1. A method comprising:
receiving, at a computing device, inputs indicative of a user state of each user of a group of users, the received inputs comprising:
sensor inputs from one or more sensors in communication with the computing device; andor
user inputs received from the users through a graphical user interface;
determining, using the computing device, a collective user state for each user of the group of users based on the received inputs;
determining, using the computing device, possible activities for the group of users to collectively partake in together based on the collective user states of the group of users;
executing, at the computing device, one or more behaviors that evaluate the possible activities, each behavior having an objective, for each behavior:
determining whether any input of the received inputs is of an input type associated with the behavior;
when an input of the received inputs is of an input type associated with the behavior, incrementing an influence value with the behavior; and
decrementing the influence value of the behavior after a threshold period of time,
wherein when the influence value of the behavior satisfies an influence value criteria, the behavior participates in evaluating the possible activities, and when the influence value of the behavior does not satisfy the influence value criteria, the behavior does not participate in evaluating the possible activities;
selecting, using the computing device, one or more activities based on the evaluations of the possible activities; and
sending results including the selected one or more activities from the computing device.
2. The method of claim 1, wherein the received inputs comprise biometric data of at least one user and environmental data regarding a surrounding of the at least one user.
3. The method of claim 1, wherein the one or more sensors comprise at least one of a global positioning system, a temperature sensor, a camera, a three dimensional volumetric point cloud imaging sensor, a fingerprint reader, a blood glucose monitor, a skin PH meter, an inertial measurement unit, a microphone, a blood oxygen meter, a humidistat, or a barometer.
4. The method of claim 1, further comprising querying one or more remote data sources in communication with the computing device to identify the possible activities.
5. The method of claim 1, further comprising determining, using the computing device, the possible activities based on one or more preferences of the group of users.
6. The method of claim 1, wherein each behavior evaluates a possible activity positively when the possible activity at least partially achieves the objective of the behavior.
7. The method of claim 6, wherein each behavior evaluates a possible activity positively when the possible activity at least partially achieves one or more preferences of the group of users.
8. The method of claim 1, wherein a first behavior evaluates a possible activity based on an evaluation by a second behavior of the possible activity.
9. The method of claim 1, wherein each behavior elects to participate or not participate in evaluating the possible activities based on the collective user state of at least one user of the group of users.
10. The method of claim 1, wherein the evaluations of each behavior are weighted based on the influence value of the behavior.
11. A method comprising:
receiving, at a computing device, inputs indicative of a user state of each user of a group of users, the received inputs comprising:
sensor inputs from one or more sensors in communication with the computing device; andor
user inputs received from the users through a graphical user interface displayed on one or more screens in communication with the computing device;
determining, using the computing device, a collective user state for each user of the group of users based on the received inputs;
determining, using the computing device, one or more possible activities for the group of users to collectively partake in together and one or more predicted outcomes for each possible activity based on the collective user states of the group of users;
executing, at the computing device, one or more behaviors that evaluate the one or more possible activities andor the corresponding one or more predicted outcomes, each behavior modeling a human behavior andor a goal oriented task, for each behavior:
determining whether any input of the received inputs is associated with the behavior;
when an input of the received inputs is associated with the behavior, incrementing an influence value associated with the behavior, the input being associated with the behavior when the input is of an input type associated with the behavior; and
decrementing the influence value of the behavior after a threshold period of time;
wherein when the influence value of the behavior satisfies an influence value criteria, the behavior participates in evaluating the one or more possible activities andor the corresponding one or more predicted outcomes; and
wherein when the influence value of the behavior does not satisfy the influence value criteria, the behavior does not participate in evaluating the one or more possible activities andor the corresponding one or more predicted outcomes;
selecting, using the computing device, one or more activities based on the evaluations of the one or more possible activities andor the corresponding one or more predicted outcomes; and
sending results including the selected one or more activities from the computing device to the one or more screens for display on the one or more screens.
12. The method of claim 1, further comprising selecting for the results a threshold number of possible activities having the highest evaluations.
13. The method of claim 1, further comprising determining, using the computing device, one or more predicted outcomes for each possible activity based on the collective user states of the group of users, the one or more behaviors evaluating the one or more predicted outcomes of each possible activity.
14. The method of claim 1, further comprising:
selecting multiple possible activities;
combining the selected possible activities; and
sending a combined activity in the results.
15. The method of claim 1, wherein the computing device comprises:
a user computer processor of a user device including a screen; andor
one or more remote computer processors in communication with the user computer processor.
16. A system comprising:
one or more computing devices; and
non-transitory memory in communication with the one or more computing devices, the non-transitory memory storing instructions that, when executed by the one or more computing devices, cause the one or more computing devices to perform operations comprising:
receiving inputs indicative of a user state of each user of a group of users, the received inputs comprising:
sensor inputs from one or more sensors in communication with the computing device; andor
user inputs received from the users through a graphical user interface;
determining a collective user state for each user of the group of users based on the received inputs;
determining possible activities for the group of users to collectively partake in together based on the collective user states of the group of users;
executing one or more behaviors that evaluate the possible activities, each behavior having an objective, for each behavior:
determining whether any input of the received inputs is of an input type associated with the behavior;
when an input of the received inputs is of an input type associated with the behavior, incrementing an influence value with the behavior; and
decrementing the influence value of the behavior after a threshold period of time,
wherein when the influence value of the behavior satisfies an influence value criteria, the behavior participates in evaluating the possible activities, and when the influence value of the behavior does not satisfy the influence value criteria, the behavior does not participate in evaluating the possible activities;
selecting one or more activities based on the evaluations of the possible activities; and
sending results including the selected one or more activities from the computing device.
17. The system of claim 16, wherein the inputs comprise biometric data of at least one user and environmental data regarding a surrounding of the at least one user.
18. The system of claim 16, wherein the one or more sensors comprise at least one of a global positioning system, a temperature sensor, a camera, a three dimensional volumetric point cloud imaging sensor, a fingerprint reader, a blood glucose monitor, a skin PH meter, an inertial measurement unit, a microphone, a blood oxygen meter, a humidistat, or a barometer.
19. The system of claim 16, wherein the operations further comprise querying one or more remote data sources in communication with the one or more computing devices to identify the possible activities.
