Disclosed are an anonymous ID-based signature system and method using homomorphic encryption. According to an embodiment of the present invention, the method comprises: a step of allowing an authentication requestor terminal to generate a first homomorphic cryptogram (c=HE(id)) corresponding to an ID of the authentication requester terminal by using a symmetric homomorphic password secret key (hsk) of the authentication requestor terminal; a step of allowing an authentication authority server to generate a second homomorphic cryptogram (c=HE(sk_id)) for the secret key corresponding to the ID by using the first homomorphic cryptogram (C) received from the authentication requestor terminal; and a step of allowing the authentication requestor terminal to receive the second homomorphic cryptogram (C) and obtain the secret key (sk_id) from the received second homomorphic cryptogram (C). According to the present invention, ID-based signatures can be further secured.
展开▼