Divertible Zero-Knowledge Proof of Polynominal Relations and Blind Group Signature

A divertible protocol is a protocol between three parties in which one party is able to divert another party's proof of some facts to prove some other facts to the other party. This paper presents a divertible protocol to prove multi-variant polynomial relations. Its direct application to blind group signature is also shown.