Suppose Bob provides Alice with an RSA modulus N = PQ , where P and Q are very large primes known only to Bob, and Bob wants to prove to Alice that he knows a secret exponent x such that s ≡ tx (mod N). If Alice selects c i = 0 , Bob sends Alice z i = a i , and Alice sees that tz i ≡ ta i ≡ α i s0 ≡ α i (mod N) and accepts the i -th iteration of the proof. If any one of Bob’s k guesses for Alice’s c i values are wrong, Alice will reject the proof as invalid.