Keys used for elliptic curve cryptography
By linearly combining and initializing K second elliptic curve encryption key pairs, N first key pairs are generated using addition operations, which solves the problems of slow generation speed and insufficient security in the existing technology and achieves faster and more secure key generation.
Patent Information
- Application Number
- CN202111275402.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-10-20
- Filing Date
- 2021-10-29
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2041-10-29
AI Technical Summary
Existing elliptic curve cryptography key generation methods have problems such as slow generation speed, inability to be implemented on weaker processors, and insufficient security.
N first key pairs are generated by using a linear combination of K second elliptic curve encryption key pairs, using addition operations instead of scalar multiplication operations, and combining initialization and matrix operations to generate N first elliptic curve encryption key pairs.
This enables faster key generation, suitable for less powerful processors, and improves the security and quantity of key generation.
Smart Images

Figure CN114448634B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates generally to encryption and its use in digital signatures and key agreement, and more particularly to elliptic curve cryptography. The present disclosure more particularly addresses the generation of a pair of keys for elliptic curve cryptography. Background Art
[0002] Elliptic Curve Cryptography (ECC) is a type of cryptography that exploits certain properties of elliptic curves. More specifically, cryptographic primitives compatible with elliptic curves have advantageous properties in terms of security and performance.
[0003] It would be desirable to at least partially improve upon certain aspects of known methods and apparatus for elliptic curve cryptography key generation. Summary of the Invention
[0004] There is a need for faster methods of generating keys for elliptic curve cryptography.
[0005] There is a need for a method for generating elliptic curve cryptography keys that enables a faster signing method.
[0006] There is a need for a method for generating elliptic curve cryptography keys that enables faster key agreement methods.
[0007] There is a need for a method for generating elliptic curve cryptography keys that can be implemented by less powerful processors.
[0008] One embodiment facilitates addressing all or part of the shortcomings of known methods of generating elliptic curve cryptography keys.
[0009] One embodiment provides a method for generating N first ECC key pairs for elliptic curve encryption, wherein each first key pair is a linear combination of previously generated second elliptic curve encryption key pairs.
[0010] According to one embodiment, the linear combination is an addition of some of said second key pairs.
[0011] According to one embodiment, the some second key pairs are randomly selected among the second ECC key pairs.
[0012] According to one embodiment, the method comprises a step of initializing the N first key pairs before applying the linear combination.
[0013] According to one embodiment, during the initialization step, N first ECC key pairs are set to zero and infinity, respectively.
[0014] According to one embodiment, during the initialization step, the N first key pairs are initialized to the values taken by the last generated first key pair.
[0015] According to one embodiment, during an initialization step, N first key pairs (r(i), R(i)) are initialized to the values taken by one of the last generated W key pairs (r(i-j), R(i-j)), where j <= W, j < i, and j >= 1.
[0016] According to one embodiment, N first elliptic curve cryptography (ECC) key pairs r(i), R(i) are generated using K previously generated second ECC key pairs p(k), P(k), where i varies from 1 to N, k varies from 1 to K, where K is less than N, and where the linear combination is:
[0017]
[0018] where A(i,j) represents the general term of a matrix A of size N*K and all submatrices of size K*K are invertible.
[0019] According to one embodiment, matrix A is a Vandermonde matrix.
[0020] According to one embodiment, the first key pairs and the second key pairs are formed by a scalar and a point on an elliptic curve.
[0021] According to one embodiment, the number of second key pairs is less than N.
[0022] One embodiment provides a device capable of generating elliptic curve cryptography keys by implementing the disclosed method.
[0023] One embodiment provides a digital signature and / or key agreement method using elliptic curve cryptography keys generated by implementing the disclosed method.
[0024] One embodiment provides a digital signature and / or key agreement device capable of performing digital signature and / or key agreement by implementing the disclosed method.
[0025] In one embodiment, a method includes: using an encryption circuitry to generate N first elliptic curve cryptography (ECC) key pairs r(i), R(i), where i varies from 1 to N, the N first ECC key pairs using K second ECC key pairs p(k), P(k), where k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows:
[0026]
[0027] wherein A(i,j) represents a common entry of a matrix A of size N*K, and all sub-matrices of size K*K are reversible; and performing an encryption operation using the encryption circuit system, the encryption operation using one or more pairs of ECC keys in the first ECC key pair.
