IP Library Granted Patent US 9,076,000
Granted Patent B2
US 9,076,000 · App. 13/704,658 · Granted Jul 7, 2015

Authentication device, authentication method, and program

Inventors: Koichi Sakumoto (Tokyo, JP); Taizo Shirai (Kanagawa, JP); Harunaga Hiwatari (Kanagawa, JP)
Assignee: Sony Corporation
G06F21/602H04L9/3221H04L9/3271H04L9/3093H04L2209/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,076,000
App. No.
13/704,658
Granted
Jul 7, 2015
Kind
B2
Abstract

An authentication device includes circuitry that holds L (L≧2) secret keys s i (i=1 to L) and L public keys y i that satisfy y i =F(s i ) with respect to a set F of multivariate polynomials of n-th order (n≧2). The circuitry also performs with a verifier, an interactive protocol for proving knowledge of (L−1) secret keys s i that satisfy y i =F(s i ). The circuitry receives L challenges from the verifier, arbitrarily selects (L−1) challenges from the L challenges received. The circuitry also generates, by using the secret keys s i , (L−1) responses respectively for the (L−1) challenges selected, and transmits the (L−1) responses generated.

Claims (43)

1. An authentication device comprising:

circuitry configured to

set sεK n to a secret key, and setting multi-order polynomials on a ring K, f i (x 1 , . . . , x n ) (i=1 to m) and y i =f i (s) to a public key;

transmit message c to a verifier;

receive information on one verification pattern selected from k (k≧3) verification patterns by the verifier according to one piece of the message c; and

transmit response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier,

wherein the response information is calculated using information zεK n in which the secret key s is masked by rεK n , t′εK n in which the r is masked by tεK n , polynomial f i ″(x) in which multi-order polynomials f i (x+r) related to x is masked by polynomial f i ′(x).

2. An authentication device according to claim 1 ,

wherein the multi-order polynomials f i (x 1 , . . . , x n ) (i=1 to m) is a second-order polynomial, and

the f i ′(x) is a first-order polynomial.

3. An authentication device according to claim 2 ,

wherein the first-order polynomial is a first-order polynomial f i (x+t)−−f i (x)−f i (t)+e i (e i εK) related to x.

4. An authentication device comprising:

circuitry configured to

set sεK n to a secret key, and setting second-order polynomials on a ring K, f i (x 1 , . . . , x n ) (i=1 to m) and y i =f i (s) to a public key;

transmit message c to a verifier;

receive information on one verification pattern selected from k (k≧3) verification patterns by the verifier according to one piece of the message c; and

transmit response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier,

wherein the response information is calculated using information zεK n in which the secret key s is masked by rεK n , t′εK n in which the r is masked by tεK n , e i ′εK in which f i (r) substituted by the r for the second-order polynomials f i is masked by e i εK.

5. An authentication method comprising:

setting, with circuitry, sεK n to a secret key, and setting multi-order polynomials on a ring K, f i (x 1 , . . . , x n ) (i=1 to m) and y i =f i (s) to a public key;

transmitting, with the circuitry, message c to a verifier;

receiving, with the circuitry, information on one verification pattern selected from k (k≧3) verification patterns by the verifier according to one piece of the message c; and

transmitting, with the circuitry, response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier,

wherein the response information is calculated using information zεK n in which the secret key s is masked by rεK n , t′εK n in which the r is masked by tεK n , polynomial f i ″(x) in which multi-order polynomials f i (x+r) related to x is masked by polynomial f i ′(x).

6. An authentication method comprising:

setting, with circuitry, sεK n to a secret key, and setting second-order polynomials on a ring K, f i (x 1 , . . . , x n ) (i=1 to m) and y i =f i (s) to a public key;

transmitting, with the circuitry, message c to a verifier;

receiving, with the circuitry, information on one verification pattern selected from k (k≧3) verification patterns by the verifier according to one piece of the message c; and

transmitting, with the circuitry, response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier,

wherein the response information is calculated using information zεK n in which the secret key s is masked by rεK n , t′εK n in which the r is masked by tεK n , e i ′εK in which f i (r) substituted by the r for the second-order polynomials f i is masked by e i εK.

7. A non-transitory computer readable medium including computer executable instructions causing a computer to perform operations comprising:

setting SεK n to a secret key, and setting multi-order polynomials on a ring K, f i (x 1 , . . . , x n ) (i=1 to m) and y i =f i (s) to a public key;

transmitting message c to a verifier;

receiving information on one verification pattern selected from k (k≧3) verification patterns by the verifier according to one piece of the message c; and

transmitting response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier,

wherein the response information is calculated using information zεK n in which the secret key s is masked by rεK n , t′εK n in which the r is masked by tεK n , polynomial f i ″(x) in which multi-order polynomials f i (x+r) related to x is masked by polynomial f i ′(x).

8. A non-transitory computer readable medium including computer executable instructions causing a computer to perform operations comprising:

setting sεK n to a secret key, and setting second-order polynomials on a ring K, f i (x 1 , . . . , x n ) (i=1 to m) and y i =f i (s) to a public key;

transmitting message c to a verifier;

receiving information on one verification pattern selected from k (k≧3) verification patterns by the verifier according to one piece of the message c; and

transmitting response information corresponding to the information on the verification pattern received, the response information being one of k ways of response information to the verifier,

wherein the response information is calculated using information zεK n in which the secret key s is masked by rεK n , t′εK n in which the r is masked by tεK n , e i ′εK in which f i (r) substituted by the r for the second-order polynomials f i is masked by e i εK.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2012
From: SAKUMOTO, KOICHI; SHIRAI, TAIZO; HIWATARI, HARUNAGA
To: SONY CORPORATION
Reel/Frame 029479/0439 →
Priority Claims (2)
JP 2010-171940 · Jul 30, 2010 · national
JP 2010-224752 · Oct 4, 2010 · national
Continuity (1)
Related Publication 20130089201A1 · Apr 11, 2013