A signature scheme is provided in which a message is divided in to a first portion which is hidden and is recovered during verification, and a second portion which is visible and is required as input to the verification algorithm. A first signature component is generated by encrypting the first portion alone. An intermediate component is formed by combining the first component and the visible portion and cryptographically hashing them. A second signature component is then formed using the intermediate component and the signature comprises the first and second components with the visible portion. A verification of the signature combines a first component derived only from the hidden portion of the message with the visible portion and produces a hash of the combination. The computed hash is used together with publicly available information to generate a bit string corresponding to the hidden portion. If the required redundancy is present the signature is accepted and the message reconstructed from the recovered bit string and the visible portion. <IMAGE>
申请公布号
DE60035317(D1)
申请公布日期
2007.08.09
申请号
DE2000635317
申请日期
2000.09.07
申请人
PITNEY BOWES INC.;CERTICOM CORP.
发明人
PINTSOV, LEON;RYAN, RICK;SINGER, ARI;VANSTONE, SCOTT ALEXANDER;GALLANT, ROBERT;LAMBERT, ROBERT J.