摘要:
The method of delegating according to the invention a calculation of a value e(A,B) of bilinear coupling between two values A and B by an entity to a calculation server comprises: - the selection (E10) by the entity of public elements P1 and P2 and of secret elements S1 and S2, two elements out of P1, P2, S1 and S2 being taken equal to A and B; — the generation (E20) by the entity of elements R1 =vS1, R2=uS2, T1 =uP1+S1, T2=vP2+S2, where u and v are random; - the transmission (E30) by the entity of R1, R2, T1 and T2 to the calculation server; - the calculation (E40) by the server of: (a1) y = e(T1, T2)[e(R1, P2)e(P1, R2)]-1 (a2) z = e(D1, D2), y and z designating two integers equal to 1 or to an integer c, D1 and D2 designating two public elements out of A and B or R1 and R2; - the transmission (E50) by the server of a1 and a2 to the entity; - the obtaining (E60) of the value e(A,B) by the entity on the basis of a1 or a2.
摘要:
The invention relates to a method of anonymous access to a service, comprising the allocation (100), by at least one certifying entity (C j ), of a plurality of certificates (σι,σΝ·) to a user entity (U), the certificates being calculated on the basis of at least one attribute (m k ) associated with the user entity, the calculation (200), by the user entity (U), an aggregated certificate (aa) on the basis of a plurality of certificates (σ 1 ,σ Ν ) among the certificates allocated to the user entity (U), the calculation (300), by the user entity (U), of a proof of knowledge (ΡοΚσ) of the aggregated certificate (aa) and a verification (400), performed by a verifying entity (V), of at least one of these certificates by means of said proof of knowledge (ΡοΚ σ ), the access to the service being provided by the verifying entity to the user entity as a function of the result of this verification. The invention furthermore relates to a corresponding computer program, the user entity (U), verifying entity (V) and certificating entity (Q) corresponding as well as to a system of anonymous accreditation (SAA) for anonymous access to a service comprising these various entities.
摘要:
The method comprises, for each inclusion of an element in a target folder of a file tree of a first user, stored on a storage server, which the first user has authorized a second user to access by providing a re-enciphering key for the target folder of the first to the second user: — the generation of a re-enciphering key for the first user of the element to a folder of a hierarchical level directly above in the tree containing element, by using a secret identifier of the element, a secret identifier of the folder of the level directly above, and private and public keys of the first user; — if the element is a file, the enciphering of the element with a public key of the first user and the secret identifier of the element; and — the updating of the tree comprising the provision to the server of the re-enciphering key generated for the first user, and as appropriate of the cipher of the element.