EP1145483B1

Authenticating or signature method with reduced computations

Abstract

Authentication and signature process with reduced number of calculations. The process involves a first entity called the “prover”, which possesses a public key v and a secret key s, these keys verify the relation v=s−t (mod n), where n is an integer called modulus and t is a parameter, and a second entity called a “verifier”, which knows the public key v. This process implies exchange of information following a “zero-knowledge protocol” between the verifier and the prover and cryptographic calculations on this information, some calculations being carried out “modulo n”. The process of the invention is characterised by the fact that the modulus n is specific to the prover that communicates this modulus to the verifier.

EP1145483B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 26 January 2020, 6.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

7 claims: 7 independent, 0 dependent

  1. 1
    Authentication process involving a first entity called a "prover" (A), which possesses a public key v and a secret key s, these keys being related y an operation modulo n, where n is an integer called modulus, and a second entity called a "verifier" (B), which knows the public key v, wherein these entities are provided with means to exchange zero-knowledge information and carry out cryptographic calculations on this information, some calculations being carried out modulo n, the process being characterized in that the modulo n operation is of the type v=s-t (mod n), t being a parameter. Authentication process involving a first entity called a "prover" (A), which possesses a public key v and a secret key s, these keys being related y an operation modulo n, where n is an integer called modulus, and a second entity called a "verifier" (B), which knows the public key v, wherein these entities are provided with means to exchange zero-knowledge information and carry out cryptographic calculations on this information, some calculations being carried out modulo n, the process being characterized in that the modulo n operation is of the type v=s-t (mod n), t being a parameter. Authentifizierungsverfahren, das eine erste, "zu authentifizierende" Einheit (A), welche eine öffentlichen Schlüssel v und einen Geheimschlüssel s besitzt, wobei diese Schlüssel durch eine Operation modulo n verbunden sind, wobei n eine Modul genannte ganze Zahl ist, und der Modul n der zu authentifizierenden Einheit A eigen ist, sowie eine zweite, "authentifizierende" Einheit (B), welche den öffentlichen Schlüssel v kennt, verwendet, wobei diese Einheiten Einrichtungen umfassen, die Informationen vom Typ mit Null-Beitrag an Kenntnis bzw. Wissen austauschen können und auf diese Informationen gestützt, kryptographische Berechnungen ausführen können, wobei bestimmte Berechnungen modulo n ausgeführt werden, wobei dieses Verfahren dadurch gekennzeichnet ist, daß die Operation modulo n vom Typ v=s-t (mod n) ist, wobei t ein Parameter ist. Procédé d'authentification mettant en oeuvre une première entité dite "à authentifier" (A), possédant une clé publique v et une clé secrète s, ces clés étant reliées par une opération modulo n où n est un entier appelé module, le module n étant propre à l'entité à authentifier (A), et une seconde entité dite "authentifiante" (B), connaissant la clé publique v, ces entités, comprenant des moyens aptes à échanger des informations du type à apport nul de connaissance et à effectuer des calculs cryptographiques portant sur ces informations, certains calculs étant effectués modulo n, ce procédé étant caractérisé en ce que l'opération modulo n est du type v=s-t (mod n), t étant un paramètre.
  2. 2
    Process according to claim 1, wherein the information exchanges are of zero-knowledge type and the cryptographic calculations are as follows:· the prover (A) selects one (several) integer(s) r at random, ranging between 1 and n-1 and calculates one (several) parameter(s) (x) equal to rt (mod n), then one (several) number(s) c called opening(s) which is (are) one (several) function(s) of this (these) parameter(s) and possibly of a message (M), and sends this (these) opening(s) to the verifier (B):· the verifier entity (B) receives the opening(s) c, selects one number e at random called "question" and sends this question to the prover (A);· the prover (A) receives the question e, carries out one (several) calculation(s) using this question e and the secret key s, the result of this (these) calculation(s) yielding one (several) answer(s) y and sends this (these) answer(s) to the verifier (B);· the verifier (B) receives the answer(s) y, carries out one calculation using the public key v and the modulus n, and checks with a modulo n calculation that the