摘要 |
PURPOSE: To provide a method for certifying at least one identifying device by a confirming device for executing certification by a protocol invalidating decoding based on the problem of decoding by syndrome. CONSTITUTION: A secret vector (s) of humming weight (d), known matrix M of a size (n)×(k), and public vector K of K=Ms are set. At an identifying device side, a random vector (y) and a random permutation (p) are generated, a parameter depending on (y) and/or (p) and/or (s) is diverged by using a cipher notching function H and the matrix M, information related with (y), (p), and (s) enabling to answer a problem suggested by a confirming device is exchanged without directly or indirectly clarifying the (s) to the confirming device, and the validity of the notched divergence is confirmed by using the K and/or previously transferred information. Thus, this method can be applied especially to a pay television. |