the language, it seems like the verifier might be able to thwart its plans if it can hide its internal state from it. This was a primary motivation in defining the IP proof systems.

In 1986, Goldwasser and Sipser[4] showed, perhaps surprisingly, that the verifier's ability to hide coin flips from the prover does it little good after all, in that an Arthur–Merlin public coin protocol with only two more rounds can recognize all the same languages. The result is that public-coin and private-coin protocols are roughly equivalent. In fact, as Babai shows in 1988, AM[k]=AM for all constant k, so the IP[k] have no advantage over AM.[5]

To demonstrate the power of these classes, consider the graph isomorphism problem, the problem of determining whether it is possible to permute the vertices of one graph so that it is identical to another graph. This problem is in NP, since the proof certificate is the permutation which makes the graphs equal. It turns out that the complement of the graph isomorphism problem, a co-NP problem not known to be in NP, has an AM algorithm and the best way to see it is via a private coins algorithm.[6]

IP

Private coins may not be helpful, but more rounds of interaction are helpful. If we allow the probabilistic verifier machine and the all-powerful prover to interact for a polynomial number of rounds, we get the class of problems called IP. In 1992, Adi Shamir revealed in one of the central results of complexity theory that IP equals PSPACE, the class of problems solvable by an ordinary deterministic Turing machine in polynomial space.[7]

QIP

If we allow the elements of the system to use quantum computation, the system is called a quantum interactive proof system, and the corresponding complexity class is called QIP.[8] A series of results culminated in a 2010 breakthrough that QIP = PSPACE.[9][10]

Zero knowledge

Not only can interactive proof systems solve problems not believed to be in NP, but under assumptions about the existence of one-way functions, a prover can convince the verifier of the solution without ever giving the verifier information about the solution. This is important when the verifier cannot be trusted with the full solution. At first it seems impossible that the verifier could be convinced that there is a solution when the verifier has not seen a certificate, but such proofs, known as zero-knowledge proofs are in fact believed to exist for all problems in NP and are valuable in cryptography. Zero-knowledge proofs were first mentioned in the original 1985 paper on IP by Goldwasser, Micali and Rackoff for specific number theoretic languages. The extent of their power was however shown by Oded Goldreich, Silvio Micali and Avi Wigderson.[6] for all of NP, and this was first extended by Russell Impagliazzo and Moti Yung to all IP.[11]

MIP

One goal of IP's designers was to create the most powerful possible interactive proof system, and at first it seems like it cannot be made more powerful without making the verifier more powerful and so impractical. Goldwasser et al. overcame this in their 1988 "Multi prover interactive proofs: How to remove intractability assumptions", which defines a variant of IP called MIP in which there are two independent provers.[12] The two provers cannot communicate once the verifier has begun sending messages to them. Just as it's easier to tell if a criminal is lying if he and his partner are interrogated in separate rooms, it's considerably easier to detect a malicious prover trying to trick the verifier into accepting a string not in the language if there is another prover it can double-check with.

In fact, this is so helpful that Babai, Fortnow, and Lund were able to show that MIP = NEXPTIME, the class of all problems solvable by a nondeterministic machine in exponential time, a very large class.[13] NEXPTIME contains PSPACE, and is believed to strictly contain PSPACE. Adding a constant number of additional provers beyond two does not enable recognition of any more languages. This result paved the way for the celebrated PCP theorem, which can be considered to be a "scaled-down" version of this theorem.

MIP also has the helpful property that zero-knowledge proofs for every language in NP can be described without the assumption of one-way functions that IP must make. This has bearing on the design of provably unbreakable cryptographic algorithms.[12] Moreover, a MIP protocol can recognize all languages in IP in only a constant number of rounds, and if a third prover is added, it can recognize all languages in NEXPTIME in a constant number of rounds, showing again its power over IP.

