paper on commitments with efficient zero-knowledge arguments from subset sum problems accepted in ESORICS 2023