Blind signature method, device therefor, and program and recording medium therefor
Abstract
(57) A summary and subject It guarantees that a signature demand person cannot get the right signature more than the number published by the signer. Solution means Whenever there is a signature demand, the signature issue generates the characteristic data rnd, and z=H (rnd), Use z=z/z (z: signer public key) z, z, and z as a temporary public key, and a signature demand person by the random numbers v U=z, Calculate U=z and U=U/U, 撹乱 the document m using U and U, send e to a signer, and a signer signs e with the secret key x, and return r, c, s, and s, and it 撹乱 so that the signature demand person can verify r, c, s, and s, It asks for the certificates L and N proving the relation between the signature F, K, and T by a signer, T, and Z and U, and is referred to as the signature U, U, and F to m, K, T, T, L, and N.
Term
Term ended
Projected expiry passed 27 April 2021, 5.4 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
12 claims: 8 independent, 4 dependent
- 1[Claims] [Claim 1] Each time a signature is issued, the signer's device includes information unique to the issuance, and generates and publishes a temporary public key associated with at least one of the signer's public keys. The signing requester device disturbs the above temporary public key and its original public key, Using this disturbed public key, the signature target is disturbed and sent to the signer's device. The signer's device signs the disturbed signature object received with the private key and sends it to the signer's device. The signature requester device issues a certificate showing the relationship between the original public key and the disturbed public key, and disturbs and makes the received signature verifiable, and the verifiable signature and the above certificate Is a blind signature method, which comprises signing the above-mentioned signature target. 【特許請求の範囲】 【請求項1】 署名者装置は署名発行ごとにその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵を生成して公開し、 署名要求者装置は上記一時的公開鍵及びそのもとの公開鍵を撹乱し、 この撹乱された公開鍵を用いて署名対象を撹乱して署名者装置へ送り、 署名者装置は受信した撹乱された署名対象に対し、秘密鍵で署名して署名要求者装置へ送り、 署名要求者装置はもとの公開鍵と撹乱された公開鍵との関係を示す証明書を発行し、かつ受信した署名を撹乱して検証可能にし、この検証可能とされた署名と上記証明書を上記署名対象に対する署名とすることを特徴とするブラインド署名方法。
- 2The signer device generates and publishes a temporary public key that includes information unique to the issuance for each signature issuance and is associated with at least one of the signer device's public keys, and is also a random number. To the signature requester device, The signing requester device disturbs the temporary public key and its original public key, generates data based on the disturbed public key and the random number received from the signing device, and transfers the data to the signing device. Send, The signer device signs the received data with the private key and sends it to the sign requester device. The signing requester device disrupts the received signature so that it can be verified, and associates the disturbed signature with the signature target. Using the associated information and the information used to disturb the public key, a certificate showing the relationship between the original public key and the disturbed public key is issued, and this certificate can be verified as described above. A blind signature method, characterized in that the signature is a signature for the above-mentioned signature target. 【請求項2】 署名者装置は署名発行ごとにその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵を生成して公開し、また乱数を署名要求者装置へ送り、 署名要求者装置は一時的公開鍵及びそのもとの公開鍵を撹乱し、その撹乱された公開鍵と、署名者装置から受信した乱数に基づいてデータを生成し、そのデータを署名者装置へ送り、 署名者装置は受信したデータに対し秘密鍵で署名して署名要求者装置へ送り、 署名要求者装置は受信した署名を検証可能なように撹乱し、その撹乱された署名と、署名対象を関連付け、 その関連付けられた情報と、上記公開鍵の撹乱に用いた情報とを用いて、もとの公開鍵と撹乱された公開鍵との関係を示す証明書を発行し、この証明書と上記検証可能とされた署名を上記署名対象に対する署名とすることを特徴とするブラインド署名方法。
- 3A means for sending a signature issuance request to a signer device, Disrupts the temporary public key and its original public key that contain information unique to the issue published by the signer's device for the signature issuance and that is associated with at least one of the signer's public keys. Means and A means of disturbing the signature target using this disturbed public key and sending it to the signer's device, A means of disturbing and verifiable the signature received from the signer device and issuing a certificate showing the relationship between the original public key and the disturbed public key. A means for outputting the verifiable signature and the certificate as a signature for the signature target together with the signature target, and A signature requester device for blind signatures. 【請求項3】 署名者装置に署名発行要求を送る手段と、 その署名発行に対し署名者装置から公開されたその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵及びそのもとの公開鍵を撹乱する手段と、 この撹乱された公開鍵を用いて署名対象を撹乱して署名者装置へ送る手段と、 署名者装置から受信した署名を撹乱して検証可能にすると共にもとの公開鍵と撹乱された公開鍵との関係を示す証明書を発行する手段と、 上記検証可能とされた署名及び上記証明書を上記署名対象に対する署名としてその署名対象と共に出力する手段と、 を具備するブラインド署名の署名要求者装置。
- 4A means for sending a signature issuance request to a signer device, Disrupts the temporary public key and its original public key that contain information unique to the issue published by the signer's device for the signature issuance and that is associated with at least one of the signer's public keys. Means and A means of generating data based on the disturbed public key and a random number received from the signer's device and sending the data to the signer's device. Means to disturb the signature received from the signer device so that it can be verified, A means of generating information that associates the disturbed signature with the signature target, A means of issuing a certificate showing the relationship between the original public key and the disturbed public key by using the associated information and the information used for disturbing the public key. The disturbed signature, the means for outputting the certificate as a signature for the signature target, and A signature requester device for blind signatures. 【請求項4】 署名者装置に署名発行要求を送る手段と、 その署名発行に対し署名者装置から公開されたその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵及びそのもとの公開鍵を撹乱する手段と、 その撹乱された公開鍵と、署名者装置から受信した乱数に基づいてデータを生成し、そのデータを署名者装置へ送る手段と、 署名者装置から受信した署名を検証可能なように撹乱する手段と、 その撹乱された署名と署名対象とを関連付けた情報を生成する手段と、 その関連付けられた情報と上記公開鍵の撹乱に用いた情報とを用いて、もとの公開鍵と撹乱された公開鍵との関係を示す証明書を発行する手段と、 上記撹乱された署名、上記証明書を上記署名対象に対する署名として出力する手段と、 を具備するブラインド署名の署名要求者装置。