It is known that for any constant k, a MIP system with k provers and polynomially many rounds can be turned into an equivalent system with only 2 provers, and a constant number of rounds.[14]

PCP

While the designers of IP considered generalizations of Babai's interactive proof systems, others considered restrictions. A very useful interactive proof system is PCP(f(n), g(n)), which is a restriction of MA where Arthur can only use f(n) random bits and can only examine g(n) bits of the proof certificate sent by Merlin (essentially using random access).

There are a number of easy-to-prove results about various PCP classes. , the class of polynomial-time machines with no randomness but access to a certificate, is just NP. , the class of polynomial-time machines with access to polynomially many random bits is co-RP. Arora and Safra's first major result was that ; put another way, if the verifier in the NP protocol is constrained to choose only bits of the proof certificate to look at, this won't make any difference as long as it has random bits to use.[15]

Furthermore, the PCP theorem asserts that the number of proof accesses can be brought all the way down to a constant. That is, .[16] They used this valuable characterization of NP to prove that approximation algorithms do not exist for the optimization versions of certain NP-complete problems unless P = NP. Such problems are now studied in the field known as hardness of approximation.

See also

References

  1. ^ Goldreich, Oded (2002), Zero-Knowledge twenty years after its invention, ECCC TR02-063.
  2. ^ László Babai. Trading group theory for randomness. Proceedings of the Seventeenth Annual Symposium on the Theory of Computing, ACM. 1985.
  3. ^ Goldwasser, S.; Micali, S.; Rackoff, C. (1989). "The knowledge complexity of interactive proof systems" (PDF). SIAM Journal on Computing. 18 (1): 186–208. doi:10.1137/0218012. ISSN 1095-7111. Extended abstract Archived 2006-06-23 at the Wayback Machine
  4. ^ Shafi Goldwasser and Michael Sipser. Private coins versus public coins in interactive proof systems Archived 2005-01-27 at the Wayback Machine. Proceedings of ACM STOC'86, pp. 58–68. 1986.
  5. ^ László Babai and Shlomo Moran. Arthur–Merlin games: a randomized proof system, and a hierarchy of complexity classes. Journal of Computer and System Sciences, 36: p.254–276. 1988.
  6. ^ a b O. Goldreich, S. Micali, A. Wigderson. Proofs that yield nothing but their validity. Journal of the ACM, volume 38, issue 3, p.690–728. July 1991.
  7. ^ Adi Shamir. IP = PSPACE. Journal of the ACM, volume 39, issue 4, p.869–877. October 1992.
  8. ^ Tsuyoshi Ito; Hirotada Kobayashi; John Watrous (2010). "Quantum interactive proofs with weak error bounds". arXiv:1012.4427v2 [quant-ph].
  9. ^ Jain, Rahul; Ji, Zhengfeng; Upadhyay, Sarvagya; Watrous, John (2010). "QIP = PSPACE". STOC '10: Proceedings of the 42nd ACM symposium on Theory of computing. ACM. pp. 573–582. ISBN 978-1-4503-0050-6.
  10. ^ Aaronson, S. (2010). "QIP = PSPACE breakthrough". Communications of the ACM. 53 (12): 101. doi:10.1145/1859204.1859230. S2CID 34380788.
  11. ^ Russell Impagliazzo, Moti Yung: Direct Minimum-Knowledge Computations. CRYPTO 1987: 40-51 [1]
  12. ^ a b M. Ben-or, Shafi Goldwasser, J. Kilian, and A. Wigderson. Multi prover interactive proofs: How to remove intractability assumptions. Proceedings of the 20th ACM Symposium on Theory of Computing, pp. 113–121. 1988.
  13. ^ László Babai; L. Fortnow; C. Lund (1991). "Non-deterministic exponential time has two-prover interactive protocols. Computational Complexity". pp. 3–40. Archived from the original on 8 February 2007.
  14. ^ Ben-Or, Michael; Goldwasser, Shafi; Kilian, Joe; Widgerson, Avi (1988). "Multi-prover interactive proofs: How to remove intractability" (PDF). Proceedings of the twentieth annual ACM symposium on Theory of computing - STOC '88. pp. 113–131. doi:10.1145/62212.62223. ISBN 0897912640. S2CID 11008365. Archived from the original (PDF) on 13 July 2010. Retrieved 17 November 2022.
  15. ^ Sanjeev Arora and Shmuel Safra. Probabilistic Checking of Proofs: A New Characterization of NP. Journal of the ACM, volume 45, issue 1, pp. 70–122. January 1998.
  16. ^ Sanjeev Arora, C. Lund, R. Motwani, M. Sudan, and M. Szegedy. Proof Verification and the Hardness of Approximation Problems. Proceedings of the 33rd IEEE Symposium on Foundations of Computer Science, pp. 13–22. 1992.

