CA2804394C

Authentication device, authentication method, and program

Abstract

Provided is an authentication device including a key holding unit for holding L (L > 2) secret keys s, (i = 1 to L) and L public keys y, that satisfy y, = F(S i) with respect to a set F of multivariate polynomials of n-th order (n >= 2), and an interactive protocol execution unit for performing, with a verifier, an interactive protocol for proving knowledge of (L-1) secret keys s i that satisfy y i = F(S i). The interactive protocol execution unit includes a challenge reception unit for receiving L challenges Ch i from the verifier, a challenge selection unit for arbitrarily selecting (L-1) challenges Ch i from the L challenges Ch i received by the challenge reception unit, a response generation unit for generating, by using the secret keys S i, (L-1) responses Rsp i respectively for the (L-1) challenges Ch i selected by the challenge selection unit, and a response transmission unit for transmitting the (L-1) responses Rsp i generated by the response generation unit to the verifier.

CA2804394C, drawing sheet 1
Sheet 1 of 23

Term

Projected expiry 12 July 2031.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

8 claims: 6 independent, 2 dependent

  1. 1
    CA 2804394 2017-04-25 CLAIMS 1. An authentication device comprising:circuitry configured to: set seK11 to a secret key, and set multi-order polynomials on a ring K, f,(xi, ..., xn) (i=l to m) and yj=fj(s) to a public key;transmit message c to a verifier;receive information on one verification pattern selected from k (k > 3) verification patterns by the verifier according to one piece of the message c;and transmit response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier, wherein the response information is calculated using information ζθΚ in which the secret key s is masked by r G Kn, t’ e Kn in which the r is masked by tEK, polynomial fi’ ’(x) in which multi-order polynomials fi(x+r) related to x is masked by polynomial fi’ (x).
  2. 4
    An authentication device comprising:circuitry configured to: set sekn to a secret key, and set second-order polynomials on a CA 2804394 2017-04-25 ring K, t'j(xi, ..., xn) (i=l to m) and yi=fi(s) to a public key;transmit message c to a verifier;receive information on one verification pattern selected from k (k > 3) verification patterns by the verifier according to one piece of the message c;and transmit response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier, wherein the response information is calculated using information z = K” in which the secret key s is masked by r£ Kn, f e Kn in which the r is masked by t£K. ei’Ik in which f, (r) substituted by the r for the second-order polynomials fi is masked by e,t=K.
  3. 5
    An authentication method comprising:setting, with circuitry, seKn to a secret key, and setting multi-order polynomials on a ring K, fi(xi, .... xn) (i=l to m) and yi=fi(s) to a public key;transmitting, with the circuitry, message c to a verifier;receiving, with the circuitry, information on one verification pattern selected from k (k > 3) verification patterns by the verifier according to one piece of the message c;and transmitting, with the circuitry, response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier, wherein the response information is calculated using information zAK in which the secret key s is masked by rEKn, fEK in which the r is masked by UK, polynomial ff ’(x) in which multi-order polynomials fi(x+r) related to x is masked by polynomial fi’ (x).
  4. 6
    An authentication method comprising:setting, with circuitry, seKn to a secret key, and setting second-order CA 2804394 2017-04-25 polynomials on a ring K, ij(xi, ..., xn) (i=l to m) and yj=fi(s) to a public key;transmitting, with the circuitry, message c to a verifier;receiving, with the circuitry, information on one verification pattern selected from k (k > 3) verification patterns by the verifier according to one piece of the message c;and transmitting, with the circuitry, response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier, wherein the response information is calculated using information z€=Kn in which the secret key s is masked by rGK. f G Kn in which the r is masked by t/K, efeK in which f, (r) substituted by the r for the second-order polynomials f, is masked by ο,^Κ.
  5. 7
    A non-transitory computer readable medium including computer executable instructions, which when executed by a computer cause the computer to perform a method comprising:setting sgK to a secret key, and setting multi-order polynomials on a ring K, fi(xi, . . . , xn) (i=l to m) and yi=fi(s) to a public key;transmitting message c to a verifier;receiving information on one verification pattern selected from k (k > 3) verification patterns by the verifier according to one piece of the message c;and transmitting response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier, wherein the response information is calculated using information z/Kn in which the secret key s is masked by U Kn, fe Kn in which the r is masked by UK, polynomial ff ’(x) in which multi-order polynomials fi(x+r) related to x is masked by polynomial ff (x). CA 2804394 2017-04-25
  6. 8
    A non-transitory computer readable medium including computer executable instructions, which when executed by a computer cause the computer to perform a method comprising:setting seK to a secret key, and setting second-order polynomials on a ring K, fj(xi, ..., xn) (i=l to m) and yi=fl(s) to a public key;transmitting message c to a verifier;receiving information on one verification pattern selected from k (k > 3) verification patterns by the verifier according to one piece of the message c;and transmitting response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier, wherein the response information is calculated using information z£Kin which the secret key s is masked by r£ Kn. f G Kn in which the r is masked by t θ Kn, ef θ K in which fl (r) substituted by the r for the second-order polynomials fl is masked by ei^K.