[0028] In one embodiment, a device includes a memory and cryptographic circuitry coupled to the memory. The cryptographic circuitry, in operation, generates N first elliptic curve cryptography (ECC) key pairs r(i), R(i) using K second ECC key pairs p(k), P(k), where i varies from 1 to N and k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first key pair is a linear combination of the ECC key pairs in the second ECC key pair, as follows:
[0029]
[0030] wherein A(i,j) represents a common entry of a matrix A of size N*K, and all sub-matrices of size K*K are reversible; and an encryption operation is performed using one or more pairs of ECC keys in a first ECC key pair.
[0031] In one embodiment, a system includes: functional circuitry; and cryptographic circuitry coupled to the functional circuitry. The cryptographic circuitry, in operation, uses K second elliptic curve cryptography (ECC) key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where i varies from 1 to N, k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first key pair is a linear combination of the ECC key pairs in the second ECC key pair, as follows:
[0032]
[0033] wherein A(i,j) represents a common entry of a matrix A of size N*K, and all sub-matrices of size K*K are reversible; and an encryption operation is performed using one or more pairs of ECC keys in a first ECC key pair.
[0034] In one embodiment, the contents of a non-transitory computer-readable medium configure a cryptographic circuit system to perform a method. The method includes: using K second elliptic curve cryptography (ECC) key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where i varies from 1 to N, k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first key pair is a linear combination of the ECC key pairs in the second ECC key pair, as follows:
[0035]
[0036] wherein A(i,j) represents a common entry of a matrix A of size N*K, and all sub-matrices of size K*K are reversible; and an encryption operation is performed using one or more pairs of ECC keys in a first ECC key pair. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The above-mentioned features and advantages and other features and advantages will be described in detail in the following description of specific embodiments given by way of illustration and not limitation with reference to the accompanying drawings, in which:
[0038] Figure 1 An embodiment of an electronic system is shown very schematically in block diagram form;
[0039] Figure 2 An embodiment of a method for generating a pair of elliptic curve encryption keys is shown in the form of a flow chart;
[0040] Figure 3 Another embodiment of a method for generating a pair of elliptic curve encryption keys is shown in the form of a flow chart; and
[0041] Figure 4 Another embodiment of a method for generating a pair of elliptic curve encryption keys is shown in the form of a flowchart. DETAILED DESCRIPTION
[0042] In the various figures, similar features are designated by similar reference numerals. In particular, common structural and / or functional features in various embodiments may have the same reference numerals and may be provided with the same structure, dimensions, and material properties.
[0043] For the sake of clarity, only the steps and elements useful for understanding the embodiments described herein are explained and described in detail. In particular, the general principles of elliptic curve cryptography are not reminded in the description of the embodiments.
[0044] Unless otherwise stated, when two elements are referred to as being connected together, this means a direct connection without any intervening elements other than conductors, and when two elements are referred to as being coupled together, this means the two elements may be connected or they may be coupled via one or more other elements.
[0045] In the following disclosure, unless otherwise stated, when referring to absolute position qualifiers such as terms "front", "back", "top", "bottom", "left", "right", or relative position qualifiers such as terms "above", "below", "higher", "lower", or orientation qualifiers such as "horizontal", "vertical", reference is made to the orientation shown in the figures.
[0046] Figure 1 The electronic device 10 is schematically shown in block diagram form.
[0047] The device 10 includes:
[0048] Processor (CPU) 11;
[0049] a data storage unit or memory (MEM) 12, which can include one or more different types of memory circuits;
[0050] Cryptographic coprocessor (CYP) 13;
[0051] One or more circuits (FCTs) 14 that enable specific functions of device 10; and
[0052] Optionally, for example, a communication unit or interface (I / O) 15 enables the device 10 to exchange data, for example, with other electronic devices.
[0053] The different elements included in the device 10 are coupled together and can exchange data via a data bus 16 .
[0054] The processor 11 is capable of processing data stored in the memory unit 12 and / or data originating from the circuit 14 and from the unit or interface 15 .
[0055] Cryptographic coprocessor unit or circuit 13 is a processor capable of performing modular arithmetic and elliptic curve operations. Cryptographic coprocessor unit 13 may form part of processor 11 or act as an intermediary for processor 11 through which cryptographic coprocessor unit 13 exchanges data with elements of device 10. For example, unit 13 may act as an intermediary between unit 13 and processor 11 by processing the data being exchanged.
