摘要 |
<P>PROBLEM TO BE SOLVED: To make it possible to perform a deniable zero-knowledge interactive proof requiring a small amount of both communication and calculation by utilizing a method for a special honest verifier zero-knowledge interactive proof when the method is given. <P>SOLUTION: A second relation proof generation device 417, to which common input and a third random tape are input, outputs a proof of non-interactive knowledge related to a second relation to a second relation proof verification device 423. The second relation proof verification device 423 determines whether or not a prescribed relational expression is established by using the proof of non-interactive knowledge related to the second relation. A proof generation device 425; to which the common input, evidence, a first random tape, and a second random tape are input; generates a proof of non-interactive knowledge of either evidence of evidence meeting a first relation and evidence meeting the second relation. A proof verification device 434 outputs a signal showing acceptance or nonacceptance of the proof as a verification result. <P>COPYRIGHT: (C)2012,JPO&INPIT |