摘要 |
PROBLEM TO BE SOLVED: To provide a signature method, wherein signature length is short and calculation amount of signature generation and signature verification is smaller. SOLUTION: In a signature and verification system, a bilinear map composed of different groups (G<SB>1</SB>, G<SB>2</SB>) is used to assume that mapping from a group G<SB>1</SB>to a group G<SB>2</SB>is difficult and, by using the property where the exponent part of different generators is hard to determine, a message on two different groups is output as a signature. A signature device includes at least a signature recording section, a commitment group element selection section, a commitment random number generation section, a commitment calculation section, a key random number generation section, a key calculation section, a key group element selection section, a key randomizing section, a key generation section, a message acquisition section, a signature random number generation section, a signature calculation section, and a signature output section. A verification device includes a verification input section, a verification confirmation section, and a verification output section. COPYRIGHT: (C)2011,JPO&INPIT |