[0056] The cryptographic coprocessor unit 13 is more specifically capable of implementing digital signature and key agreement algorithms based on elliptic curve cryptography. In particular, the cryptographic coprocessor 13 is capable of generating elliptic curve cryptographic key pairs or ECC key pairs to implement functions such as Figures 2 to 4 The described key pair generation method. Figures 2 to 4 The generation method of is based on the fact that a linear combination of elliptic curve cryptographic keys provides an elliptic curve cryptographic key.
[0057] The cryptographic coprocessor 13 is also capable of using elliptic curve cryptographic key pairs in digital signature and / or key agreement algorithms.
[0058] Figure 2 It shows that Figure 1 Flowchart of an implementation mode of a method for generating multiple pairs of ECC keys implemented by the described device 10. More specifically, Figure 2The method can generate N pairs of ECC keys (r(i), R(i)), where i varies from 1 to N and N is an integer. A pair of keys (r(i), R(i)) is formed by a scalar r(i) and a point R(i) of the elliptic curve.
[0059] The method described herein is capable of generating N pairs of ECC keys (r(i), R(i)) by using linear combinations of K pairs of ECC keys (p(k), P(k)), where k varies from 1 to K and K is an integer less than N. A pair of ECC keys (p(k), P(k)) is formed by a scalar p(k) and a point P(k) of an elliptic curve.
[0060] In a preliminary step 20 (GEN K key pairs), K pairs of ECC keys (p(k), P(k)) are generated, for example, using a current ECC key generation method. The K pairs of ECC keys (p(k), P(k)) are, for example, generated in advance and then stored in a memory circuit.
[0061] In step 22 following step 20, N pairs of ECC keys (r(i), R(i)) are generated. To this end, each pair of ECC keys (r(i), R(i)) is generated one by one by using the following three steps:
[0062] Step 221 (Init), initializing the ECC key pair (r(i), R(i));
[0063] Step 222 (Random Addition, Add Rnd), addition of the pre-generated key pair (p(k), P(k)) to the ECC key pair (r(i), R(i)); and
[0064] In step 223 (Return), the ECC key pair (r(i), R(i)) is ready for use.
[0065] In step 221, the ECC key pair (r(i), R(i)) is set to zero. More specifically, the scalar r(i) is zero, and the point R(i) is set to a neutral element of the elliptic curve, also known as the point at infinity.
[0066] In step 222, a number C of randomly selected ECC key pairs (p(k), P(k)) are added to the ECC key pair (r(i), R(i)). More specifically, step 222 is a loop of C iterations, during which a pair of ECC keys (p(k), P(k)) is randomly selected and then added to the ECC key pair (r(i), R(i). More specifically, in each iteration, the scalar p(k) of the randomly selected ECC key pair (p(k), P(k)) is added to the scalar r(i) of the ECC key pair (r(i), R(i)). Similarly, in each iteration, the point P(k) of the randomly selected ECC key pair (p(k), P(k)) is added to the point R(i) of the ECC key pair (r(i), R(i)).
[0067] The larger the number C, the larger the number N of ECC key pairs (r(i), R(i)) that can be generated, and the better the security. However, the larger the number C, the more computation is required. As an example, C is 32, K is 8, and N is 64.
[0068] In step 223, the key pair (r(i), R(i)) is ready for use and can be stored in a memory space, for example.
[0069] Once a pair of keys (r(i), R(i)) is generated, the method continues to generate the next pair of keys (r(i+1), R(i+1)) until N pairs of keys are generated.
[0070] The advantage of the ECC key pair generation method described in this article is that, based on the conventional generation of K pairs of ECC keys (p(k), P(k)), it is possible to obtain N pairs of ECC keys (r(i), R(i)) by performing only addition operations, where the computation time of the addition operations is negligible compared to the computation time of scalar multiplication operations. Therefore, this method can generate N pairs of ECC keys more quickly. An example application of this method is its use in signature methods.
[0071] Figure 3 It shows that Figure 1 Flowchart of an implementation mode of a method for generating multiple pairs of ECC keys implemented by the described device 10. More specifically, Figure 2 The method can generate N pairs of ECC keys (r(i), R(i)), where i varies from 1 to N and N is an integer. The key pair (r(i), R(i)) is formed by a scalar r(i) and a point R(i) of the elliptic curve.
[0072] about Figure 3 The method described is similar to that described for Figure 2 The method described herein only modifies the initialization step 221 in the initialization step 221'. The common elements of the two methods are not described again.
