Certifying permutations: noninteractive zero-knowledge based on any trapdoor permutationMihir BellareMoti Yung1996Journal of Cryptology