- 5Each time a signature issuance request is received from a signing requester device, a temporary public key that includes information unique to the issuance and is associated with at least one of the signing party's public keys is generated. Means to publish and A means of signing the disturbed signature target received from the sign requester device with a private key and sending it to the sign requester device, A blind signature signer device comprising. 【請求項5】 署名要求者装置から署名発行要求を受信するごとにその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵を生成して公開する手段と、 署名要求者装置より受信した撹乱された署名対象に対し、秘密鍵で署名して署名要求者装置へ送る手段と、 を具備するブラインド署名の署名者装置。
- 7The process of making a signature issuance request to the signer device and For the signature issuance, it disturbs the temporary public key and its original public key that contain information unique to the issuance published by the signer's device and that is associated with at least one of the signer's public keys. And the process of doing The process of disturbing the signature target using the disturbed public key and sending it to the signer's device, The process of disturbing the signature received from the signer device to make it verifiable and generating a certificate showing the relationship between the original public key and the disturbed public key. The process of outputting the disturbed signature and the certificate together with the signature target as a signature for the signature target, and How to handle a signing requester device with a blind signature. 【請求項7】 署名者装置に署名発行要求を行う過程と、 その署名発行に対し、署名者装置から公開されたその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵及びそのもとの公開鍵を撹乱する過程と、 その撹乱された公開鍵を用いて署名対象を撹乱して署名者装置へ送る過程と、 署名者装置から受信した署名を撹乱して検証可能にすると共にもとの公開鍵と撹乱された公開鍵との関係を示す証明書を生成する過程と、 上記撹乱された署名及び上記証明書を上記署名対象に対する署名として署名対象と共に出力する過程と、 を有するブラインド署名の署名要求者装置の処理方法。
- 8The process of sending a signature issuance request to the signer device, Disrupts the temporary public key and its original public key that contain information unique to the issuance published by the signer's device for the signature issuance and that is associated with at least one of the signer's public keys. The process and The process of generating data based on the disturbed public key and the random number received from the signer device and sending the data to the signer device, The process of disturbing the signature received from the signer device so that it can be verified, The process of generating information that associates the disturbed signature with the signature target, Using the associated information and the information used to disturb the public key, the process of issuing a certificate showing the relationship between the original public key and the disturbed public key, and The disturbed signature, the process of outputting the certificate as a signature for the signature target, and A signature requester device processing method for blind signatures. 【請求項8】 署名者装置に署名発行要求を送る過程と、 その署名発行に対し署名者装置から公開されたその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵及びそのもとの公開鍵を撹乱する過程と、 その撹乱された公開鍵と、署名者装置から受信した乱数に基づいてデータを生成し、そのデータを署名者装置へ送る過程と、 署名者装置から受信した署名を検証可能なように撹乱する過程と、 その撹乱された署名と署名対象とを関連付けた情報を生成する過程と、 その関連付けられた情報と上記公開鍵の撹乱に用いた情報とを用いて、もとの公開鍵と撹乱された公開鍵との関係を示す証明書を発行する過程と、 上記撹乱された署名、上記証明書を上記署名対象に対する署名として出力する過程と、 を有するブラインド署名の署名要求者装置処理方法。
- 9Each time a signature issuance request is received from a signing requester device, a temporary public key that includes information unique to the issuance and is associated with at least one of the signing party's public keys is generated. The process of publishing and The process of signing the disturbed signature target received from the sign requester device with the private key and sending it to the sign requester device, A blind signature signer device processing method with. 【請求項9】 署名要求者装置から署名発行要求を受信するごとにその発行に固有な情報を含み、かつ署名者装置の公開鍵の少くとも一つと関連付けられた一時的公開鍵を生成して公開する過程と、 署名要求者装置より受信した撹乱された署名対象に対し、秘密鍵で署名して署名要求者装置へ送る過程と、 を有するブラインド署名の署名者装置処理方法。
Independent claims8
91 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a blind signature method, a device thereof, a program thereof, and a recording medium thereof, which allows a signer to attach an electronic signature to electronic information while keeping the electronic information confidential.
【0002】
[Conventional technology]
For this type of blind signature, the method based on the RSA method is described in Reference D. Chaum, Security without Identification: Transaction Systems to Make Big Brother Obsolete, Comm.of the ACM, 28,10, pp.1030-1044 (1985). ). The requester of the signature creates a blind message e by disturbing the document m with a random number a by the blind signature preprocessing. The signer uses the private key to calculate the tentative signature s corresponding to e. At this time, since e is disturbed by a, the signer cannot know the document m. The signing requester removes the influence of the random number a from the temporary signature s by blind signature post-processing, obtains the signature c for the original document m, and sends the pair of m and c to the verifier. The verifier uses the signer's public key to verify that c is the signature of m. Here, since the verifier does not know the random number a, he cannot know the correspondence between s and c.
