|
|
|
|
|
by XMPPwocky
2293 days ago
|
|
You could also do it modulo some number, I think? Then knowing any individual number (weight + pad) mod n gives zero knowledge (I think. If all but one party reveal their pads, they can trivially determine the other's weight so it fails. Believe it to be secure if only 1 party is malicious, though. Cases for other numbers of bad actors are more complicated...) |
|