[0073] and Figure 2 Similar to the method of , the method described herein can generate N pairs of ECC keys (r(i), R(i)) by using a linear combination of K pairs of ECC keys (p(k), P(k)), where k varies from 1 to K and K is an integer less than N. A pair of ECC keys (p(k), P(k)) is formed by a scalar p(k) and a point P(k) of an elliptic curve. The K pairs of ECC keys (p(k), P(k)) are generated in advance during the implementation of step 20.
[0074] In step 22 following step 20, N pairs of ECC keys (r(i), R(i)) are generated. To this end, each pair of ECC keys (r(i), R(i)) is generated one by one by using the following three steps:
[0075] Step 221′ (Init), initializing the ECC key pair (r(i), R(i));
[0076] Step 222 (Random Addition, Add Rnd), adds the pre-generated key pair (p(k), P(k)) to the ECC key pair (r(i), R(i)); and
[0077] In step 223 (Return), the ECC key pair (r(i), R(i)) is ready for use.
[0078] Step 221' and about Figure 2 The difference in the described step 221 is that the ECC key pair (r(i), R(i)) is not set to zero, but one of the W pairs of ECC keys (r(ij), R(ij)) generated previously, where j <= W, j<i,j> =1 and is an integer, and the integer is an algorithm parameter. More specifically, the first pair of keys (r(1), R(1)) is set to a first pair of values, for example, to zero and the point at infinity, after which the next pair of keys takes the value of a pair of ECC keys in the previous W pairs of ECC keys (r(ij), R(ij)), where j is a random integer between 1 and the maximum value between W and (i-1). For example, when the parameter W is selected to be 1, the ECC key pair (r(i), R(i)) is not set to zero, but is set to the previously generated ECC key pair (r(i-1), R(i-1)). More specifically, the first pair of keys (r(1), R(1)) is set to a first pair of values, for example, to zero and the point at infinity, after which the next pair of keys takes the value of the immediately previous pair of ECC keys (r(i-1), R(i-1)).
[0079] about Figure 3 The method described has the Figure 2The same advantages as the , but with additional advantages.
[0080] In particular, with regard to Figure 2 Compared to the described method, Figure 3 The method can achieve better security because the number N of ECC key pairs (r(i), R(i)) that can be generated becomes larger.
[0081] Furthermore, once N pairs of ECC keys (r(i), R(i)) are generated, the device 10 (or more specifically, the cryptographic coprocessor 13) only uses M pairs of ECC keys (r(i), R(i)), where M is a natural integer less than N.
[0082] If the number M is greater than the number K, then the M pairs of ECC keys (r(i), R(i)) used by the device 10 or the cryptographic coprocessor 13 are linearly dependent. In other words, the inventors have shown that when M is greater than K, the ECC key pair (r(i), R(i)) satisfies the following formula:
[0083]
[0084] About Figure 2 Compared to the method described, the coefficients b(i) and B(i) are determined for Figure 3 The described method is more difficult. As a result, the set of ECC key pairs (r(i), R(i)) that can be generated by this method is larger.
[0085] Yet another advantage of this approach is that the set of key pairs that can be generated by this approach grows with N.
[0086] Figure 4 It shows that Figure 1 Flowchart of an implementation mode of a method for generating multiple pairs of ECC keys implemented by the described device 10. More specifically, Figure 4 The method can generate N pairs of ECC keys (r(i), R(i)), where i varies from 1 to N and N is an integer. As mentioned above, the key pair (r(i), R(i)) is formed by the scalar r(i) and the point R(i) of the elliptic curve.
[0087] Similar to About Figure 2 and Figure 3 The method described herein is capable of generating N pairs of ECC keys (r(i), R(i)) by using a linear combination of K pairs of ECC keys (p(k), P(k)), where k varies from 1 to K and K is an integer less than N. A pair of ECC keys (p(k), P(k)) is formed by a scalar p(k) and a P(k) point of an elliptic curve.
[0088] In the preliminary step 30 (generate K key pairs, GEN K key pairs), Figure 2 The same as described in step 20, K pairs of ECC keys (p(k), P(k)) are generated by using the ECC key generation method. The K pairs of ECC keys (p(k), P(k)) are, for example, generated in advance and then stored in the memory circuit.
[0089] In step 31, N pairs of ECC keys (r(i), R(i)) are generated. For this purpose, a vector comprising K pairs of ECC keys (p(k), P(k)) is multiplied by a matrix A. The matrix A has a common entry A(i, j) and is of size N*K, and is characterized in that all its square submatrices of size K*K are reversible. Thus, the N pairs of ECC keys (r(i), R(i)) are given by the following formula:
[0090]
[0091] An example of such a matrix is the Vandermonde matrix. Each row (i) in the Vandermonde matrix is defined as follows:
[0092] Row(i)=(1, c(i), (c(i)) 2 , ..., (c(i)) K-1 )
[0093] where c(i) are integers or coefficients that are different for each row in the Vandermonde matrix.
