摘要 |
PROBLEM TO BE SOLVED: To allow a signer to entrust a third party with signature generation processing while restricting a signature target. SOLUTION: A signer device selects an arbitrary value t, calculates h=H(m, t)εG2 with respect to a message m, calculates w=h<SP>sk</SP>εG2 by using a secret key sk, and transmits m, t, w, and rk(=g1<SP>sk</SP>εG1) to a proxy signature device 20. The proxy signature device 20 receives them, calculates f=e(g1, h)εG3, selects an arbitrary value r, calculates a=(g3)<SP>r</SP>εG3 and b=f<SP>r</SP>εG3, calculates c=H'(m, t, w, a, b), and calculates z=(g1)<SP>r</SP>/(rk)<SP>c</SP>εG1. The proxy signature device transmits the message m and a signatureσ=(t, w, c, z). In addition,εis used as a mathematical character meaning a set. COPYRIGHT: (C)2008,JPO&INPIT
|