Textbooks

Read other articles:

Aditi Rao HydariLahir28 Oktober 1986 (umur 37)Hyderabad, Andhra Pradesh (sekarang Telangana), IndiaAlmamaterUniversitas Lady Shri RamPekerjaanAktris PenyanyiPenariTahun aktif2004–sekarangSuami/istriSatyadeep Mishra, cerai tahun 2013Orang tuaEhsaan HydariVidya RaoKerabatKiran Rao (sepupu)Aditi Rao Hydari (lahir 28 Oktober 1986) adalah seorang aktris, penari, dan penyanyi berkebangsaan India yang bekerja di film Bollywood, Tamil, Malayalam, dan Telugu. Lihat juga Portal India Porta...

 

 

Katja KippingKatja Kipping pada 2014 Ketua Partai Partai KiriPetahanaMulai menjabat 2 June 2012Menjabat bersama Bernd Riexinger PendahuluGesine Lötzsch, Klaus ErnstPenggantiPetahanaAnggota Bundestag untuk Saxony Distrik I Dresden (list)PetahanaMulai menjabat 2005Anggota Parlemen SaxonyMasa jabatan1999–2004Anggota Dewan Kota DresdenMasa jabatan1999–2003 Informasi pribadiLahir18 Januari 1978 (umur 46)Dresden, Jerman TimurKewarganegaraanJermanPartai politikPartai Kiri (...

 

 

Dunia MimpiAlbum studio karya AriyoDirilis16 November 2002GenrepopLabelEMIProduserBongkyKronologi Ariyo -String Module Error: Match not foundString Module Error: Match not found Dunia Mimpi(2002) Live And Let Live(2002)Live And Let Live2002 Dunia Mimpi (digayakan sebagai Dunia>Mimpi) merupakan sebuah album musik perdana karya penyanyi dan aktor berkebangsaan Indonesia, Ariyo Wahab, yang dirilis tahun 2002. Lagu yang dijagokan dari album ini adalah “Kucinta Caramu” dan “Tiada yang...

Device for making an impression in wax or other medium For other uses, see Seal (disambiguation). Town seal (matrix) of Náchod (now in the Czech Republic) from 1570 Present-day impression of a Late Bronze Age seal A seal is a device for making an impression in wax, clay, paper, or some other medium, including an embossment on paper, and is also the impression thus made. The original purpose was to authenticate a document, or to prevent interference with a package or envelope by applying a se...

 

 

الدوري المقدوني الأول لكرة القدم 2017-18 تفاصيل الموسم الدوري المقدوني الأول لكرة القدم  النسخة 26  البلد مقدونيا الشمالية  التاريخ بداية:12 أغسطس 2017  نهاية:20 مايو 2018  المنظم اتحاد مقدونيا الشمالية لكرة القدم  البطل نادي شكينديا  الهابطون نادي بيليستر  مبار...