[0094] According to one example, if K is an even number, the coefficients c(1), c(2), ..., c(K) are paired, and in each pair (c(i), c(i+1)), c(i+1) is equal to the opposite of c(i), denoted by -c(i). This has the advantage of accelerating the generation of a pair of keys associated with a row of the Vandermonde matrix. More specifically, an example of c(i) is as follows:
[0095]
[0096] in Indicates the rounded value of the number d.
[0097] Another example of such a matrix A is the Pascal matrix, which is defined as follows:
[0098]
[0099] in represents the binomial coefficient associated with i+j and j.
[0100] Another example of such a matrix A is a matrix from the family of matrices described in the second section "The first matrix" of the article entitled "Two matrices for Blakley's secret sharing scheme" by Xiali Hei, Xiaojiang Du, Binheng Song and referenced in ICC 2012: 810-814. The matrix A has the general form referenced as II-4 in the above article.
[0101] For each example of matrix A, it is important to select convenient coefficients for matrix A to increase the speed of generating a pair of keys associated with matrix A. After reviewing this disclosure, one skilled in the art will be able to select these convenient coefficients.
[0102] In step 32, N pairs of ECC keys (r(i), R(i)) are prepared for use, which may be stored, for example, in a memory space.
[0103] Furthermore, once N pairs of ECC keys (r(i), R(i)) are generated, the device 10 (or more specifically, the cryptographic coprocessor 13) only uses M pairs of ECC keys (r(i), R(i)), where M is a natural integer less than N.
[0104] If the number M is less than or equal to the number K, then the M pairs of ECC keys (r(i), R(i)) used by the device 10 or the cryptographic coprocessor 13 are not linearly dependent. This provides greater security for signatures generated by such keys.
[0105] Various embodiments and variations have been described. Those skilled in the art will appreciate that certain features of these various embodiments and variations may be combined, and those skilled in the art will be able to devise other variations.
[0106] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variants is within the capabilities of those skilled in the art. In particular, although the present disclosure is described with respect to ECC, it can be applied to other finite groups in which keys are generated by scalar multiplication.
[0107] A method for generating N first ECC key pairs for elliptic curve encryption, wherein each first key pair can be a linear combination of previously generated second elliptic curve encryption key pairs.
[0108] The linear combination may be an addition of some of the second key pairs.
[0109] The some second key pairs may be randomly selected from the second ECC key pairs.
[0110] The method may include the step of initializing (20, 30) N first key pairs before applying the linear combination.
[0111] During the initialization step, the N first ECC key pairs may be set to zero and the point at infinity respectively.
[0112] During the initialization step, the N first key pairs may be initialized to the values taken by the last generated first key pair.
[0113] During the initialization step, the N first key pairs (r(i), R(i)) may be initialized to the values taken by one of the last generated W key pairs (r(i-j), R(i-j)), where j <= W, j = 1.
[0114] N first elliptic curve cryptography key pairs r(i), R(i) may be generated using K previously generated second elliptic curve cryptography key pairs p(k), P(k), where i varies from 1 to N, k varies from 1 to K, where K may be less than N, and where the linear combination may be:
[0115]
[0116] where A(i,j) represents the general term of a matrix A of size N*K, all submatrices of which of size K*K are invertible.
[0117] The matrix A may be a Vandermonde matrix.
[0118] The first key pairs and the second key pairs may be formed by a scalar and a point on an elliptic curve.
[0119] The number of second key pairs (K) may be less than N.
[0120] A device may be capable of generating elliptic curve cryptography keys by implementing the method.
[0121] A digital signature and / or key agreement method may use the elliptic curve cryptography keys generated by implementing the method.
[0122] A digital signature and / or key agreement device may be capable of performing digital signature and / or key agreement by implementing the method.