20. The system of claim 16, wherein the operations further comprise determining the possible activities based on one or more preferences of the group of users.
21. The system of claim 16, wherein each behavior evaluates a possible activity positively when the possible activity at least partially achieves the objective of the behavior.
22. The system of claim 21, wherein each behavior evaluates a possible activity positively when the possible activity at least partially achieves one or more preferences of the group of users.
23. The system of claim 16, wherein a first behavior evaluates a possible activity based on an evaluation by a second behavior of the possible activity.
24. The system of claim 16, wherein each behavior elects to participate or not participate in evaluating the possible activities based on the collective user state of at least one user of the group of users.
25. The system of claim 16, wherein the evaluations of each behavior are weighted based on the influence value of the behavior.
26. A system comprising:
one or more computing devices; and
non-transitory memory in communication with the one or more computing devices, the non-transitory memory storing instructions that, when executed by the one or more computing devices, cause the one or more computing devices to perform operations comprising:
receiving inputs indicative of a user state of each user of a group of users, the received inputs comprising:
sensor inputs from one or more sensors in communication with the one or more computing devices; andor
user inputs received from the users through a graphical user interface displayed on one or more screens in communication with the one or more computing devices;
determining a collective user state for each user of the group of users based on the received inputs;
determining one or more possible activities for the group of users to collectively partake in together and one or more predicted outcomes for each possible activity based on the collective user states of the group of users;
executing one or more behaviors that evaluate the one or more possible activities andor the corresponding one or more predicted outcomes, each behavior modeling a human behavior andor a goal oriented task, for each behavior:
determining whether any input of the received inputs is associated with the behavior;
when an input of the received inputs is associated with the behavior, incrementing an influence value associated with the behavior, the input being associated with the behavior when the input is of an input type associated with the behavior; and
decrementing the influence value of the behavior after a threshold period of time;
wherein when the influence value of the behavior satisfies an influence value criteria, the behavior participates in evaluating the one or more possible activities andor the corresponding one or more predicted outcomes; and
wherein when the influence value of the behavior does not satisfy the influence value criteria, the behavior does not participate in evaluating the one or more possible activities andor the corresponding one or more predicted outcomes;
selecting one or more activities based on the evaluations of the one or more possible activities andor the corresponding one or more predicted outcomes; and
sending results including the selected one or more activities to the one or more screens for display on the one or more screens.
27. The system of claim 16, wherein the operations further comprise selecting for the results a threshold number of possible activities having the highest evaluations.
28. The system of claim 16, wherein the operations further comprise determining, using the computing device, one or more predicted outcomes for each possible activity based on the collective user states of the group of users, the one or more behaviors evaluating the one or more predicted outcomes of each possible activity.
29. The system of claim 16, wherein the operations further comprise:
selecting multiple possible activities;
combining the selected possible activities; and
sending a combined activity in the results.
30. The system of claim 16, wherein the one or more computing devices comprise:
a user computer processor of a user device including a screen; andor
one or more remote computer processors in communication with the user computer processor.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
What is claimed is:
1. A method for implementing electronic cash in an electronic cash system which comprises issuer equipment as an institution for issuing electronic cash, user equipment as a user which receives electronic cash issued from said issuer equipment, and shop equipment as an institution which receives a payment by electronic cash, and wherein:
(a) said issuer equipment: having an electronic cash balance counter for each user; issues electronic cash in response to a request from said user equipment; increments said balance counter by the amount of electronic cash issued; and, upon receiving electronic cash returned thereto, decrements said balance counter by the amount of electronic cash returned based on a user signature; and
(b) said user equipment having a balance counter; upon receiving electronic cash issued from said issuer equipment, increments said balance counter by the amount of electronic cash issued; makes a payment to said shop equipment by electronic cash attached with a user signature; and decrements said balance counter by the amount of electronic cash paid.
2. The method of claim 1, wherein said shop equipment verifies the validity of said user signature attached to electronic cash received from said user equipment and, if valid, receives said payment by electronic cash, then stores at least said user signature as history information, and returns said user signature to said issuer equipment for conversion.
3. The method of claim 1 or 2, wherein said electronic cash system further comprises trustee equipment as an institution for registering therewith said user, and said method comprises:
user registration procedure wherein:
said user equipment generates, as a pseudonym, a public key for verifying its own signature, and registers it with said trustee equipment; and
said trustee equipment generates its signature for said user pseudonym as a license, and sends it to said user equipment;
electronic cash issuing procedure wherein:
said user equipment sends its requested amount of issue and said pseudonym to said issuer equipment;
said issuer equipment responds to said request from said user equipment to generate an issuer signature for said requested amount of issue and said pseudonym, and sends said issuer signature as electronic cash to said user equipment;
said user equipment verifies the validity of said issuer signature received as electronic cash, and if valid, increments said balance counter by the amount of electronic cash received; and
electronic cash payment procedure wherein:
said user equipment generates said user signature for the amount due, and sends said license, said pseudonym and said user signature to said shop equipment.
4. The method of claim 2, wherein said shop equipment verifies the validity of said license received from said user, and if valid, receives the payment by electronic cash; and stores said license as part of said history information; and
said issuer equipment verifies the validity of said history information, and if valid, decrements said electronic cash balance counter corresponding to said pseudonym by the amount paid, and stores the associated history information.
5. The method of claim 3, wherein said shop equipment verifies the validity of said license received from said user, and if valid, receives the payment by electronic cash; and stores said license as part of said history information; and
said issuer equipment verifies the validity of said history information, and if valid, decrements said electronic cash balance counter corresponding to said pseudonym by the amount paid, and stores the associated history information.
6. The method of claim 1 or 2, wherein said electronic cash system further comprises bank equipment as an institution for managing an account of each user and for issuing a coupon, and trustee equipment as an institution for registering therewith each user, and said method comprises:
user registration procedure wherein:
said user equipment generates a public key for verifying its own signature as a pseudonym, and registers it with said trustee equipment; and
said trustee equipment generates its signature for said user public key as a license, and sends it to said user equipment;
electronic cash issuing procedure wherein:
said bank equipment issues a coupon in exchange for the reduction of the balance in an account of said user in response to a request from said user equipment, and sends thereto said coupon;
said user equipment sends said coupon and said pseudonym to said issuer equipment;
said issuer equipment generates an issuer signature for said pseudonym and the amount of issue, as electronic cash corresponding to said coupon, then increments said electronic cash balance counter corresponding to said user pseudonym, and sends said issuer signature to said user equipment; and
said user equipment verifies the validity of said issuer signature sent thereto from said issuer equipment, and if valid, increments said balance counter by the amount received; and
electronic cash payment procedure wherein:
said user equipment generates said user signature for the amount due, and sends said license, said pseudonym and said user signature to said shop equipment.
