Prover uses predictable coins? (e.g. does not change coins)
In principle, Diffie-Hellman and Schnorr protocols can be defined
for any group, not just Zp*.
Describe how these protocols would look if Zp+were used instead. Is it a good idea to use this group? Why or why
not (be very specific and formal)
How about Zn* for some n=pq
for two large primes p,q?
[in fact, in cryptography we do commonly use groups other than Zp*
- they are defined using