【0003】
The procedure for blind signature based on Schnorr signature is shown below. Let p and q be large prime numbers, and let q be divisible by p-1. g, Z<sub>p </sub>It is the source of the order q of. The signer is the private key x and y = g<sup>x </sup>Hold the public key y that satisfies mod p. Let H be a hash function. It is assumed that p, q, g, H and y are open to the public (see Fig. 9 below). Step-1 The signer is a random number k Z<sub>p </sub>To generate r: = g<sup>k </sup>Calculate mod q and send r to the signing requester.
【0004】
Step-2 The signing requester is a random number a, b<sub></sub>Is generated and r is d: = rg<sup>a </sup>y<sup>b b </sup>Disturb with modp. Next, using d and the document m, the challenge h is calculated as h: = H (m, d), and this challenge is disturbed by b as C = h-b mod q. Finally, send C to the signer. Step-3 The signer calculates s = k-xCmod q and sends the tentative signature s to the signing requester. Step-4 The signing requester outputs c: = s + amod q and s as a signature for the document m by disturbing with a so that it can be verified.
【0005】
The signature (h, c) for document m is h = H (m, g)<sup>c </sup>y<sup>h </sup>When mod p) holds, it is recognized as a correct document-signature pair, and if it does not hold, it is considered an invalid signature. If the signature generation procedure is executed correctly, the output (h, c) is h = H (m, d) h = H (m, rg<sup>a </sup>y<sup>b b </sup>mod p) = H (m, g<sup>k + a </sup>y<sup>b b </sup>mod p) = H (m, g<sup>s + xC + a</sup>y<sup>b b </sup>mod p) = H (m, g<sup>c-a + hx-bx + a</sup>y<sup>b b </sup>mod p) = H (m, g<sup>c + hx </sup>mod p) = H (m, g<sup>c </sup>y<sup>h </sup>mod p) And the verification formula h = H (m, g)<sup>c </sup>y<sup>h </sup>mod p) is satisfied.
【0006】
[Problems to be Solved by the Invention]
With the blind signature method described above, it is difficult to prove that the signature (h, c) is unique to the document m, so the security of the signature is unknown. That is, it cannot be denied that the number of signatures requested by the signature requester may be output more than the number requested. Therefore, it cannot be safely used for applications such as electronic cash and electronic tickets that require that the signature issued by the signer cannot be inflated.
【0007】
An object of the present invention is to provide a blind signature method, an apparatus thereof, a program thereof and a recording medium thereof to ensure that a signature requester cannot output more signatures than requested.
【0008】
[Means for solving problems]
According to the present invention, the signer device generates a temporary public key z'from a part z of a plurality of public keys at the time of signing. At this time, z and z satisfy a certain relation R, but generate z in a way that the signing requester can understand the fact that the signer does not know the relation. The signer device generates signatures s based on this z, z'. The signing requester device disturbs z, z'and s to make them U, U', σ, and obtains a signature σ based on a part U of the disturbed public key. At this time, the method of disturbance by the signature requester device is such that when z, z'is correctly disturbed, the relation R satisfied by z, z'is also satisfied by U, U', and the signature requester device If does not follow the correct method of disturbance, make it difficult to obtain U, U', σ that the verifier considers correct.
【0009】
By limiting the method of disturbance by the signature requester device as described above, the signature s issued by the signer device and the signature σ after the disturbance can be related. At the same time, all signatures issued by the signer's device and the signing requester's device by using a perturbation method such that it is difficult for the signer's device to obtain an irrelevant signature by a method other than the original perturbation method. It will be possible to guarantee that there is a one-to-one correspondence between all the correct signatures obtained.
【0010】
BEST MODE FOR CARRYING OUT THE INVENTION
As shown in FIG. 1, the signature requester device 10, the signer device 20, and the verifier device 30 can be connected via, for example, a communication network 40. The signature requester device 10 may be like an IC card, in which case the signer device 20 and the verifier device shall be capable of reading and writing to the IC card. FIG. 2 shows each process of the signature requester device 10 and the signer device 20 and an example of mutual communication, FIG. 3 shows an example of the process procedure in the signer device 20, and FIG. 4 shows a process procedure of the signature requester device 10. Examples of each are shown. Embodiment 1 In this embodiment, a method based on the Schnorr signature will be described. Let p and q be large prime numbers, and let q be divisible by p-1. g, Z<sub>p </sub>It is the source of the order q of. Z generated by g<sub>p </sub>Let G be a subgroup of. The signer device has private keys x and y = g<sup>x </sup>Hold the public key y that satisfies mod p. H, H<sub>1 </sub>, H<sub>2 </sub>Is a hash function. H, H<sub>1 </sub>, H<sub>2 </sub>Is a hash function that accepts arbitrary input and outputs G elements. Let h be h = H (gThepTheqThey). z = H<sub>1</sub>Let (gThepTheqThehThey). p, q, g, h, H, H<sub>1 </sub>, H<sub>2 </sub>And y, z shall be publicly available as a public key. In the following explanation, all operations shall be performed by mod p unless otherwise specified.
【0011】
First, the processing procedure of the signer device 20 will be described (see FIGS. 2 and 3). When the signature requester device 10 requests a signature (A0), the signer device issues a blind signature according to the following procedure. A1: Select (generate) the unique information rnd for issuing any of the signatures. For example, rnd may be a random character string that is different for each signature issued, or may be a serial number. A2: z<sub>1 </sub>: = H<sub>1</sub>(rnd), z<sub>2 </sub>: = z / z<sub>1 </sub>Calculate mod p. This z (part of the public key) and z<sub>1 </sub>, z<sub>2 </sub>Is a temporary public key for each signature issuance. Temporary public key z and z<sub>1 </sub>Are both elements of G, so z = z<sub>1</sub><sup>i</sup>The relationship is always established, but z and z<sub></sub><sub></sub><sub>1 </sub>Finding i from is a so-called discrete logarithm problem and is difficult. That is, the temporary public keys z and z<sub>1 </sub>Is z = z<sub>1</sub><sup>i</sup>Satisfies the relationship R, but the signer device 20 z in a way that the signer can be convinced that the signer does not know this relationship.<sub>1</sub>Is being generated.