result is coherent with the received opening(s). Process according to claim 1, wherein the information exchanges are of zero-knowledge type and the cryptographic calculations are as follows: · the prover (A) selects one (several) integer(s) r at random, ranging between 1 and n-1 and calculates one (several) parameter(s) (x) equal to rt (mod n), then one (several) number(s) c called opening(s) which is (are) one (several) function(s) of this (these) parameter(s) and possibly of a message (M), and sends this (these) opening(s) to the verifier (B):· the verifier entity (B) receives the opening(s) c, selects one number e at random called "question" and sends this question to the prover (A);· the prover (A) receives the question e, carries out one (several) calculation(s) using this question e and the secret key s, the result of this (these) calculation(s) yielding one (several) answer(s) y and sends this (these) answer(s) to the verifier (B);· the verifier (B) receives the answer(s) y, carries out one calculation using the public key v and the modulus n, and checks with a modulo n calculation that the result is coherent with the received opening(s). Procédé selon la revendication 1, dans lequel les échanges d'informations du type à apport nul de connaissance et les calculs cryptographiques sont les suivants : • l'entité à authentifier (A) choisit au hasard un (des) nombre(s) entier(s) r compris entre 1 et n-1 et calcule un (des) paramètre(s) (x) égal (égaux) à rt(mod n), puis un (des) nombre(s) c appelé(s) engagement(s) qui est (sont) une (des) fonction(s) de ce (ces) paramètre(s) et éventuellement d'un message (M), et envoie cet (ces) engagement(s) à l'entité authentifiante (B) ;• l'entité authentifiante (B) reçoit le ou les engagement(s) c, choisit au hasard un nombre e appelé "question" et envoie cette question à l'entité à authentifier (A) ;• l'entité à authentifier (A) reçoit la question e, effectue un (des) calcul(s) utilisant cette question e et la clé secrète s, le résultat de ce (ces) calcul(s) constituant une (des) réponse(s) y, et envoie cette (ces) réponse(s) à l'entité authentifiante (B) ;• l'entité authentifiante (B) reçoit la (les) réponse(s) y, effectue un calcul utilisant la clé publique v et le module n, et vérifie par une opération modulo n que le résultat de ce calcul est bien cohérent avec le (les) engagement(s) reçu(s). Verfahren nach Anspruch 1, wobei die Informationsaustausche vom Typ mit Nullbeitrag an Kenntnis bzw. Wissen und die kryptographischen Berechnungen die folgenden sind: • Die zu authentifizierende Einheit (A) wählt zufällig eine oder mehrere ganze Zahlen r, die zwischen 1 und n-1 liegen, und berechnet einen (der) Parameter (x) gleich rt (mod n), und dann eine Zahl bzw. Zahlen c, die Zusage(n) (engagement(s)) genannt wird/werden, und eine Funktion bzw. Funktionen dieser/dieses Parameter(s) und eventuell einer Nachricht (M) ist/sind, und schickt diese Zusage(n) an die authentifizierende Einheit (B);• die authentifizierende Einheit (B) empfängt die Zusage(n) c, wählt zufällig eine Zahl e, als "Frage" bezeichnet, und sendet diese Frage der zu authentifizierenden Einheit (A);• die zu authentifizierende Einheit (A) empfängt die Frage e, führt eine Berechnung bzw. Berechnungen unter Verwendung dieser Frage e und des geheimen Schlüssels s aus, wobei das Ergebnis dieser Berechnung(en) eine Antwort bzw. Antworten y bildet, und sendet diese Antwort(en) der authentifizierenden Einheit (B);• die authentifizierende Einheit (B) empfängt die Antwort(en) y, führt eine Berechnung unter Verwendung des öffentlichen Schlüssels v und des Moduls n aus, und überprüft durch eine Operation modulo n, ob das Ergebnis dieser Berechnung kohärent mit der/den empfangenen Zusage(n) ist.
  3. 3
    Process according to claim 2, wherein the size of the number n, expressed in number of bits, is less than 1,000. Process according to claim 2, wherein the size of the number n, expressed in number of bits, is less than 1,000. Procédé selon la revendication 2, dans lequel la taille du nombre n, exprimée en nombre de bits, est inférieure à 1 000. Verfahren nach Anspruch 2, wobei die Größe der Zahl n, als Zahl der Bits ausgedrückt, unter 1000 liegt.
  4. 4
    Process according to claim 3, wherein the size of the number n is between 700 and 800. Process according to claim 3, wherein the size of the number n is between 700 and 800. Procédé selon la revendication 3, dans lequel la taille du nombre n est comprise entre 700 et 800. Verfahren nach Anspruch 3, wobei die Größe der Zahl n zwischen 700 und 800 liegt.
  5. 5