7. The method of claim 5, wherein said shop equipment verifies the validity of said license sent thereto from said user equipment, and if valid, receives it as electronic cash, and stores it as part of said history information, and said method comprises:
electronic cash depositing procedure wherein:
said shop equipment sends a real name of said shop and said history information to said bank equipment; and
said bank equipment verifies the validity of said license and said user signature, and if valid, increases the balance in an account of said shop by the amount paid; and
electronic cash return procedure wherein:
said bank equipment sends said history information to said issuer equipment; and
said issuer equipment verifies the validity of said history information, and if valid, decrements said electronic cash balance counter corresponding to said pseudonym of said user by the amount paid, and stores said history information.
8. The method of claim 1 or 2, wherein said electronic cash system further comprises a bank equipment as an institution for managing an account of each user, and said method comprises:
user registration procedure wherein:
said user equipment generates a common key, then encrypts a signature verifying public key, which is a pseudonym of said user and said common key with an issuer public key, and sends said encrypted pseudonym to said bank equipment together with user identification information IdU;
said bank equipment stores said user identification information IdU and said encrypted pseudonym, and sends said encrypted pseudonym to said issuer equipment;
said issuer equipment decrypts said encrypted data from said bank equipment with an issuer secret key to extracts said pseudonym and said common key of said user, then stores said pseudonym and said encrypted pseudonym, then generates an issuer signature for said pseudonym as a license, then encrypts said license with said common key, and sends said encrypted license to said bank equipment;
said bank sends said encrypted license from said issuer equipment to said user equipment; and
said bank equipment transmits information received from said issuer equipment to said user equipment;
said user equipment decrypts said encrypted license with said common key to extract said license, and stores it;
electronic cash issuing procedure wherein:
said user equipment encrypts its pseudonym and a common key with an issuer public key, and sends encrypted information to said bank equipment together with user identification information IdU and its requested amount of withdrawal;
said bank equipment reduces the balance in an account of said user in response to said request from said user equipment, and in exchange therefor, sends to said issuer equipment said requested amount of withdrawal and said encrypted user pseudonym and common key received from said user equipment;
said issuer equipment decrypts said received information with an issuer secret key to extract said user pseudonym and said common key, then generates as electronic cash an issuer signature for said user pseudonym and said requested amount of withdrawal, then encrypts said electronic cash with said common key, then increments said electronic cash balance counter corresponding to said user pseudonym by the amount withdrawn, and sends said encrypted electronic cash to said bank equipment;
said bank equipment sends said encrypted electronic cash to said user equipment; and
said user equipment decrypts said encrypted electronic cash with said common key, verifies the validity of said issuer signature attached to said electronic cash, and if valid, increments said balance counter by the amount received from said bank equipment; and
payment procedure wherein:
said user equipment decrements said balance counter by the amount due, generates a user signature therefor, and sends said user signature to said shop equipment together with said license and said user pseudonym.
9. The method of claim 8, wherein said shop equipment verifies the validity of said license received from said user equipment, and if valid, receives it as electronic cash, and stores said license as part of said history information; and said method comprises:
electronic cash depositing procedure wherein:
said shop equipment sends said history information to said bank equipment; and
said bank equipment verifies the validity of said license and said user signature, and if valid, increases the balance in an account of said shop by the amount received; and
electronic cash return procedure wherein:
said bank equipment sends said history information to said issuer equipment; and
said issuer equipment verifies the validity of said history information, and if valid, decrements said balance counter corresponding to said user pseudonym by the amount paid, and stores said history information.
10. The method of claim 1 or 2, wherein said electronic cash system further comprises a bank equipment as an institution for managing an account of each user, and said method comprises:
user registration procedure wherein:
said user equipment generates a common key, then encrypts a signature verifying public key and said common key as a pseudonym of said user with an issuer public key, and sends said encrypted pseudonym to said bank equipment together with user identification information IdU;
said bank equipment stores said user identification information IdU and said encrypted pseudonym, and sends said encrypted pseudonym to said issuer equipment;
said issuer equipment decrypts said encrypted data from said bank equipment with an issuer secret key to extracts said pseudonym and said common key, then adds an identifier for said common key as common key information KID, then stores said pseudonym and said encrypted pseudonym, and at the same time, stores said common key information KID and said common key in correspondence with each other, then generates an issuer signature for said pseudonym as a license, then encrypts said license and said common key information KID with said common key to obtain an encrypted license, and sends said encrypted license to said bank equipment; and
said bank equipment sends said encrypted information received from said issuer equipment to said user equipment; and
said user equipment decrypts said encrypted license with said common key to extract said license and said common key information KID, and stores them;
electronic cash issuing procedure wherein:
said user equipment encrypts its pseudonym and its requested amount of withdrawal with said common key to obtain an encrypted pseudonym, and sends said common key information KID and said encrypted pseudonym to said bank equipment together with user identification information IdU and said requested amount;
said bank equipment reduces the balance in an account of said user in response to said request from said user equipment, and sends to said issuer equipment said requested amount, said encrypted pseudonym and said common key information KID received from said user equipment;
said issuer equipment retrieves said common key corresponding to said common key information KID received from said bank equipment, decrypts said received encrypted pseudonym with said common key to extract said user pseudonym, then generates as electronic cash an issuer signature for said user pseudonym and said requested amount, then encrypts said electronic cash with said common key, then increments said electronic cash balance counter corresponding to said user pseudonym by the amount of said encrypted electronic cash, and sends said encrypted electronic cash to said bank equipment;
said bank equipment sends said encrypted electronic cash to said user equipment; and
said user equipment decrypts said encrypted electronic cash with said common key, verifies the validity of said issuer signature of said electronic cash, and if valid, increments said balance counter by the amount of said electronic cash received from said bank equipment; and
electronic cash payment procedure wherein:
said user equipment decrements said balance counter by the amount due, generates a user signature therefor, and sends said user signature to said shop equipment together with said license and said user pseudonym.
