US2009217041A1PendingUtilityA1
Provisional signature schemes
Est. expiryAug 27, 2024(expired)· nominal 20-yr term from priority
H04L 9/3218H04L 9/3013H04L 2209/42H04L 9/3257H04L 9/3066H04L 2209/56
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and apparatus for implementing portions of a provisional signature scheme are disclosed. In one embodiment, the method comprises creating a provisional signature by performing an operation on a message and completing the provisional signature to create a final signature on the message. Such a scheme may be used for server assisted signature schemes, designated confirmer signature schemes and blind signature schemes.
Claims
exact text as granted — not AI-modified1 . A method comprising:
creating a provisional signature by performing an operation on a message, wherein creating a provisional signature by performing an operation on a message comprises
selecting a random value r,
computing a value X equal to the commitment C(M, r), where M is the message,
sending the value X to the signer,
performing a zero-knowledge proof of knowledge of the random value r and the message M such that value X equals to the commitment C(M,r),
signing the value X and returning Sig(x) only if the proof succeeds, and
outputting the provisional signature on M as Sig(X)=Sig(C(M, r)); and
completing the provisional signature to create a final signature on the message.
2 . The method defined in claim 1 wherein completing the provisional signature to create a final signature on the message comprises:
generating a second random value r′; and outputting the final signature on the message M as (C(Sig(C(M, r)), r′)).
3 . A method comprising:
generating a provisional signature by
selecting a random value r,
computing a value X equal to the commitment C(M, r), where M is the message,
sending the value X to the signer,
performing a zero-knowledge proof of knowledge of the random value r and the message M such that value X equals to the commitment C(M,r),
signing the value X and returning Sig(x) only if the proof succeeds, and
outputting the provisional signature on M as Sig(X)=Sig(C(M, r)); and
transmitting the provisional signature to a verifier via a network.
4 . An apparatus comprising:
a processor to generate a provisional signature by
selecting a random value r,
computing a value X equal to the commitment C(M, r), where M is the message,
sending the value X to the signer,
performing a zero-knowledge proof of knowledge of the random value r and the message M such that value X equals to the commitment C(M,r),
signing the value X and returning Sig(x) only if the proof succeeds, and
outputting the provisional signature on M as Sig(X)=Sig(C(M, r)); and
a network interface coupled to the processor to transmit the provisional signature to a verifier via a network.
5 . A method comprising:
receiving a provisional signature; converting a provisional signature into a final signature by
generating a second random value r′, and
outputting the final signature on the message M as (C(Sig(C(M, r)), r′)); and
sending the final signature to a network location.
6 . An apparatus comprising:
a network interface to receive a provisional signature; and a processor to convert the provisional signature into a final signature by
generating a second random value r′, and
outputting the final signature on the message M as (C(Sig(C(M, r)), r′)), wherein the network interface sends the final signature to a network location.Join the waitlist — get patent alerts
Track US2009217041A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.