    Process according to any of claims 1 to 4, wherein n is the product of at least two primes (p and q) and wherein the modulo n calculations are performed according to the method called "Chinese remainders". Process according to any of claims 1 to 4, wherein n is the product of at least two primes (p and q) and wherein the modulo n calculations are performed according to the method called "Chinese remainders". Procédé selon l'une quelconque des revendications 1 à 4, dans lequel n est le produit d'au moins deux nombres premiers (p, q) et dans lequel les opérations modulo n sont effectuées par la méthode dite "des restes chinois". Verfahren nach einem der Ansprüche 1 bis 4, wobei n das Produkt aus mindestens zwei Primzahlen (p, q) ist, und wobei die Operationen modulo n mit dem sogenannten Verfahren "der chinesischen Reste" ausgeführt werden.
  6. 6
    Message signature process intended for a signatory (A) provided with a public key v and a secret key s, wherein these keys are related via a modulo n calculation, where n is an integer called modulus, the said process involving means to calculate an opening c that is notably function of the message M to be signed, able to calculate a number y that is a function of the secret key, and able to transmit the numbers y and c that are the signature of the message M and to transmit the message M, the process being characterized in that the modulo n operation is the operation v=s-t (mod n), t being a parameter. Message signature process intended for a signatory (A) provided with a public key v and a secret key s, wherein these keys are related via a modulo n calculation, where n is an integer called modulus, the said process involving means to calculate an opening c that is notably function of the message M to be signed, able to calculate a number y that is a function of the secret key, and able to transmit the numbers y and c that are the signature of the message M and to transmit the message M, the process being characterized in that the modulo n operation is the operation v=s-t (mod n), t being a parameter. Nachrichten-Signaturverfahren durch eine sogenannte "signierende" Einheit (A), wobei diese Einheit einen öffentlichen Schlüssel v und einen geheimen Schlüssel s besitzt, wobei diese Schlüssel durch eine Operation modulo n verbunden sind, wobei n eine als "Modul" bezeichnete ganze Zahl ist, die dem Signierenden eigen ist, wobei das Verfahren Einrichtungen umfaßt, welche eine Verbindlichkeit c, die insbesondere Funktion der zu signierenden Nachricht M ist, sowie eine Zahl y, die eine Funktion des geheimen Schlüssels ist, berechnen und die Zahlen y und c, die die Signatur der Nachricht M und die Nachricht M darstellen, senden können, wobei dieses Verfahren dadurch gekennzeichnet ist, daß die Operation modulo n die Operation v=s-t (mod n) ist, wobei t ein Parameter ist. Procédé de signature de message par une entité dite "signataire" (A), cette entité possédant une clé publique v et une clé secrète s, ces clés étant reliées par une opération modulo n où n est un entier appelé "module" qui est propre au signataire, comprenant des moyens aptes à calculer un engagement c fonction notamment du message à signer M et un nombre y fonction de la clé secrète, à émettre les nombres y et c qui constituent la signature du message M et le message M, ce procédé étant caractérisé en ce que l'opération modulo n est l'opération v=s-t (mod n), t étant un paramètre.
  7. 7
    Procédé de signature selon la revendication 6, dans lequel le signataire choisit au hasard un nombre entier r compris entre 1 et n-1, calcule un paramètre x égal à rt(mod n), calcule un nombre c fonction du paramètre x et du message à signer M, calcule un nombre y à l'aide de sa clé secrète s et fonction des nombres r et e, et émet les nombres c et y comme signature. Signature process according to claim 6, wherein the signatory selects an integer r at random between 1 and n-1, calculates a parameter x equal to rt (mod n), calculates a number c that is a function of parameter x and message M to be signed, calculates a number y using its secret key s, the said number y being a function of numbers r and e, and transmits the numbers c and y as signature. Signature process according to claim 6, wherein the signatory selects an integer r at random between 1 and n-1, calculates a parameter x equal to rt (mod n), calculates a number c that is a function of parameter x and message M to be signed, calculates a number y using its secret key s, the said number y being a function of numbers r and e, and transmits the numbers c and y as signature. Signaturverfahren nach Anspruch 6, wobei der Signierende zufällig eine ganze Zahl r wählt, die zwischen 1 und n-1 liegt, einen Parameter x gleich rt (mod n) berechnet, eine Zahl c als Funktion des Parameters x und der zu signierenden Nachricht M berechnet, eine Zahl y mit Hilfe seines geheimen Schlüssels s und als Funktion der Zahlen r und e berechnet und die Zahlen c und y als Signatur sendet.