11. The method of claim 8, wherein:
in said user registration procedure:
said bank equipment generates, as a pseudonymous bank signature, a bank signature for an encrypted pseudonym, and sends said pseudonymous bank signature to said issuer equipment;
said issuer equipment verifies the validity of said pseudonymous bank signature received from said bank equipment, and if valid, generates said issuer signature for said encrypted license, and sends to said bank equipment said issuer signature for said encrypted license; and
said bank equipment verifies the validity of said issuer signature for said encrypted license; and
in said electronic cash issuing procedure:
said bank equipment generates a bank signature for said encrypted pseudonym and said requested amount of withdrawal, and sends said bank signature to said issuer equipment;
said issuer equipment verifies the validity of said bank signature, and if valid, generates an issuer signature for said encrypted electronic cash, and sends to said bank equipment said issuer signature for said encrypted electronic cash; and
said bank equipment verifies the validity of said issuer signature.
12. The method of claim 10, wherein:
in said user registration procedure:
said bank equipment generates, as a pseudonymous bank signature, a bank signature for an encrypted pseudonym, and sends said pseudonymous bank signature to said issuer equipment;
said issuer equipment verifies the validity of said pseudonymous bank signature received from said bank equipment, and if valid, generates said issuer signature for said encrypted license, and sends to said bank equipment said issuer signature for said encrypted license; and
said bank equipment verifies the validity of said issuer signature for said encrypted license; and
in said electronic cash issuing procedure:
said bank equipment generates a bank signature for said encrypted pseudonym and said requested amount of withdrawal, and sends said bank signature to said issuer equipment;
said issuer equipment verifies the validity of said bank signature, and if valid, generates an issuer signature for said encrypted electronic cash, and sends to said bank equipment said issuer signature for said encrypted electronic cash; and
said bank equipment verifies the validity of said issuer signature.
13. The method of claim 10, wherein:
in said user registration procedure:
said user equipment generates, as n pseudonyms, n signature verifying public keys including said signature verifying public key, said n being an integer equal to or greater than 2, then generates n signature generating secret keys corresponding to said n signature verifying public keys and including said signature generating secret key, then encrypts said n pseudonyms and said common key with said issuer public key, and sends them as said encrypted pseudonym to said bank equipment together with said user identification information IdU;
said issuer equipment decrypts data received from said bank equipment with an issuer secret key to extract said n pseudonyms and said common key, then stores said n pseudonyms and said encrypted pseudonym in correspondence with each other, then attaches an issuer signature to each of said n pseudonyms to generate n licenses including said license, then encrypts said n licenses and said common key information KID with said common key to obtain encrypted information, and sends said encrypted information as said encrypted license to said bank equipment; and
said user equipment decrypts said encrypted license with said common key to extract said n licenses and said common key information KID, and stores them;
in said electronic cash issuing procedure:
said user equipment encrypts an arbitrarily selected one of said n pseudonyms and its requested amount of withdrawal with said common key to generate said encrypted pseudonym, and sends said encrypted pseudonym to said bank equipment together with said user identification information IdU, said requested and said common key information KID;
said issuer equipment decrypts said encrypted pseudonym with said common key to extract said selected pseudonym, then attaches said issuer signature to a set of said extracted pseudonym and said requested amount to generate said electronic cash, then encrypts said electronic cash with a common key into said encrypted electronic cash, then increments by said requested amount an electronic cash balance counter corresponding to a set of said n pseudonyms including said selected pseudonym, and sends said encrypted electronic cash to said bank equipment; and
said user equipment decrypts said encrypted electronic cash to obtain said electronic cash, then verifies the validity said issuer signature attached to said electronic cash, and if valid, increments said balance counter in said user equipment by said requested amount; and
in said electronic cash payment procedure:
said user equipment selects any one of said n signature verifying secret keys, then sends to said shop equipment that one of said n licenses corresponding to said selected signature generating secret key and that one of said pseudonyms corresponding to said selected signature generating secret key, then decrements said balance counter by the amount due, then generates a user signature for said amount due with said selected signature generating secret key, and sends said user signature to said shop equipment.
14. In an electronic cash system which comprises issuer equipment as an institution for issuing electronic cash, user equipment as a user for receiving said electronic cash issued from said issuer equipment and shop equipment as an institution for receiving payment by said electronic cash, said user equipment comprising:
key generating means for generating a user secret key SKU and a public key PKU as a pseudonym corresponding to said user secret key;
input means for inputting the amount of withdrawal x and the amount due y;
storage means for storing user identification information IdU, said secret key SKU, said public key PKU and a license for the use of electronic cash;
balance counter means set in said storage means;
signature generating means for attaching a user signature to challenge information, as information received from said shop in association with payment by electronic cash, and said amount due y with said secret key SKU;
balance updating means for decrementing said balance counter by said amount due y at the time of generating said user signature;
sending means for sending information to the other institutions;
receiving means for receiving various pieces of information from said other institutions; and
control means for controlling each of said means to execute its process.
15. The user equipment of claim 14, wherein: said electronic cash system further comprises trustee equipment having a public key PKR and a secret key SKR; said issuer equipment manages an account of said user; and said storage means has stored therein said public key PKR of said trustee; said user equipment further comprising:
signature verifying means for verifying, with said public key PKR, the validity of a trustee signature SKR(PKU) attached to said pseudonym PKU received from said trustee equipment and for storing said trustee signature as said license in said storage means if said trustee signature is valid.
16. The user equipment of claim 14, wherein: said electronic system further comprises trustee equipment having a public key PKR and a signature generating secret key SKR, and bank equipment for managing an account of said user; and said storage means has stored therein said public key PKR; said user equipment further comprising:
signature verifying means for verifying, with said public key PKR, the validity of a trustee signature SKR(PKU) attached to said pseudonym PKU received from said trustee equipment and for storing said trustee signature as said license in said storage means if said trustee signature is valid;
wherein said signature verifying means includes means for verifying a bank signature SKBx(PKU) with a secret key SKBx corresponding to said amount of withdrawal x, sent from said bank equipment in response to a user’s request thereto for withdrawal, and for storing said bank signature as a coupon in said storage means if it is valid; and
wherein at the time of requesting issuance of electronic cash, said sending means sends said coupon SKBx(PKU), said amount of withdrawal x and said pseudonym PKU to said issuer equipment, and at the time of payment, sends said license SKR(PKU) to said shop.
