@unpublished{Smyth25-implementing-Fiat-Shamir, author = {Ben Smyth}, title = {{Hooking up with Fiat-Shamir}}, year = {2025}, url = {https://publications.bensmyth.com/2025-implementing-Fiat-Shamir/}, url-pdf = {https://publications.bensmyth.com/files/Smyth25-implementing-Fiat-Shamir.pdf}, url-bib = {https://publications.bensmyth.com/files/Smyth25-implementing-Fiat-Shamir.bib}, url-yaml = {https://publications.bensmyth.com/files/Smyth25-implementing-Fiat-Shamir.yml}, url-md = {https://publications.bensmyth.com/files/Smyth25-implementing-Fiat-Shamir.md}, keywords = {Fiat-Shamir, zero-knowledge proof, sigma protocol, discrete logarithm, non-malleable ElGamal, JavaScript, proven secure by design}, abstract = {A zero-knowledge proof convinces us of some claim's validity without revealing specifics. For example, you can prove possession of a private key without leaking any information about your key. Zero-knowledge proofs are typically derived by application of the Fiat-Shamir transformation to sigma protocols. Unfortunately, the transformation is commonly misapplied, introducing security vulnerabilities. Herein, I present a JavaScript framework for correct transformation.} }