key: 2025-implementing-Fiat-Shamir type: unpublished title: Hooking up with Fiat-Shamir authors: - Ben Smyth year: 2025 description: >- A JavaScript framework for applying the Fiat-Shamir transformation to sigma protocols correctly, with proofs of knowledge of a discrete logarithm, of equality between logarithms, and of disjunctive equality as worked examples. keywords: >- Fiat-Shamir, zero-knowledge proof, sigma protocol, discrete logarithm, non-malleable ElGamal, JavaScript, proven secure by design abstract: >- A zero-knowledge proof convinces us of some claim's validity without revealing specifics. For example, you can prove possession of a private key without leaking any information about your key. Zero-knowledge proofs are typically derived by application of the Fiat-Shamir transformation to sigma protocols. Unfortunately, the transformation is commonly misapplied, introducing security vulnerabilities. Herein, I present a JavaScript framework for correct transformation. links: - file: Smyth25-implementing-Fiat-Shamir.pdf text: Draft