17. The user equipment of claim 16, further comprising:
random generating means for generating and storing a random number R in said storage means;
blinding means for blinding said pseudonym with said random number R to obtain Br(PKU, R) and for sending it as said request for withdrawal to said bank equipment together with said amount of withdrawal x; and
unblinding means for unbending a bank signature SKBx(Br(PKU, R) for said request for withdrawal received from said bank equipment with said random number R to obtain a signature SKBx(PKU) for said pseudonym PKU.
18. The user equipment of claim 14, wherein: said electronic cash system further comprises bank equipment for managing an account of said user; and said key generating means comprises means for generating and storing a common key K in said storage means; said user equipment further comprising:
encrypting means for encrypting said pseudonym PKU and said common key K with said public key PKI to obtain encrypted information PKI(PKU, K) and for sending it as a request for registration to said bank together said user identification information IdU;
decrypting means for decrypting encrypted issuer signature K(SKI(PKU)) for said pseudonym PKU received via said bank to obtain an issuer signature SKI(PKU); and
signature verifying means for verifying the validity of said decrypted issuer signature SKI(PKU) and for storing it as said license in said storage means if it is valid;
wherein, at the time of requesting an issuance of electronic cash, said encrypting means encrypts said pseudonym PKU, said common key K and said amount of withdrawal x with said issuer public key PKI to obtain encrypted information PKI(PKU, K, x), and sends it as said request for withdrawal to said bank together with said amount of withdrawal x and said user identification information IdU;
wherein said decrypting means comprises means for decrypting an encrypted issuer signature K(SKI(PKU, x)) received via said bank to obtain an issuer signature SKI(PKU, x);
wherein said signature verifying means comprises means for verifying the validity of said issuer signature SKI(PKU, x) with said public key PKI; and
wherein said balance updating means comprises means for incrementing said balance counter in said storage means by x when said issuer signature SKI(PKU, x) is found valid by said signature verifying means.
19. The user equipment of claim 14, wherein: said electronic cash system further comprises bank equipment for managing an account of said user; and said key generating means comprises means for generating and storing a common key K in said storage means; said user equipment further comprising:
encrypting means for encrypting said pseudonym PKU and said common key K with said public key PKI to obtain encrypted information PKI(PKU, K) and for sending it as a request for registration to said bank together said user identification information IdU;
decrypting means for decrypting encrypted issuer signature K(SKI(PKU, KID)) received via said bank to obtain an issuer signature SKI(PKU) and common key information KID; and
signature verifying means for verifying the validity of said decrypted issuer signature SKI(PKU) and for storing it as said license in said storage means together with said common key information KID if it is valid;
wherein, at the time of requesting an issuance of electronic cash, said encrypting means encrypts said pseudonym PKU, said common key K and said amount of withdrawal x with said issuer public key PKI to obtain encrypted information PKI(PKU, x), and sends it as said request for withdrawal to said bank together with said amount of withdrawal x, said common key information KID and said user identification information IdU;
wherein said decrypting means comprises means for decrypting an encrypted issuer signature K(SKI(PKU, x)) received via said bank to obtain an issuer signature SKI(PKU, x);
wherein said signature verifying means comprises means for verifying the validity of said issuer signature SKI(PKU, x) with said public key PKI; and
wherein said balance updating means comprises means for incrementing said balance counter in said storage means by x when said issuer signature SKI(PKU, x) is found valid by said signature verifying means.
20. The user equipment of claim 19, wherein: said key generating means generates, as said public key PKU and said secret key SKU, n public keys PKU1, PKU2, . . . , PKUn and n secret keys SKU1, SKU2, . . . , SKUn corresponding thereto, and stores them in said storage means, said n public keys being used as n pseudonyms; said encrypting means comprises means for encrypting said n pseudonyms and said common key K with said public key PKI to obtain encrypted information PKI(PKU1, PKU2, . . . , PKUn, K) and for sending them to said bank together with said user identification information IdU; and said decrypting means comprises means for decrypting an encrypted issuer signature received via said bank to obtain n signatures SKI (PKU1), SKI(PKU2), . . . , SKI(PKUn) as n licenses and said common key information KID; wherein:
at the time of requesting an issuance of electronic cash, said encrypting means encrypts a set of an arbitrarily selected one PKUi of said n pseudonyms and said amount of withdrawal x with said common key to obtain encrypted information K(PKUi, x) and sends it to said bank together with said amount x, said common key information KID and said user identification information IdU; said decrypting means decrypts said encrypted issuer signature K(SKI (PKUi, x) with said common key K to obtain an issuer signature SKI(PKUi, x) for said set of said selected pseudonym PKUi and said amount x; and said balance updating means increments said balance counter by said amount x; and
wherein an arbitrary one of said n licenses is selected and used at the time of payment to said shop.
21. In an electronic cash system which comprises issuer equipment as an institution for issuing electronic cash, user equipment as a user for receiving said electronic cash issued from said issuer equipment and shop equipment as an institution for receiving payment by said electronic cash, said shop equipment comprising:
storage means for storing history information H on the communication with said user, inclusive of a user public key PKU, a license, challenge information, the amount paid y and a user signature, shop identification information IdS and a public key of a license issuer;
signature verifying means responsive to a payment request for payment composed of said user public key PKU and said license, for verifying the validity of a signature of said license with said license issuer public key, and for verifying the validity of said user signature for said challenge information and said amount paid y with said public key PKU;
means for storing said public key PKU, said license, said challenge information and said user signature as said history information H in said storage means when both of said signatures are found valid by said signature verifying means;
means for generating said challenge information associated with the payment of electronic cash when said license is found valid;
sending means for sending said challenge information to said user equipment and said history information H and said shop identification information IdS to deposit institution equipment;
receiving means for receiving various pieces of information from the other institutions; and
control means for controlling each of said means to execute its process.
sending means for sending said signature SKI(PKU, x) from said signature generating means to said user equipment;
receiving means for receiving various pieces of information from the other institutions; and
control means for controlling each of said means to execute its process.
