US2009217042A1PendingUtilityA1
Provisional signature schemes
Est. expiryAug 27, 2024(expired)· nominal 20-yr term from priority
H04L 2209/42H04L 9/3257H04L 9/3218H04L 9/3066H04L 9/3013H04L 2209/56
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and apparatus for implementing portions of a provisional signature scheme are disclosed. In one embodiment, the method comprises creating a provisional signature by performing an operation on a message and completing the provisional signature to create a final signature on the message. Such a scheme may be used for server assisted signature schemes, designated confirmer signature schemes and blind signature schemes.
Claims
exact text as granted — not AI-modified1 . A method comprising:
creating a provisional signature by performing an operation on a message, wherein creating the provisional signature comprises
creating a commitment C(M, r) to the message, where M represents the message and r is a random string,
creating a S=Sig(C(M, r)), where Sig(C(M, r)) represents the signing of the commitment C(M, r), and
outputting (M, S, E pk (r)) as the provisional signature, where E is a semantically secure public-key encryption scheme; and
completing the provisional signature to create a final signature on the message.
2 . The method defined in claim 1 further comprising confirming the provisional signature.
3 . The method defined in claim 2 wherein confirming the provisional signature comprises performing a zero-knowledge proof of knowledge of a value r such that Ver(S) equals 1 and the commitment Sig(C(M, r)) equals S, where M represents the message, r is a random string, and S represents the signing of the commitment C(M, r).
4 . The method defined in claim 1 further comprising disavowing the provisional signature.
5 . The method defined in claim 4 wherein disavowing the provisional signature comprises performing a zero-knowledge proof of knowledge of an r and an M′ such that Ver(S) equals 1, the commitment C(M′, r) equals S, D ch (E ch (r)) equals r and M′≠M
6 . A method comprising:
generating a provisional signature by
creating a commitment C(M, r) to the message, where M represents the message and r is a random string,
creating a S equal to Sig(C(M, r)), where Sig(C(M, r)) represents the signing of the commitment C(M, r), and
outputting (M, S, E pk (r)) as the provisional signature, where E is a semantically secure public-key encryption scheme; and
transmitting the provisional signature to a verifier via a network.
7 . An apparatus comprising:
a processor to generate a provisional signature by
creating a commitment C(M, r) to the message, where M represents the message and r is a random string,
creating a S equal to Sig(C(M, r)), where Sig(C(M, r)) represents the signing of the commitment C(M, r), and
outputting (M, S, Epk(r)) as the provisional signature, where E is a semantically secure public-key encryption scheme; and
a network interface coupled to the processor to transmit the provisional signature to a verifier via a network.Join the waitlist — get patent alerts
Track US2009217042A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.