摘要 |
<p>In one embodiment, it is proposed a signing method delivering a partial signature associated with a message, said partial signature being used in a threshold signing method, the signing method being executed on an electronic device. The signing method is remarkable in that it comprises: - obtaining a partial secret key SK i being obtained from an output of a secret sharing scheme, said partial secret key SK i being equal to {u1 (i), uK+1 (i)}, where elements uj (i) ∈ Zp for all j ∈ {1,..., K + 1}, with p being a prime number, and K being an integer greater or equal to one; - determining from said partial key, K elements tj = g -uj(i) , with j ∈ {1,...,K + 1} and g being a generator of a group G, said group G being part of a bilinear group (G, Ĝ, G T ) with Ĝ being a group and G T being a target group; - determining from said message a vector so as to define a Groth-Sahai common reference string; - determining Groth-Sahai commitments on said K + 1 elements t j with j ∈ {1,...,Κ + 1} from said Groth-Sahai common reference string, said Groth-Sahai commitments belonging to said group G; and - determining a non-interactive witness indistinguishable proof comprising K(K + 1) elements, all the K(K + 1) elements belonging to said group Ĝ, said proof guarantying that said K + 1 elements tj verify K pairing equations; - delivering said partial signature associated with said message, said partial signature comprising said Groth-Sahai commitments, and said non-interactive witness indistinguishable proof.</p> |