摘要 |
An anonymous information system is capable of maintaining anonymity of data while improving safety with regard to loss of anonymity caused by hacking of secret information, or the like. Conversion processing for converting from individual specifying information to anonymous individual information is split between an information providing device and an anonymity server device. Further, the manner in which the conversion processing is split is varied for each information providing device. A parameter generating device calculates X<SUB>inv </SUB>to satisfy X<SUB>i</SUB>xX<SUB>inv</SUB>=1 mod q, a first characteristic parameter KA<SUB>i</SUB>=GˆX<SUB>inv </SUB>mod q, and a second characteristic parameter KB<SUB>i</SUB>=X<SUB>i</SUB>. The information providing device generates a semi-anonymous individual identifier C=(KA<SUB>i</SUB>)ˆD mod P. The anonymity server device calculates an anonymous individual identifier E=(C)ˆKB<SUB>i </SUB>mod P.
|