| | The Dining Cryptographers Problem |
 | | To see why the protocol is unconditionally secure if carried out faithfully,consider the dilemma of a cryptographer who is not the payer and wishes tofind out which cryptographer is. (If NSA pays, there is no anonymity problem.)There are two cases. |
 | | In case (1) the two coins he sees are the same, one ofthe other cryptographers said "different," and the other one said "same." Ifthe hidden outcome was the same as the two outcomes he sees, the cryptographerwho said "different" is the payer; if the outcome was different, the one whosaid "same" is the payer. |
 | | In case (2) the coins he sees are different; if bothother cryptographers said "different," then the payer is closest to the cointhat is the same as the hidden coin; if both said "same," then the payer isclosest to the coin that differs from the hidden coin. |
| www.cs.cornell.edu /People/egs/615/dcnets.html (4713 words) |