これは例で説明するのが最も分かりやすいだろう。ある人物 A が株式を保有しており、いつでも売却できるとする。A は緊急に株式を売却したいと考えており、ブローカーに電話でその旨を伝えたいと考えている。ブローカー B は電話による承認だけで売却することは望んでいない。この問題を解決するために、A は = を計算して B に渡しておく。両者は A が株式を売却したい場合には を B に開示することに合意する (この場合は、 の値と の説明を含むが、 の値を含まない書面契約 [4] として正式に作成できる)。その後、B (訳注: A の誤記?) は を提示し、 を証明できるため、B は A が株式を売却したかったことを証明できる。
A が後に株式の売却を否認した場合、B は契約書と を裁判官に示して、A の発言に反して実際に株式を売却したことの証拠とできる。 と はどちらも元の (書面による) 契約に記載されているため、裁判官は を計算し、それが に等しいことを検証することができる。 を知り得る唯一の人物は A であり、B が を知り得た唯一の方法は A が を開示した場合のみである。したがって、A は を開示したに違いない。つまり、事前の合意により A が株式を売却したいとしていたことを意味する行為である。
新しいプロトコルは大容量のストレージ要件を解消するだろう。A がメッセージへの署名直前に を B に送信すれば、B は事前に A から のコピーを取得して保管する必要がない。しかし、残念ながらそのようなプロトコルは機能しない。誰でも A であると主張し偽の を送信して、実際には何も受け取っていないにもかかわらず適切に認証された署名を受け取ったと B に思い込ませることができる。B は自分が受け取った が偽造ではなく正しいものであることを何らかの方法で確認する必要がある。
It is a great pleasure for the author to acknowledge the pleasant and informative conversations he had with Dov Andelman, Whitfield Diffie, John Gill, Martin Hellman, Raynold Kahn, Loren Kohnfelder, Leslie Lamport, and Steve Pohlig.
10. BIBLIOGRAPHY
Diffie, W., and Hellman, M. New directions in cryptography. IEEE Trans. on Inform. IT-22, 6(Nov. 1976), 644-654.
Evans A., Kantrowitz, W., and Weiss, E. A user authentication system not requiring secrecy in the computer. Comm. ACM 17, 8(Aug. 19741, 437-442.
Kohnfelder, L.M. Using certificates for key distribution in a public-key cryptosystem. Private communication.
Lipton, S.M.,a nd Matyas, S.M. Making the digital signature legal--and safeguarded. Data Communications (Feb. 1978), 41-52.
McEliece, R.J. A public-key cryptosystem based on algebraic coding theory. DSN Progress Report, JPL, (Jan. and Feb. 1978), 42-44.
Merkle, R. Secure Communications over Insecure Channels. Comm. ACM 21, 4(Apr. 1978), 294-299.
Merkle, R., and Hellman, M. trapdoor knapsacks. IEEE Trans. on Inform. IT-24, 5(Sept. 1978), 525-530. Hiding information and signatures in
Rivest, R.L., Shamir, A., and Adleman, L. A method for obtaining digital signatures and public-key cryptosystems. Comm. ACM 21, 2(Feb. 1978), 120-126.
Wilkes, M.V., Time-sharing Computer Systems. Elsevier, New York, 1972.
Lamport, L., Constructing digital signatures from a one way function. SRI Intl. CSL - 98
Shannon, C.E., Communication theory of secrecy systems. Bell Sys. Tech. Jour. 28(0ct. 1949) 656-715.
Rabin, M.O., Digitalized signatures. In Foundations of Secure Computation, R. Lipton and R. DeMillo, Eds., Academic Press, New York, 1978, pp. 165-166.
翻訳抄
公開鍵暗号に依存せず、従来の暗号化関数のみを使用して一方向関数とツリー構造を組み合わせたデジタル署名システムを提案する 1979 年の論文。現代の Merkle Tree やハッシュベース署名の基礎となる先駆的研究である。
Merkle, R.C. (1990). A Certified Digital Signature. In: Brassard, G. (eds) Advances in Cryptology — CRYPTO’ 89 Proceedings. CRYPTO 1989. Lecture Notes in Computer Science, vol 435. Springer, New York, NY. https://doi.org/10.1007/0-387-34805-0_21