H needn't to be a trap-door hash function (no trap-door is used in the protocol). I am not sure about the proper requirement, though.