PROBLEM TO BE SOLVED: To provide a partial blind signature scheme which enables a signer and a signature requesting person to check that the necessary information is correctly included in documents to be signed.;SOLUTION: The documents to be signed are divided to public common documents D and private documents m and random public keys y1 are formed in accordance with D on a signer 10 side. The blind signature for m is issued in accordance with the zero knowledge certification protocol to certify that the secret key corresponding to at least one of the originally held public keys y0 is held. This zero knowledge certification is executed by spuriously making certification to the secret key corresponding to y1 while actually performing the certification to the secret key corresponding to Y0. Unless the signature requesting person 20 can forge the secret key corresponding to y1 or y0, the formed signature is certified to be based on D and m. On the signature requesting person 20 and signature certifying person 300 sides, y1 is formed by the procedure similar to that for the signer 10 and the signature is certified by using both of y0 and y1.;COPYRIGHT: (C)2001,JPO
展开▼