NIZKNon Interactive Zero Knowledge
In addition, since there are two constructions are presented in [9], the more efficient construction based on Waters signature is used to measure the signature size, and the underlying Groth-Sahai NIZK system is instantiated under DLIN Assumption.
Once a string "FALSE- 1" is output, TPA can issue a NIZK proof [[pi].
Our UndeniableProof algorithm actually relies on two NIZK protocols, which are also a DH-tuple witness hiding (WH) protocol and a non Diffie-Hellman(DH)-tuple WH protocol respectively.