H needn't to be a trap-door hash function (no trap-door is used in the protocol, collision resistance is not required), just a one-way function.