On Sun, 24 Jun 2001, Michael Conlen wrote:
> I'm reading about zero knowledge identity proofs and 'The Mafia Fraud' in
> Applied Cryptography. Has no one found a way to perform an identity proof
> such that you can prove who you are to a specific person? In the example in
> the book Alice proves who she is to Bob who transmits to Carol, and Carol
> proves that she is Alice to Dave. I'm curious what the problem is with
> creating a proof that Alice is Alice such that only Bob can be assured that
> she is Alice so that Carol can't use the proof to identify who she is to
> Dave.
THe proofs that you are requesting for have been standard tools in
cryptography for many years - they are usually known as identification
schemes. The best known scheme (and most elegant IMHO) is the Schnorr
identification scheme. See
http://www.tml.hut.fi/~helger/crypto/link/identification/
for a (noncomplete) collection of links.
Helger