【0012】
A3: u, s<sub>1 </sub>, s<sub>2 </sub>Randomly select (generate), d from {0, ..., q-1}. A4: a: = g<sup>u </sup>, b<sub>1 </sub>: = g<sup>s1</sup>z<sub>1</sub><sup>d</sup>, b<sub>2 </sub>: = h<sup>s2</sup>z<sub>2</sub><sup>d</sup>To calculate. A5: rnd, a, b<sub>1 </sub>, b<sub>2 </sub>Is sent to the signature requester device 10. A6: Receive e from the signing requester device 10. A7: Find c: = e-dmod q. A8: Find r: = u-cxmod q. In other words, blind signature is done with the private key x.
【0013】
A9: r, c, s<sub>1 </sub>, s<sub>2 </sub>Is temporarily sent to the signing requester device 10 as a signature. After making a request to the signer device 20 (B0), the signing requester device 10 obtains a signature for the document m according to the following procedure (see FIGS. 2 and 4). B1: rnd, a, b<sub>1 </sub>, b<sub>2 </sub>Is received from the signer device 20. B2: b<sub>1 </sub>, b<sub>2 </sub>Make sure that is an element of G. Otherwise it terminates abnormally (b)<sub>1 </sub>Is an element of G, for example b<sub>1</sub><sup>q</sup>It can be confirmed by the fact that mod p = 1 holds. b b<sub>2 </sub>The same applies to). For example, b<sub>1 </sub>As for q, g<sub>1 </sub>, z<sub>1 </sub>Are both elements of G, so g<sup>s1</sup>, z<sub>1</sub><sup>d</sup>Are also elements of G, and the product of these is also an element of G.
【0014】
B3: z<sub>1 </sub>: = H<sub>1</sub>Calculate (rnd). B4: v is randomly selected (generated) from {1, ..., q-1}. B5: U: = z<sup>v </sup>, U<sub>1 </sub>: = z<sub>1</sub><sup>v</sup>, U<sub>2 </sub>: = U / U<sub>1 </sub>To calculate. That is, the temporary public key z, z<sub>1 </sub>To disturb. Moreover, U and U<sub>1 </sub>Is z = z<sup>i </sup>The same relationship as the relationship U = U<sub>1</sub><sup>i</sup>Will be satisfied. Z, z so that such a relationship can be obtained<sub>1 </sub>Is disturbing. B6: t<sub>1 </sub>, t<sub>2 </sub>, t<sub>3 </sub>, t<sub>4 </sub>, t<sub>5 </sub>Is randomly selected (generated) from {0, ..., q-1}.
【0015】
B7: A: = ag<sup>t1</sup>y<sup>t2</sup>, B<sub>1 </sub>: = b<sub>1</sub><sup>v</sup>g<sup>t3</sup>U<sub>1</sub><sup>t4</sup>, B<sub>2 </sub>: = b<sub>2</sub><sup>v</sup>h<sup>t5</sup>U<sub>2</sub><sup>t4</sup>To calculate. That is, a, b<sub>1 </sub>, b<sub>2 </sub>Is disturbed, and the tentative signature is disturbed. B8: W is randomly selected (generated) from {0, ..., q-1}. B9: D: = z<sup>w </sup>To calculate. B10: E: = H<sub>2</sub>(UTheU<sub>1 </sub>TheATheB<sub>1 </sub>B<sub>2 </sub>TheDThem) (challenge) is sought. B11: e: = Et<sub>2 </sub>-t<sub>4 </sub>Find mod q. That is, it disturbs E.
【0016】
B12: Send e to signer device 20. Since the signer device 20 processes steps A7 and A8 for this e, z, z<sub>1 </sub>, z<sub>2 </sub>Temporary signature based on r, c, s<sub>1 </sub>, s<sub>2 </sub>Will be generated. B13: Temporary signature r, c, s from signer device 20<sub>1 </sub>, s<sub>2 </sub>To receive. B14: F: = r + t<sub>1 </sub>mod q, K: = c + t<sub>2 </sub>mod q, T<sub>1 </sub>: = vs<sub>1 </sub>+ t<sub></sub><sub></sub><sub>3 </sub>mod q, T<sub>2 </sub>: = vs<sub>2 </sub>+ t<sub>5 </sub>mod q, L: = e-c + t<sub>4 </sub>Find mod q, N: = w-Lv mod q. That is, the tentative signature is disturbed so that it can be verified, and the disturbed temporary public key U is proved to be generated from the original public key. Generate certificates L and N. Since the disturbance is used as an exponent at the time of verification, it is performed by an addition process. In this way, the tentative signature s<sub>1 </sub>, s<sub>2 </sub>Disturbance against, z, z<sub>1 </sub>It is done in the same relationship as the disturbance to.
【0017】
B15: K + L = H<sub>2</sub>(UTheU<sub>1 </sub>Theg<sup>F </sup>y<sup>K </sup>Theg<sup>T1</sup>U<sub>1</sub><sup>L</sup>Theh<sup>T2</sup>U<sub>2</sub><sup>L</sup>The z<sup>N </sup>U<sup>L </sup>Them) If mod q holds, proceed to the next step. If it does not hold, it ends abnormally. That is, it is verified that the signer device 20 has signed correctly. That is, g<sup>F </sup>y<sup></sup><sup></sup><sup>K </sup>, g<sup>T1</sup>U<sub>1</sub><sup>L</sup>, h<sup>T2</sup>U<sub>2</sub><sup>L</sup>Is to confirm that the signer device 20 was made correctly, z<sup>N </sup>U<sup>L </sup>Is for confirmation that the signing requester device 10 correctly created U from z. B16: U, U like this<sub>1 </sub>, U<sub>2 </sub>U, U by the perturbation treatment of step B14 with the signature based on<sub>1 </sub>, F, K, T<sub>1 </sub>, T<sub>2 </sub>, L, N are output as a signature for the document m.