 

 

Halaman ini berisi artikel tentang pengusaha. Untuk peneliti medikal, lihat Jawahar L. Mehta. Jay Mehta Informasi pribadiLahir18 Januari 1960 (umur 64)IndiaSuami/istriJuhi ChawlaAnak2[1]PekerjaanDirektur Grup operasi India (Mehta Group)Wakil Ketua Eksekutif (Saurashtra Cement Ltd dan Gujarat Sidhee Cement Ltd) Direktur Non-Eksekutif Independen dari ADF Foods LimitedSunting kotak info • L • B Jay Mehta adalah seorang pengusaha asal India. Ia adalah putra dari pasanga...

Virus Hendra Hendra virus Gambar mikrograf elektron berwarna dari virion Hendra henipavirus (memiliki panjang sekitar 300 nanometer)TaksonomiSuperdomainBiotaDomainVirusDuniaRiboviriaKerajaanOrthornaviraeFilumNegarnaviricotaSubfilumHaploviricotinaKelasMonjiviricetesOrdoMononegaviralesFamiliParamyxoviridaeSubfamiliParamyxovirinaeGenusHenipavirusSpesiesHendra virus lbs Virus Hendra, nama ilmiah Hendra henipavirus, merupakan virus yang dibawa oleh kelelawar yang menyebabkan infeksi mematikan pada...

 

 

Irish geographer Anne ButtimerBorn(1938-10-31)October 31, 1938Cork, IrelandDiedJuly 15, 2017(2017-07-15) (aged 78)Dublin, IrelandNationalityIrishAlma materUniversity College CorkUniversity of WashingtonScientific careerFieldsGeographyInstitutionsSeattle UniversityGrenoble Alpes UniversityUniversity of TexasLund UniversityClark University Anne Buttimer (31 October 1938 – 15 July 2017) was an Irish geographer. She was emeritus professor of geography at University College, Dublin. Ba...

 

 

Ode to the GoosePoster teatrikalNama lainHangul군산: 거위를 노래하다 Alih Aksara yang DisempurnakanGunsan: Geowileul Nolaehada SutradaraZhang LüProduserZhang LüDitulis olehZhang LüPemeranPark Hae-ilMoon So-riJung Jin-youngPark So-damSinematograferCho Young-jikPenyuntingZhang LüLee Hak-minPerusahaanproduksiLu FilmTanggal rilis 5 Oktober 2018 (2018-10-05) (BIFF) 8 November 2018 (2018-11-08) (Korea Selatan) Durasi122 menit[1]NegaraKorea SelatanBahasaK...

This article is about the New York high school. For the South Carolina high school, see Scholars Academy. 40°35′03″N 73°49′31″W / 40.5842°N 73.82535°W / 40.5842; -73.82535 SchoolThe Scholars' AcademyAddress320 Beach 104th St, Rockaway Park, NY 11694InformationEstablishedSeptember 2005PrincipalMichele SmythGrades6 to 12Color(s)Navy blue, light blue and khaki pantsSloganTechnology today, Smarter tomorrowTeam nameSeawolvesNewspaperThe Seaside ChronicleWebsiteh...

 

 

Football derby between Real Sociedad and Athletic Bilbao Not to be confused with Basque basketball derby. Basque derbyLocationBasque Country, SpainTeamsAthletic BilbaoReal SociedadFirst meeting4 April 1909Copa del ReyClub Ciclista 4–2 Athletic BilbaoLatest meeting13 January 2024La LigaAthletic Bilbao 2–1 Real SociedadStadiumsSan Mamés (Bilbao)Anoeta (San Sebastian)StatisticsMeetings total191Most winsAthletic Bilbao (79)Top scorerTelmo ZarraJesús María Satrústegui(14 each)Largest victo...

 

 

Indian cricketer (born 1993) In this Indian name, the name Ramaswamy Gopal is a patronymic, and the person should be referred to by the given name, Shreyas. Shreyas GopalGopal in a post-match presentation during 2019 IPLPersonal informationFull nameRamswamy Shreyas GopalBorn (1993-09-04) 4 September 1993 (age 30)Bangalore, Karnataka, IndiaBattingRight-handedBowlingRight-arm leg breakRoleAll-rounderDomestic team information YearsTeam2013/14–2022/23Karnataka2014–2017Mumbai Indians...

