水银承诺方案是一般承诺方案的一种有趣变形.水银承诺方案中增加了soft解承诺阶段,soft解承诺阶段所公开的解承诺值不要求绑定性但是不能与真实的解承诺值冲突.讨论了多重非延展水银承诺方案.通常意义的非延展性是指敌手只允许存取一个承诺值,多重非延展性是指敌手可以存取任意数量的承诺值.已有结论说明多重非延展性是严格强于通常非延展性的安全性概念.采用多重非延展性的概念在于水银承诺方案本身固有的性质,给出多重非延展水银承诺方案的概念,以及基于多陷门水银承诺方案的一个具体构造.
Mercurial commitment scheme is an interesting variation of regular commitment scheme, which additionally allows for a soft decommit stage. The soft decommitments arc not required to binding but can not conflict with the true decommmitments (if the true decommmitments exist). In our paper, we consider reusable non-malleable mercurial commitment schemes. Reusable non-malleability is that the adversary accesses to an arbitrary number of commitments, which is a strictly stronger security notion than general non-malleability in which the adversary has access to only one commitment. We adopt the reusability mainly due to the inherent property of mercurial commitment scheme. We introduce the notion of reusable non-malleable mercurial commitment scheme and give a construction based on the multi-trapdoor mercurial commitment scheme.