【0018】
The signature verifier device 30 is a signature-document pair (U, U).<sub>1 </sub>, F, K, T<sub>1 </sub>, T<sub>2 </sub>, L, N) m for K + L = H<sub>2</sub>(UTheU<sub>1 </sub>Theg<sup>F </sup>y<sup>K </sup>Theg<sup>T1</sup>U<sub>1</sub><sup>L</sup>Theh<sup>T2</sup>(U / U<sub>1</sub>)<sup>L</sup>The z<sup>N </sup>U<sup>L </sup>Them) Verify that mod q and U 1 hold. If it holds, the signature is considered correct, otherwise it is considered an invalid signature. If signature generation is successful K + L = c + t<sub>2 </sub>+ d + t<sub>4 </sub>= e + t<sub>2 </sub>+ t<sub>4 </sub>= E (mod q) g<sup>F </sup>y<sup>K </sup>= g<sup>r + t1</sup>y<sup>c + t2</sup>= g<sup>r + cx</sup>g<sup>t1</sup>y<sup>t2</sup>= ag<sup>t1</sup>y<sup>t2</sup>= A g<sup>T1</sup>U<sub>1</sub><sup>L</sup>= g<sup>vs1 + t3</sup>U<sub>1</sub><sup>d + t4</sup>= (b<sub>1</sub>z<sub>1</sub><sup>-d</sup>)<sup>v</sup>g<sup>t3</sup>U<sub>1</sub><sup>d + t4</sup>= b<sub>1</sub><sup>v</sup>g<sup>t3</sup>U<sub>1</sub><sup>t4</sup>= B<sub>1</sub>h<sup>T2</sup>(U / U<sub>1</sub>)<sup>L</sup>= h<sup>vs2 + t5</sup>U<sub>2</sub><sup>d + t4</sup>= (b<sub>2</sub>z<sub>2</sub><sup>-d</sup>)<sup>V</sup>h<sup>t5</sup>U<sub>2</sub><sup>d + t4</sup>= b<sub>2</sub><sup>v</sup>h<sup>t5</sup>U<sub>2</sub><sup>t4</sup>= B<sub>2</sub>z<sup>N</sup>U<sup>L</sup>= z<sup>w-Lv</sup>U<sup>L </sup>= z<sup>w </sup>= D And (U, U<sub>1 </sub>, F, K, T<sub>1 </sub>, T<sub>2 </sub>, L, N), m pass the verification. In addition, z<sup>N </sup>U<sup>L </sup>It will be understood that = D to N, L are proofs that U is made from z.
【0019】
If U = 1 is acceptable, U = z<sup>v </sup>Therefore, U = 1 is v = 0, and U = U<sub>1 </sub> U<sub>2 </sub>Therefore, U = 1, U<sub>1 </sub>= 1, U<sub>2 </sub>Allows the relationship of = 1, y = g<sup>x </sup>There is a relationship, U = z<sup>v </sup>= g<sup>xo</sup>, U<sub>1 </sub>= g<sup>x1</sup>, D<sub>2 </sub>= h<sup>x2</sup>U = 1, U<sub>1 </sub>= 1, U<sub>2 </sub>Allowing = 1 is x<sub>0 </sub>= x<sub>1 </sub>= x<sub>2 </sub>Can be signed as = 0, i.e. x<sub>0 </sub>, x<sub>1 </sub>, x<sub>2 </sub>Anyone other than those who know or x will be able to sign. Therefore, in step B4, v is selected from {1, ..., q-1}, and if U = 1, it is not recognized as a signature by the legitimate signer device 20.
【0020】
The order of the variables input to the hash function may be any order as long as the procedure of the signing requester device 10 and the verifier device 30 is the same. In the above method, the temporary public key generation means of the signer device 20 z from any unique string rnd that is selected each time it is signed.<sub>1 </sub>= H<sub>1</sub>Calculate (rnd), z and z<sub>1 </sub>Is used as a temporary public key. In addition, the temporary public key disturbing means of the signing requester device 10 randomly selects the disturbing component v, and U = z.<sup>v </sup>, U<sub>1 </sub>= z<sub>1</sub><sup>v</sup>Like z, z<sub>1 </sub>Disturb, U, U<sub>1 </sub>Is a disturbed temporary public key.
【0021】
Temporary public key (U, U) disturbed by the above procedure<sub>1 </sub>) Is the original temporary public key (z, z) used when issuing the signature<sub>1 </sub>), Log<sub>2 </sub>z<sub>1 </sub>= log<sub>U </sub>U<sub>1 </sub>Have a relationship. However, someone other than the signing requester who does not know the disturbing component v (z, z)<sub>1 </sub>, U, U<sub>1 </sub>) Satisfies the relationship, which is a problem called Diffie-Hellman decision problem, which is considered to be computationally difficult. Therefore, even the signaturer has the signature sent to the verifier device 30. However, it is difficult to determine which signature requester device 10 the signature was issued to. In other words, it is difficult for the signer to deal with the signature document m and the signature requester. Therefore, the above method provides blindness as a blind signature.