Ardizzone da CarraraSignore di Ascoli PicenoStemma TrattamentoSignore Altri titoliSignore di Civitella del Tronto ed Offida NascitaPadova MorteMontemerano, settembre 1441 DinastiaDa Carrara PadreConte da Carrara Madre? ConsorteAntonia Sforza Figlivedi sezione ReligioneCattolicesimo Ardizzone da CarraraNascitaPadova, ? MorteMontemerano, settembre 1441 Dati militariPaese servito Regno di Napoli Stato Pontificio Repubblica di Firenze Ducato di Milano Regno d'Aragona Repubblica...

 

 

Державний комітет телебачення і радіомовлення України (Держкомтелерадіо) Приміщення комітетуЗагальна інформаціяКраїна  УкраїнаДата створення 2003Керівне відомство Кабінет Міністрів УкраїниРічний бюджет 1 964 898 500 ₴[1]Голова Олег НаливайкоПідвідомчі ор...

 

 

اتفاق انسحاب القوات الأمريكية من العراق جزء من حرب العراق    التاريخ 18 ديسمبر 2011  الموقع العراق  تعديل مصدري - تعديل   اتفاق انسحاب القوات الأميركية من العراق هو الاتفاق الذي عقد بين القوات العراقية والأمريكية لجدولة انسحاب القوات الأمريكية من العراق وإخراج...

Trinamool Congress SingkatanAITCDibentuk1 Januari 1998; 26 tahun lalu (1998-01-01)Dipisah dariKongres Nasional IndiaBendera All India Trinamool Congress (AITC) atau Trinamool Congress (TMC) adalah sebuah partai politik di India yang terutamanya berbasis di Benggala Barat. Pemimpin partai adalah Mamata Banerjee yang telah menjadi Ketua Menteri Bengal Barat sejak tahun 2011. AITC merupakan partai terbesar ketiga setelah BJP dan INC dalam Parlemen India, dengan memiliki 23 anggota dala...

 

 

فسيفساء رومانية في جرش بالأردن للشاعرة اليونانية الكمان تظهر شرب الخمر. أواخر القرن الثاني والثالث معصرة نبيذ أثرية في عبدون يتم إنتاج النبيذ الأردني من قبل اثنين من مصانع النبيذ، مع إنتاج سنوي ما يقرب من مليون زجاجة في السنة. للأردن تقليد طويل في صناعة النبيذ، [1] يعود...

 

 

GR 7Lodève, sur le parcours du GR 7.LocalisationContinent EuropeLocalisation Espagne, Andorre et FranceDésignationAutre nom Du Ballon d'Alsace à Andorre-la-VieilleType Sentier de grande randonnée, sentier de longue randonnéeTracéPoint de départ Le Ballon d'Alsace  Andorre-la-Vieille (Andorre)Extrémités Andorre-la-VieilleDétroit de GibraltarBallon d'AlsaceLongueur 1 471 kmmodifier - modifier le code - modifier Wikidata Le sentier de grande randonnée 7 (GR 7) suit appr...

Chemical solution in solid form This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Solid solution – news · newspapers · books · scholar · JSTOR (November 2007) (Learn how and when to remove this message) A solid solution, a term popularly used for metals, is a homogeneous mixture of two different kinds of atoms...

 

 

Australian physician (born 1960) Dale FisherBornDale Andrew Fisher1960 (age 63–64)Melbourne, AustraliaEducationCamberwell Grammar School, Melbourne, VictoriaHutchins School, Hobart, Tasmania,United World College of South East Asia, Singapore,University of Tasmania, Australia (MBBS)Medical careerFieldMedicine, Infectious DiseasesInstitutionsNational University HospitalNational University of Singapore Websitewww.nuh.com.sg/patients-visitors/Pages/find-a-doctor-details.aspx?docid=Dale...