23. The issuer equipment of claim 22, wherein said electronic cash system further comprises trustee equipment having a public key PKR and a secret key SKR corresponding thereto, said issuer equipment further comprising:
means for managing an account of said user and for drawing said amount x from an account corresponding to said public key PKU upon receiving said public key PKU, the user identification information IdU and said amount of withdrawal x as a request for withdrawal from said user; and
wherein said signature verifying means comprises means for verifying the validity of an issuer signature SKR(PKU) as said license with said public key PKR.
24. The issuer equipment of claim 22, wherein said electronic cash system further comprises trustee equipment having a public key PKR and a secret key SKR corresponding thereto, and bank equipment for managing an account of said user, said issuer equipment further comprising:
signature verifying means which, upon receiving, as a request for issuance of electronic cash from said user, a bank signature SKBx(PKU) corresponding to the amount of issue x and said pseudonym PKU, verifies the validity of said bank signature with a public key PKBx; and
means for incrementing said balance counter by said amount x and for generating said signature SKI(PKU, x) when said bank signature is found valid by said signature verifying means.
25. The issuer equipment of claim 22, wherein said electronic cash system further comprises bank equipment for managing an account of said user, and wherein:
said issuer equipment comprises decrypting means for decrypting encrypted information PKI(PKU, K), received as a request for registration from said user via said bank equipment, with said secret key SKI to obtain said user pseudonym PKU and a common key K and for storing them in said storage means;
said signature generating means comprises means for generating, as a license, an issuer signature SKI(PKU) for said pseudonym at the time of registration;
said issuer equipment comprises encrypting means which, at the time of registration, encrypts said license SKI(PKU) with said common key K to obtain an encrypted license K(SKI(PKU)) and sends it to said user via said bank equipment;
said decrypting means comprises means which, at the time of withdrawal, decrypts encrypted information PKI(PKU, K, x), received as a request for withdrawal by said receiving means from said user equipment via said bank equipment, with said secret key SKI to obtain said public key PKU, said common key K and said amount x;
said issuer equipment comprises comparing means for comparing said decrypted amount x and said received amount x for a match and for incrementing said balance counter by said amount x if they match;
said signature generating means comprises means for generating said signature SKI(PKU, x); and
said encrypting means comprises means for encrypting said signature SKI(PKU, x) with said common key K to obtain encrypted information K(SKI(PKU, x)) and for sending it to said user equipment via said bank equipment.
26. The issuer equipment of claim 22, wherein said electronic cash system further comprises bank equipment for managing an account of said user, and wherein:
said issuer equipment comprises: decrypting means for decrypting encrypted information PKI(PKU, K), received as a request for registration from said user via said bank equipment, with said secret key SKI to obtain said user pseudonym PKU and a common key K and for storing them in said storage means; and key information adding means for adding key identification information KID to said common key K and for storing it in said storage means in correspondence with said common key K;
said signature generating means comprises means for generating, as a license, an issuer signature SKI(PKU) for said pseudonym at the time of registration;
said issuer equipment comprises: encrypting means which, at the time of registration, encrypts said license SKI(PKU) and said key identification information KID with said common key K to obtain an encrypted license K(SKI(PKU), KID) and sends it to said user equipment via said bank equipment; and retrieving means for retrieving from said storage means said common key K corresponding to said key identification information KID contained in information K(PKU, x), KID, x received as a request for withdrawal by said receiving means from said user equipment via said bank equipment at the time of withdrawal;
said decrypting means comprises means for decrypting said received information K(PKU, x) with said retrieved common key K to obtain said pseudonym PKU and said amount of withdrawal x;
said issuer equipment comprises comparing means for comparing said decrypted amount x and said received amount x for a match and for incrementing said balance counter by said amount x by said balance updating means if they match;
said signature generating means comprises means for generating said signature SKI(PKU, x); and
said encrypting means comprises means for encrypting said signature SKI(PKU, x) with said common key K to obtain encrypted information K(SKI(PKU, x)) and for sending it to said user equipment via said bank equipment.
27. The issuer equipment of claim 26, wherein:
said decrypting means decrypts with n encrypted pseudonyms and an encrypted public key PKI(PKU1, PKU2, . . . , PKUn, K), received as a request for registration from said user equipment via said bank equipment, with said secret key SKI to obtain n pseudonyms PKU1, PKU2, . . . , PKUn and said common key K, and stores them in said storage means, said n being an integer equal to or greater than 2;
said signature generating means comprises means for attaching a signature to said n pseudonyms PKU1, PKU2, . . . , PKUn to obtain n licenses SKI(PKU1), SKI(PKU2), . . . , SKI(PKUn);
said encrypting means generates, at the time of registration, an encrypted license K(SKI(PKU1), SKI(PKU2), . . . , SKI(PKUn), KID) by encrypting said n licenses and said key identification information KID with said common key K, and sends said encrypted license to said user equipment via said bank equipment;
said decrypting means decrypts said received information K(PKUi, x) with said retrieved common key K to obtain said pseudonym PKUi and said amount of withdrawal x;
said signature generating means generates a signature SKI(PKUi,
x); and
said encrypting means encrypts said signature SKI(PKUi, x) with said common key K to obtain encrypted signature K(SKI(PKUi, x)), and sends it to said user equipment via said bank equipment.
28. A recording medium having recorded thereon a program for a user equipment to implement electronic cash in an electronic cash system which comprises issuer equipment as an institution for issuing electronic cash, user equipment as a user for receiving said electronic cash issued from said issuer equipment and shop equipment as an institution for receiving payment by said electronic cash, said program comprising:
a user registration procedure including steps of: generating a signature verifying public key PKU and a signature generating secret key SKU corresponding thereto, then storing them in storage means, and sending them to an external institution together with user identification information IdU so as to register said public key PKU as a pseudonym; and receiving a signature of said external institution for said pseudonym, and recording it as a license in said storage means;
an electronic cash issuing procedure including steps of: sending a requested amount of issuance x and said pseudonym PKU to said issuer equipment; verifying the validity of an issuer signature SKI (PKU, x) with a public key PKI of said issuer equipment; upon receiving from said issuer equipment, as electronic cash, said issuer signature SKI(PKU, x) for said requested amount of issuance x and said pseudonym PKU and incrementing a balance counter set in said storage means by the amount x of said received electronic cash if said issuer signature SKI(PKU, x) is found valid by said verification; and
a payment procedure including steps of sending said pseudonym PKU and said license SKI(PKU) to said shop equipment; and upon receiving therefrom a challenge associated with payment, attaching a user signature to said challenge and the amount due y, then sending said user signature to said shop together with said amount due y; and
decrementing said balance counter by said amount due y.
