- \(G = \{0, g, g^2, g^3, \dots, g^{p-1}\}\) is a finite cyclic group of prime order \(p\) and \(g\) is generator of \(G\) where
- Fix \(g, h \in G\) and let \(R = \{0, 1, 2, \dots, p-1\}\).
- For \(m, r \in R\) define \(H(m, r) = g^m * h^r\)
- FACT: For a “cryptographic” group G, this H is Collision resistance, So
- This commitment has interesting property called “Homomorphic” that is: