### Abstract

Informally speaking, an instance-hiding pruoj system for the function f is a protocol in which a polynomial-time verifier is convinced of the value of f(z) but does not reveal the input z to the provers. We show here that a boolean function f has an instance-hiding proof system if and only if it is the characteristic function of a language in NEXP ∩ coNEXP. We formalize the notion of zero-knowledge for instance-hiding proof systems with several provers and show that alI such systems can be made perfect zero-knowledge.

Hiding instances in zero-knowledge proof systems

Informally speaking, an instance-hiding pruoj system for the function f is a protocol in which a polynomial-time verifier is convinced of the value of f(z) but does not reveal the input z to the provers. We show here that a boolean function f has an instance-hiding proof system if and only if it is the characteristic function of a language in NEXP ∩ coNEXP. We formalize the notion of zero-knowledge for instance-hiding proof systems with several provers and show that alI such systems can be made perfect zero-knowledge.

