# Coefficient Test

The Knowledge of Coefficient Test and Assumption

Fact that Jennifer is able to compute E ( P ( s ) ) does not guarantee she will indeed send E ( P ( s ) ) to Ted, rather than some completely unrelated value.

Thus, we need a way to “force” Jennifer to follow the protocol correctly.

We denote by g a generator of a group G of order | G | = p where the discrete log is hard. It will be convenient from this post onwards to write our group additively rather than multiplicatively. That is, for α ∈ F p , α ⋅ g denotes the result of summing α copies of g .

