PROBLEM TO BE SOLVED: To provide a verification-enabled encryption technique that is based on a standard cryptological hypothesis and in which the size of a verification key is independent of the size of a security parameter.;SOLUTION: While using a cryptological hypothesis rendering a standard security and increasing the number of elements of a signature key, the number of elements of a verification key is greatly reduced. In encrypting a signature on the basis of a signature technique with which a signature key consists of plural group elements, not only the element of the signature having relationship with the signature key, but also the random-number element of a signature directly having no relationship with the signature key are encrypted with an arbitrator public key, and thereby the verification key is greatly reduced.;COPYRIGHT: (C)2013,JPO&INPIT
展开▼