【0022】
The signature issuing procedure of the above embodiment is y = g.<sup>x </sup>The private key x, or z<sub>1 </sub>= g<sup>w1</sup>, z / z<sub>1 </sub>= h<sup>w2</sup>W<sub>1 </sub>, w<sub>2 </sub>It is a zero-knowledge proof of knowing one of the private keys. w<sub>1 </sub>, w<sub>2 </sub>The zero-knowledge proof part for is (z) by multiplying both sides by v at the same time.<sub>1</sub>)<sup>v</sup>= g<sup>w1v</sup>, (z / z<sub>1</sub>)<sup>v</sup>= h<sup>w2v</sup>In w<sub></sub><sub></sub><sub>1 </sub>, w<sub>2 </sub>It is possible to convert to zero-knowledge proof of. Therefore, U, U made according to the correct disturbance procedure<sub>1 </sub>Regarding, the signing requester device 10 is w<sub>1 </sub>, w<sub>2 </sub>Zero-knowledge proof (rnd, a) by signer device 20 without knowing<sub>1</sub>, b<sub>1 </sub>, b<sub>2 </sub>, r, c, s<sub>1 </sub>, s<sub>2 </sub>) Can be converted to obtain a signature that passes the verification. However, U, U did not follow the original disturbance procedure.<sub>1 </sub>Is v = v<sub>1 </sub>V, v<sub>1</sub>Against U = z<sup>v </sup>, U<sub>1 </sub>= z<sub>1</sub><sup>v1</sup>If so, s<sub>1 </sub>, s<sub>2 </sub>I don't know what to do with the disturbance. Therefore, it is not possible to convert the zero-knowledge proof by the signer device 20 to obtain a signature that passes the verification. Creating a signature that passes verification by means other than converting the zero-knowledge proof by the signer device 20 is y = g, as described above.<sup>x </sup>The private key x, or z<sub>1 </sub>= g<sup>w1</sup>, z / z<sub>1 </sub>= h<sup>w2</sup>W<sub></sub><sub></sub><sub>1 </sub>, w<sub>2 </sub>It is equivalent to performing a zero-knowledge proof that the signer knows any of the private keys, and no third party other than the signer can do this. Therefore, it can be said that all the signatures that pass the verification are linked to one of the signature issuing acts, and the number of signatures that pass the verification does not exceed the number issued.
【0023】
As shown in FIG. 5, the functional configuration of the signature requester device 10 is such that public keys such as g, p, q, y, h, and z are stored in the storage unit 101, and the transmission unit 102 and the reception unit 103 are provided. A signature request is issued to the signer device 20, and the signature device 20 issues a signature unique information rnd, a disturbed random number a, and a disturbed temporary public key b.<sub>1 </sub>, b<sub>2 </sub>Is received, in the element determination unit 104, b<sub>1 </sub>, b<sub>2 </sub>Is determined to be an element of the subgroup G, and if the determination is passed, the temporary public key arithmetic unit 105 z<sub>1 </sub>= H<sub>1</sub>(rnd) is calculated, and in the temporary public key disturbance unit 106, the random number v Z from the random number generation unit 107.<sub>q </sub>U = z in U arithmetic unit 108 using<sup>v </sup>But U<sub>1 </sub>U in arithmetic unit 109<sub>1 </sub>= z<sub>1</sub><sup>v</sup>But U<sub>2 </sub>U in arithmetic unit 111<sub>2 </sub>= U / U<sub>1 </sub>Are calculated respectively.
【0024】
Random number generator 112 to t<sub>1 </sub>, ..., t<sub>5 </sub> Z<sub>q </sub>Is generated, and in the random number disturbance unit 113, A = ag in the A calculation unit 114.<sup>t1</sup>y<sup>t2</sup>But B<sub>1 </sub>B in arithmetic unit 115<sub>1 </sub>= b<sub>1</sub><sup>v</sup>g<sup></sup><sup></sup><sup>t3</sup>U<sub>1</sub><sup>t4</sup>But B<sub>2 </sub>B in arithmetic unit 116<sub>2 </sub>= b<sub>2</sub><sup>v</sup>h<sup>t5</sup>U<sub>2</sub><sup>t4</sup>Are calculated respectively. Random number w Z from random number generator 117<sub>q </sub>By D = z in D arithmetic unit 118<sup>w </sup>Is calculated, and in the challenge generation unit 119, in the E calculation unit 121 E = H<sub>2</sub>(UTheU<sub>1 </sub>TheA<sup></sup>B<sub>1 </sub>B<sub>2 </sub>TheDThem) Is calculated, and e = Et in the e-calculation unit 122.<sub>2 </sub>-t<sub>4 </sub>It is disturbed with mod q, and e is transmitted from the transmitter 102 to the signer device 20.
【0025】
Temporary signature r, c, s from signer device 20<sub>1 </sub>, s<sub>2 </sub>Is received, in the tentative signature disturbance unit 124, F = w + t in the F calculation unit.<sub>1 </sub>mod q is K = c + t in K arithmetic unit 125<sub>2 </sub>mod q is T<sub>1 </sub>T in arithmetic unit 126<sub>1 </sub>= vs<sub>1 </sub>+ t<sub>3 </sub>mod q is T<sub>2 </sub>T in arithmetic unit 127<sub>2 </sub>= vs<sub>1 </sub>+ t<sub>5 </sub>Each mod q is calculated, and in the certificate generation unit 129, L = e-c + t in the L calculation unit 131.<sub>4 </sub>mod q is calculated by N calculation unit 132, and N = w-Lv mod q is calculated respectively. In the verification unit 133, in the hash calculation unit 134 H<sub>2</sub>(UTheU<sub>1 </sub>Theg<sup>F </sup>y<sup>K </sup>Theg<sup>T1</sup>U<sub>1</sub><sup>L</sup>R<sup>T2</sup>U<sub>2</sub><sup>L</sup>The z<sup>N </sup>U<sup>L </sup>Them) Is calculated, K + L is calculated by the addition unit 135, the calculation result of K + L and the calculation result of the hash calculation unit 134 are compared by the comparison unit 136, and if they match, the signature composition unit 137 m. Its signature (U, U<sub>1 </sub>, F, K, T<sub>1 </sub>, T<sub>2 </sub>, L, N) is added and output from the transmitter 102.
