Nova Patents
EP0139313A2

Blind signature systems.

Abstract

A cryptographic system allows, in one exemplary use, a supplier (101) to cryptographically transform a plurality of messages responsive to secret keys; the transformed messages to be digitally signed by a signer (102); and the signed transformed messages returned to the supplier (101) to be transformed by the supplier (101), responsive to the same secret keys, in such a way that a digital signature related to each original message is developed by the supplier (101). One important property of these systems is that the signer (102) can not determine which transformed message received for signing corresponds with which digital signature-even though the signer (102) knows that such a correspondence must exist.

EP0139313A2, drawing sheet 1
Sheet 1 of 22

Term

Term ended

Projected expiry passed 13 August 2004, 22.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

14 claims: 12 independent, 2 dependent

  1. 1
    In digital signature cryptographic apparatus, the improvement characterized by blind signature systems comprising:first transformation means responsive to a first key taking a first input and producing a first output hiding the first input from those without the first key;digital signature means for transforming said first output responsive to a second secret key and producing a second output;and second transformation means for transforming said second output, responsive to said first secret key, producing a third output, while preserving a digital signature property related to said first input and said first output not readily linkable to the third output without the first secret key.
  2. 2
    In digital signature cryptographic apparatus, the improvement characterized by blind signature systems comprising:key source means for developing a first key for use by a first party, said first key normally at least secret from a second party;first cryptographic transformation means allowing said first party to transform a message depending at least in part on said first secret key and rendering said message not readily recognizable without said first key;first communication means for transmitting said transformed message from said first cryptographic transformation means of said first party to said second party;digital signature means allowing said second party to develop a digital signature responsive to said transformed message received from said first communication means depending at least in part on a signing key, said signing key normally at least secret from said first party;second communication means for transmitting said digital signature from said digital signature means of said second party to said first party;and second cryptographic transformation means depending at least in part on said first secret key allowing said first party to transform a digital signature of said transformed message received from said second communication channel into a digital signature relating to said message and not readily distinguishable without said first key as resulting from a particular said transformed message.
  3. 3
    In the apparatus of claims 1 & 2, first transformation means, signing transformation means, and second transformation means, such that said third output equivalent to output of said signing means if said message input to said signing means.
  4. 4
    In the apparatus of claims 1 & 2, first transformation means including means for developing residue modulo the public modulus of multiplication by the first key raised to a public signing power;signing transformation means including means for developing residue modulo the public modulus of exponentiation to a power depending on the signing key;andand second transformation means including means for multiplying by the multiplicative inverse of the first key modulo the public modulus.
  5. 5
    In the apparatus of claims 1 & 2, first transformation means such that there almost always exists some first key that would cause the first transformation of any particular message to be any particular transformed message.
  6. 6
    In the apparatus of claims 1 & 2, key source means for choosing said first key from a distribution making almost every pair of messages resulting from said first and second transformations nearly equally likely to correspond.
  7. 7
    In the apparatus of claims 1 & 2, key source means for choosing said first key from a nearly uniform distribution and first and second transformation means such that there almost always exists a unique first key that would cause the first transformation of any particular message to be any particular transformed message.
  8. 8
    Blind signature apparatus as described in claims 1 & 2, such that said first transformation means having input signals m and first key k and producing output signals described bywhere e = a public signing exponent, and n = a public signature modulus;said signing transformation means having input signals t and secret signing key d and producing output signals t' described by;and said second transformation means having input signals t' and first key k and producing output signals m' described by
  9. 9
    In a digital signature cryptographic method, with a first party supplying messages to a second party who returns to the first party a digital signature on supplied messages, the improvement comprising blind signature systems characterized by the steps of:generating a first secret key at the first party, said key normally at least unknown to said second party;transforming a message with said first secret key, producing a first transformed message;transmitting said first transformed message to said second party;forming a digital signature of said first transformed message with a secret signing key, said secret signing key normally not known to said first party;transmitting said digital signature from said second party to said first party;andtransforming said digital signature at said first party with said first secret key producing a second transformed message, such that said first transformed message and the second transformed message are not readily determined to correspond without knowledge of said first secret key, and the second transformed message bearing a digital signature property related to said message.
  10. 10
    In a digital signature method, the improvement comprising a blind signature cryptographic method characterized by the steps of:transforming an original message with a first secret key;forming a digital signature of said transformed message;transforming said signed transformed message with said first secret key, such that a digital signature related to the original message results, and the correspondence between the signed message and the first transformed message is not obvious without said first secret key.
  11. 13
    In cryptographic apparatus, the improvement comprising a blind signature system comprising:first blinding means for transforming a message responsive to a first secret key producing a first output;second blinding means for transforming output of said first blinding means responsive to a second secret key producing a second output;digital signature means for developing a digital signature related to said second output, responsive to a secret signing key;first unblinding means for transforming said digital signature, responsive to a first one of said first and second secret keys, producing a third output;andsecond unblinding means for transforming said third output, responsive to a second one of said first and said second secret keys, producing a fourth output, and the fourth output having a digital signature property related to said message, and said first output and said fourth output not readily linkable without both the first and the second secret keys.
  12. 14
    In a digital signature cryptographic method, the improvement comprising a blind signature method comprising the steps of:transforming a message with a first blinding transformation depending on a first secret key, producing a first output;transforming said first output with a blinding transformation depending on a second secret key, producing a second output;developing a digital signature related to said second output depending on a secret signing key;transforming said digital signature with a first unblinding transformation, depending on a first one of said first and said second secret keys, producing a third output;andtransforming said third output with an unblinding transformation, depending on a second one of said first and second secret keys, producing a fourth output retaining a digital signature property related to said message, and said first and fourth output not readily determined to correspond without the first and second secret keys.