29. The recording medium of claim 28, wherein said electronic cash system further comprises a bank as an institution for managing an account of said user, said external institution is a trustee having a public key PKR and a secret key SKR corresponding thereto, and said electronic cash issuing procedure in said program for the execution by said user equipment further comprises the steps of: generating and storing a random number R in said storage means; generating blinded pseudonym Br(PKU, R) by blinding said pseudonym PKU with said random number R; sending said blinded pseudonym Br(PKU, R) as a request for issuance of electronic cash to said bank together with an amount of issue x and user identification information IdU; receiving from said bank a bank signature SKBx(Br(PKU, R)) corresponding to said amount x for said blinded pseudonym Br(PKU, R); unblinding said bank signature SKBx(Br(PKU, R)) with said random number R to extract a bank signature SKBx(PKU) for said pseudonym PKU as a coupon, and storing said extracted bank signature in said storage means, and sending said bank signature SKBx(PKU) as said coupon to said issuer equipment together with said pseudonym PKU and said amount x.
30. The recording medium of claim 28, wherein said electronic cash system further comprises a bank as an institution for managing an account of said user; said external institution is said issuer equipment; and wherein:
said user registration procedure in said program for the execution by said user equipment further comprises the steps of:
generating and storing a common key K in said storage means;
generating encrypted information PKI(PKU, K) by encrypting said pseudonym PKU and said common key K with said public key PKI;
sending said encrypted information PKI(PKU, K) to said bank together with user identification information IdU; decrypting encrypted issuer signature K(SKI(PKU)) received via said bank with said common key K to extract said signature SKI(PKU); and verifying the validity of said signature SKI(PKU) with said public key PKI and, if valid, storing it as said license in said storage means; and
said electronic cash issuing procedure further comprises of:
generating encrypted information PKI(PKU, x, K) by encrypting said pseudonym PKU, an amount x and said common key K with said public key PKI, and sending said encrypted information PKI(PKU, x, K) to said bank together with said user identification information IdU and said amount x; and receiving encrypted issuer signature K(SKI (PKU, x)) generated by encrypting said pseudonym PKU and said amount x with said common key K, and decrypting said encrypted issuer signature K(SKI(PKU, x)) with said common key K to obtain said issuer signature SKI(PKU, x).
31. The recording medium of claim 28, wherein said electronic cash system further comprises a bank as an institution for managing an account of said user; said external institution is said issuer equipment; wherein:
said user registration procedure in said program for the execution by said user equipment further comprises the steps of:
generating and storing a common key K in said storage means;
generating encrypted information PKI(PKU, K) by encrypting said pseudonym PKU and said common key K with said public key PKI;
sending said encrypted information PKI(PKU, K) to said bank together with user identification information IdU; decrypting encrypted issuer signature K(SKI(PKU)), KID received via said bank with said common key K to extract said signature SKI(PKU) and common key information KID added by said issuer equipment to said common key K; and
verifying the validity of said signature SKI(PKU) with said public key PKI and, if valid, storing said signature SKI(PKU) as said license and said KID in said storage means; and
said electronic cash issuing procedure comprises steps of:
generating encrypted information K(PKU, x) by encrypting said pseudonym PKU and the amount x with said common key K, and sending said encrypted information K(PKU, x) to said bank together with said user identification information IdU, said common key information KID and said amount x; and receiving encrypted issuer signature K(SKI(PKU, x)) generated by encrypting said issuer signature SKI(PKU, x) with said common key K, and decrypting said encrypted issuer signature K(SKI(PKU, x)) with said common key K to obtain said issuer signature SKI(PKU, x).
32. The recording medium of claim 31, wherein:
said user registration procedure in said program for the execution by said user equipment further comprises the steps of:
generating n public keys PKU1, PKU2, . . . , PKUn as said public key PKU and n secret keys SKU1, SKU2, . . . , SKUn as said secret key SKU; storing them in said storage means; encrypting said n public keys as said n pseudonyms and said common key K with said public key PKI to obtain encrypted information PKI(PKU1, PKU2, . . . , PKUn, K); sending it to said bank together with said user identification information IdU;
decrypting, an encrypted issuer signature K(SKI(PKU1), SKI(PKU2), SKI(PKUn), KID) for said n pseudonyms, received via said bank, with said common key K to extract n issuer signatures SKI(PKU1), SKI (PKU2), . . . , SKI(PKUn) and common key information KID added by said issuer equipment to said common key K; and verifying the validity of said n signatures with said public key PKI and, if valid, storing said n signature as n licenses and said common key information KID in said storage means;
said electronic cash issuing procedure of said program for the execution by said user equipment comprises the steps of: encrypting an arbitrarily selected one PKUi of said n pseudonyms and said amount x with said common key K to obtain encrypted information PKI(PKUi, x); sending it to said bank together with said user identification information IdU, said common key information KID and said amount x; receiving an encrypted issuer signature K(SKI(PKUi, x)) generated by encrypting an issuer signature SKI(PKUi, x) to said selected pseudonym PKUi and said amount x with said common key K;
decrypting said encrypted issuer signature with said common key K to obtain an issuer signature SKI(PKUi, x); and verifying the validity of said issuer signature SKI (PKU:, x) with said issuer public key PKI and, if valid, incrementing said balance counter by x; and
said payment procedure comprises the steps of selecting an arbitrary one of said n pseudonyms PKU1, PKU2, . . . , PKUn and using it as said pseudonym in the payment to said shop.
