摘要 |
<p>In a group signature system of the present invention, user device 400 registered in the group, when receiving an issuing device public key of a set that includes order N of a cyclic group and its elements a_0, a_1 and a_2, determines such primes e and e' that e' is a prime that is obtained by subtracting a fixed number smaller than the prime e from the prime e, generates a user device secret key of a set including such numbers x and r that the product between a_0 and the result obtained by performing modular exponentiation of a_1 by number x, multiplied by the result obtained by performing modular exponentiation of a_2 by number r is equal to the result obtained by performing element A of the first cyclic group raised to the e-th power, based on order N as a modulus, and a user device public key of a set including prime e, prime e' and element A, transmits prime e' to revocation manager 300, receives B calculated based on prime e' from revocation manager 300 to obtain a message, generates a signature statement for the message using the B value, the user device public key, the user device secret key and the message, and transmits the signature statement with the message and to verifying device 500.</p> |