【0026】
The processing of each of the above is executed by the control unit 138. Figure 6 shows an example of the functional configuration of the signer device 20. The private key x, a part of the public key, etc. are stored in the storage unit 201, and in the public key generation unit 202, y = g in the y calculation unit 203.<sup></sup><sup></sup><sup>x </sup>mod p is h = H (gThepTheqThey) in h arithmetic unit 204, and z = H in z arithmetic unit 205.<sub>1</sub>(gThepTheqThehThey) are calculated respectively. These are published, for example, through transmitter 206. When a signature request is received from the signing requester device 10 to the receiving unit 207, the temporary public key generating unit 208 generates the unique information rnd from the unique information generating unit 209 each time, and z<sub>1 </sub>Z in arithmetic unit 211<sub>1 </sub>= H<sub>1</sub>(rnd) is z<sub>2 </sub>Z in arithmetic unit 212<sub>2 </sub>= z / z<sub>1 </sub>Are calculated respectively. Furthermore, random numbers u, s from the random number generator 213<sub>1 </sub>, s<sub>2</sub>, d ( Z<sub>q </sub>) Is generated, and in the random number disturbance unit 214, a = g in the a calculation unit 215.<sup>u </sup>But b<sub>1 </sub>In arithmetic unit 216 b<sub>1 </sub>= g<sup>s1</sup>z<sub>1</sub><sup>d</sup>But b<sub>2 </sub>In arithmetic unit 217 b<sub>2 </sub>= h<sup>s2</sup>z<sub>2</sub><sup>d</sup>Are calculated respectively. Rnd, a, b as random numbers<sub>1 </sub>, b<sub>2 </sub>Is transmitted from the transmission unit 206 to the signature requester device 10.
【0027】
When the challenge e is received from the signature requester device 10 in the receiving unit 207, the signature unit 231 calculates c = ed mod q in the c calculation unit 232 and the r calculation unit 233 calculates r = u-c x mod q. , Temporary signature r, c, s<sub>1 </sub>, s<sub>2 </sub>Is transmitted from the transmission unit 206 to the signature requester device 10. The processing in each of the above units is controlled and executed by the control unit 234. Figure 7 shows an example of the functional configuration of the verifier device 30. The public key g, q, y, h, z is stored in the storage unit 301, and when the document m to be verified and its signature are input to the reception unit 302, it is temporarily stored in the storage unit 301 and the U determination unit. At 303, it is determined whether or not U is 1, and the result is supplied to the output unit 304. A calculation unit 305 g<sup></sup><sup></sup><sup>F </sup>y<sup>K </sup>But B<sub>1 </sub>G in arithmetic unit 306<sup>T1</sup>U<sub>1</sub><sup>L</sup>But B<sub>2 </sub>Calculator 307 h<sup>T2</sup>(U / U<sub>1</sub>)<sup></sup><sup></sup><sup>L </sup>However, in D calculation unit 308, z<sup>N </sup>U<sup>L </sup>Are calculated respectively. These calculation results and U, U<sup>1 </sup>, M are input to the hash calculation unit 309, and the hash function calculation of these bit concatenations is performed. Further, K and L are added by the addition unit 311 and these addition values and hash values are compared by the comparison unit 312, and the comparison result is supplied to the output unit 304. From the output unit 304, whether or not the signature is correct is transmitted to the verification requester through the transmission unit 314. The control unit 315 controls the execution of the processing of each unit. Embodiment 2 In the above, the document m to be signed is sent to the signer device 20, and the temporary public keys U and U whose signature m is disturbed in step B10 at the time of requesting the signature.<sub>1 </sub>The signer device 20 blindly signed the signature device 20 with the private key x, but according to the method of the present invention, the signature requester was blindly signed from the signer device 20 ( After receiving the (temporary signature), you can add a signature target at any time. Hereinafter, only the processes different from those of the second embodiment will be described.
【0028】
In the signing requester device 10, m is omitted in step B10, E = H<sub>2</sub>(UTheU<sub>1 </sub>TheA<sup></sup>B<sub>1 </sub>B<sub>2 </sub>TheD) Is calculated. Verification in step B15 is based on the following equation K + L = H<sub>2</sub>(UTheU<sub>1 </sub>Theg<sup>F </sup>y<sup>K </sup>Theg<sup>T1</sup>U<sub>1</sub><sup>L</sup>Theh<sup>T2</sup>U<sub>2</sub><sup>L</sup>The z<sup>N </sup>U<sup>L </sup>) mod q In step B16, if the verification of step B15 is true (U, U)<sub>1 </sub>, F, K, T<sub>1 </sub>, T<sub>2 </sub>) S<sub>p</sub>Is retained, and N is omitted. v and w to S<sub>p </sub>Keep with. The following processing is performed when signing the signature target m (see Fig. 8).
【0029】
When B16-1: m is entered, M = H<sub>3</sub>(z<sup>w </sup>TheS<sub>p </sub>Them) is calculated. H<sub>3</sub>Is a hash function, Z<sub>p </sub>It outputs the elements of the subgroup G of, and is open to the public. B16-2: Calculate N'= w-Mvmod q. B16-3: S<sub>p </sub>, M, N'are output as the signature for the signature target m. The certificates that prove that the disturbed temporary public key U was generated from the original public key z are L and N'.