33. A recording medium having recorded thereon a program for an issuer equipment to implement electronic cash in an electronic cash system which comprises issuer equipment as an institution for issuing electronic cash, user equipment as a user for receiving said electronic cash issued from said issuer equipment and shop equipment as an institution for receiving payment by said electronic cash, said program comprising:
an electronic cash issuing procedure including steps of generating an issuer signature SKI(PKU, x) for a requested amount of issue x received from said user equipment and a user public key PKU received as a registered pseudonym, then sending said issuer signature SKI(PKU, x) as electronic cash to said user equipment, and incrementing, by the amount x of electronic cash issued, a balance counter set in storage means in correspondence with said user pseudonym; and
an electronic cash return procedure including steps of: verifying the validity of a license and a user signature contained in history information received from said shop equipment with an issuer public key PKI and said user public key PKU, respectively, and if they are valid, decrementing electronic cash balance counter corresponding to said user pseudonym by the amount used; and storing said history information in said storage means.
34. The recording medium of claim 33, wherein said electronic cash system further comprises a trustee as an institution for registering therewith a user public key PKU as a user pseudonym and for issuing to said user a license SKR(PKU) generated by attaching an issuer signature to said user pseudonym PKU with a secret key SKR;
said issuer equipment manages a user account in correspondence with said user identification information IdU; and said program for the execution by said issuer equipment further comprises a withdrawal step of, upon receiving from said user said user identification information IdU, said amount of issue x and said user pseudonym, withdrawing said amount x from an account corresponding to said user identification information IdU.
35. The recording medium of claim 33, wherein said electronic cash system further comprises a trustee as an institution for registering therewith a user public key PKU as a pseudonym and for issuing to said user a license SKR(PKU) generated by attaching an issuer signature to said user pseudonym PKU with a secret key SKR, and a bank as an institution for managing user accounts and wherein;
and said program for the execution by said issuer equipment further comprises step of: receiving from said user, as a request for issuance of electronic cash, said pseudonym PKU and said requested amount of issue x and a bank signature SKBx(PKU) made for said pseudonym PKU by a bank secret key SKBX as a coupon corresponding to said amount x; and verifying the validity of said coupon SKBx(PKU) with a public key PKBx corresponding to a bank secret key SKBx, and if it is valid, issuing said electronic cash SKI(PKU, x) and incrementing said balance counter by x.
36. The recording medium of claim 33, wherein said electronic cash system further comprises a bank as an institution for managing user accounts; and said program for the execution by said issuer equipment further comprises:
a user registration procedure including steps of: upon receiving, as a request for registration from said user via said bank, encrypted information PKI(PKU, K) generated by encrypting said user pseudonym PKU and a user’s generated common key K with said public key PKI, decrypting said encrypted information PKI(PKU, K) with said secret key SKI to extract said pseudonym PKU and said common key K; storing said pseudonym PKU together said encrypted information PKI(PKU, K) in said storage means; encrypting said signature SKI(PKU) for said pseudonym PKU with said common key K to obtain an encrypted information K(SKI(PKU)); and sending it as encrypted license via said bank to said user; and
wherein said electronic cash issuing procedure further comprises the steps of: upon receiving encrypted information PKI(PKU, K, x) and an amount of issue x as a request for issuance of electronic cash from said user via said bank, decrypting said encrypted information PKI(PKU, K, x) with said secret key SKI to extract said pseudonym PKU, said common key K and said amount of issue x; comparing said decrypted amount x and said received amount x for a match, and if a match is found, generating said electronic cash SKI(PKU, x) by signing said pseudonym PKU and said amount x with said secret key SKI;
encrypting said electronic cash SKI(PKU, x) with said common key K to produce encrypted electronic cash K(SKI(PKU, x)); and sending said encrypted electronic cash K(SKI(PKU, x)) to made user via said bank.
37. The recording medium of claim 33, wherein said electronic cash system further comprises a bank as an institution for managing user accounts; and said program for said issuer equipment further comprises:
a user registration procedure including steps of: upon receiving, as a request for registration from said user via said bank, encrypted information PKI(PKU, K) generated by encrypting said user pseudonym PKU and a user’s generated common key K with said public key PKI, decrypting said encrypted information PKI(PKU, K) with said secret key SKI to extract said pseudonym PKU and said common key K; producing a key identification information KID corresponding to said common key K; storing said common key K and said key identification information KID together with said PKU and PKI(PKU, K) in said storage means in correspondence with each other;
encrypting said signature SKI(PKU) for said pseudonym PKU and said key identification information KID with said common key K to obtain encrypted information K(SKI(PKU), KID); and sending said K(SKI(PKU), KID) as an encrypted license via said bank to said user; and
wherein said electronic cash issuing procedure further comprises the steps of: upon receiving encrypted information K(PKU, x), said key identification information KID and an amount of issue x as a request for issuance of electronic cash from said user via said bank, retrieving from said storage means said common key K corresponding to said key identification information KID; decrypting said encrypted information K(PKU, x) with said retrieved common key K to extract said pseudonym PKU and said amount of issue x; comparing said decrypted amount x and said received amount x for a match, and if a match is found, generating electronic cash SKI(PKU, x) by signing said pseudonym PKU and said amount x with said secret key SKI;
encrypting said electronic cash SKI(PKU, x) with said common key K to produce encrypted electronic cash K(SKI(PKU, x)); and sending said encrypted electronic cash K(SKI(PKU, x)) to said user via said bank.
38. The recording medium of claim 37, wherein in said registration procedure in said program for the execution by said user issuer equipment, said received pseudonym PKU is composed of n pseudonyms PKU1, PKU2, . . . , PKUn, said step of generating said signature includes step of generating, as n licenses, n signatures SKI(PKU1), SKI(PKU2), . . . , SKI(PKUn) attached to said n pseudonyms, respectively; said step of encrypting said license includes a step of encrypting said n licenses and said key identification information KID with said common key K to obtain encrypted information K(SKI (PKU1), SKI(PKU2), . . . , SKI(PKUn), KID); and sending said encrypted information to said user; and
wherein said electronic cash issuing procedure further comprises the steps of: when said pseudonym PKUi contained in encrypted information K(PKUi, x) received from said user is an arbitrarily selected one of said n pseudonyms PKU1, PKU2, . . . , PKUn, generating SKI(PKUi, x) as said electronic cash by attaching said issuer signature to said selected pseudonym PKUi and said amount of issue x;
encrypting them with said common key K to obtain encrypted electronic cash K(SKI(PKUi, x)); and sending it to said user.