【0030】
In the verifier device 30, S<sub>p </sub>, M, N'and m are received and U 1 K + L = H<sub>2</sub>(UTheU<sub>1 </sub>UTheg<sup>F </sup>y<sup>K </sup>Theg<sup>T1</sup>U<sub>1</sub><sup>L</sup>Theh<sup>T2</sup>(U / U<sub>1</sub>)<sup>L</sup>The z<sup>N'</sup>U<sup>M</sup><sup></sup>) mod q M = H<sub>3</sub>(z<sup>N'</sup>U<sup>M </sup>TheS<sub>p </sub>Them) mod q If both of these equations hold, it is a valid signature for M. This is z<sup>N'</sup>U<sup>M </sup>= z<sup>w-Mv</sup>z<sup>vM</sup>It is easy to understand from the fact that = D. For example S<sub>p </sub>Is the electronic cash signed by the bank, and the signature target m is the electronic cash S that uniquely determines the shopping (transaction) by the electronic cash.<sub>p </sub>When paying by S<sub>p </sub>, M, N'may be sent to the store equipment.
【0031】
As described above, when the signature target m is attached at any time, in the signature requester device 10, the random numbers a and b received from the signer device 20 in steps B10 and B11<sub>1 </sub>, b<sub>2 </sub>And disturbed temporary public key U, U<sub>1 </sub>Data e is created based on the above and sent to the signer device 20. The signer device 20 performs signature processing (steps A7 and A8) on the data e, and the signing requester device 10 can verify the tentative signature on the data e when outputting the signature target m and its signature. Disturbed to F, K, T, T<sub>1 </sub>, T<sub>2 </sub>(This may be done in advance), and the signature S of the signer device 20 for the data e.<sub>p </sub>= (U, U<sub>1 </sub>, F, K, T<sub>1 </sub>, T<sub>2 </sub>) Ask for this signature S<sub>p </sub>The information M that associates with the signature target m is generated, and the disturbed temporary public key is generated from the original public key by using the information M and the information for disturbing the temporary public key. Generate a certificate of existence N'and S<sub>p </sub>, M, N'are the signatures for the signature target m.
【0032】
Therefore, the signature requester device 10 has a means for generating the above information M, a means for generating the certificate N', and S.<sub>p </sub>A means for outputting, M, N'as a signature for m will be provided. The signature requester device 10, the signer device 20, and the verifier device 30 may each be operated by executing a program by a computer. The above embodiment is the multiplicative group Z.<sub>p</sub><sup>*</sup>As with the El Gamal signature, the example constructed above can be implemented on any group where the discrete logarithm problem is difficult. For example, according to the purpose of this embodiment, it may be carried out with a finite group on an elliptic curve.
【0033】
[Effect of the invention]
As described above, according to the present invention, it is guaranteed that the signature requester device cannot obtain more correct signatures than the number issued by the signer device, and the signatures such as electronic cash and electronic tickets are inflated. Blind signatures can also be used in applications where is a problem.
[Simple explanation of drawings]
[Figure 1]
The figure which shows the structural example of the system to which this invention is applied.
[Figure 2]
The figure which shows the processing procedure of Embodiment 1 of this invention method.
[Fig. 3]
The flow chart which shows the processing procedure of the signer apparatus 20 in Embodiment 1. FIG.
[Fig. 4]
The flow chart which shows the processing procedure of the signature requester apparatus 10 in Embodiment 1. FIG.
[Fig. 5]
The block diagram which shows the functional structure of the signature requester apparatus 10 in Embodiment 1. FIG.
[Fig. 6]
The block diagram which shows the functional structure of the signer apparatus 20 in Embodiment 1. FIG.
[Fig. 7]
The block diagram which shows the functional structure of the verifier apparatus 30 in Embodiment 1. FIG.
[Fig. 8]
The flow chart which shows a part of the process of the signature requester apparatus 10 in Embodiment 2.
[Fig. 9]
The figure which shows the procedure of the conventional blind signature method.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8806197B2 | Cited by | United States of America | Applicant |
| JP2008527865A | Cited by | Japan | Examiner |
| US8788827B2 | Cited by | United States of America | Applicant |
| US8204232B2 | Cited by | United States of America | Applicant |
| JP2012014203A | Cited by | Japan | Examiner |
| US10284370B2 | Cited by | United States of America | Applicant |
| US8745376B2 | Cited by | United States of America | Applicant |
| JP4870155B2 | Cited by | Japan | Examiner |
| JP2012212164A | Cited by | Japan | Search report |
| US8467535B2 | Cited by | United States of America | Applicant |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001131859 | Japan | A | |
| JP20010131859 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2002328602AThis record | Japan | A | |
| JP3859983B2 | Japan | B2 |
19 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Written notification of registration of transferR350 | R350 | |
| Written request for registration of change of domicileS531 | S531 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written amendmentA521 | A521 | |
| Notification of appointment of power of attorneyRD03 | RD03 | |
| Notification of reasons for refusalA131 | A131 |
Numbers
- Publication
- 2002-328602
- Publication, DOCDB
- 2002328602
- Publication, EPODOC
- JP2002328602
- Application
- 131859
- Application, DOCDB
- 2001131859
- Application, EPODOC
- JP20010131859
Titles2
- Japanese
- 【発明の名称】ブラインド署名方法、その装置、そのプログラム及びその記録媒体
- English
- [Title of the Invention] A blind signature method, an apparatus thereof, a program thereof, and a recording medium thereof.
Classification
- IPC, 5
- G06Q50 00
- G06Q50 10
- G06Q50 26
- G09C1 00
- H04L9 32