[0123] In one embodiment, a method includes: using an encryption circuitry to generate N first elliptic curve cryptography (ECC) key pairs r(i), R(i), where i varies from 1 to N, the N first ECC key pairs r(i), R(i) using K second ECC key pairs p(k), P(k), where k varies from 1 to K, where K is less than N, and each pair r(i), R(i) in the first key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows:
[0124]
[0125] where A(i,j) represents the general term of a matrix A of size N*K, and all sub-matrices of size K*K are invertible; and using the encryption circuitry to perform an encryption operation that uses one or more pairs in the first ECC key pairs. In one embodiment, the linear combination is an addition of some of the key pairs in the second key pairs. In one embodiment, some of the second key pairs are randomly selected among the second ECC key pairs. In one embodiment, the method includes initializing the N first key pairs before applying the linear combination. In one embodiment, during initialization, the N first ECC key pairs are respectively set to zero and the point at infinity. In one embodiment, during initialization, the N first key pairs are initialized to the values taken by the last-generated first key pair. In one embodiment, during initialization, the N first key pairs (r(i), R(i)) are initialized to the values taken by one of the last-generated W pairs of keys (r(i-j), R(i-j)), where j <= W, j = 1. In one embodiment, the matrix A is a Vandermonde matrix. In one embodiment, the first key pairs and the second key pairs are formed by a scalar and a point on an elliptic curve. In one embodiment, the encryption operation includes: generating a digital signature; generating a key agreement; or a combination of generating a digital signature and generating a key agreement. In one embodiment, the method includes: generating K second ECC key pairs; and storing the generated K ECC key pairs.
[0126] In one embodiment, a device includes: a memory; and an encryption circuitry coupled to the memory. The encryption circuitry in operation: uses K second elliptic curve cryptography (ECC) key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where i varies from 1 to N, k varies from 1 to K, where K is less than N, and each pair r(i), R(i) in the first key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows:
[0127]
[0128] Where A(i,j) represents the general term of matrix A of size N*K, and all sub-matrices of size K*K are invertible; and one or more pairs from the first ECC key pairs are used to perform encryption operations. In one embodiment, the linear combination is the addition of some of the second key pairs in the second key pair. In one embodiment, the some second key pairs are randomly selected from the second ECC key pairs. In one embodiment, in operation, the encryption circuitry initializes the N first key pairs before performing the linear combination. In one embodiment, during initialization, the N first ECC key pairs are respectively set to zero and the point at infinity. In one embodiment, during initialization, the N first key pairs are initialized to the values taken by the last generated first key pair. In one embodiment, during initialization, the N first key pairs (r(i), R(i)) are initialized to the values taken by one of the last generated W pairs of keys (r(i-j), R(i-j)), where j <= W, j < i, and j >= 1. In one embodiment, matrix A is a Vandermonde matrix. In one embodiment, the encryption operation includes: generating a digital signature; generating a key agreement; or a combination of generating a digital signature and generating a key agreement. In one embodiment, the memory stores the generated K ECC key pairs during operation.
[0129] In one embodiment, a system includes: functional circuitry; and encryption circuitry coupled to the functional circuitry. The encryption circuitry, in operation: uses K second elliptic curve cryptography (ECC) key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where i varies from 1 to N and k varies from 1 to K, where K is less than N, and each pair r(i), R(i) in the first key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows:
[0130]
[0131] Where A(i,j) represents the general term of matrix A of size N*K, and all sub-matrices of size K*K are invertible; and one or more pairs from the first ECC key pairs are used to perform encryption operations. In one embodiment, in operation, the encryption circuitry initializes the N first key pairs before performing the linear combination. In one embodiment, matrix A is a Vandermonde matrix. In one embodiment, the system includes a processor coupled to the functional circuitry and the encryption circuitry, and the processor exchanges data with the encryption circuitry in operation.
[0132] In one embodiment, the contents of a non-transitory computer-readable medium configure a cryptographic circuit system to perform a method. The method includes: using K second elliptic curve cryptography (ECC) key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where i varies from 1 to N, k varies from 1 to K, where K is less than N, and each pair r(i), R(i) in the first key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows:
[0133]
[0134] wherein A(i,j) represents a common entry of a matrix A of size N*K, and all submatrices of size K*K are invertible; and a cryptographic operation is performed using one or more of the first ECC key pairs. In one embodiment, the method includes initializing the N first key pairs before applying the linear combination. In one embodiment, the content includes instructions executable by the cryptographic circuitry.
[0135] Some embodiments may take the form of or include a computer program product. For example, according to one embodiment, a computer-readable medium including a computer program is provided, which is suitable for performing one or more of the above-described methods or functions. The medium may be a physical storage medium, such as, for example, a read-only memory (ROM) chip, or a disk, such as a digital versatile disk (DVD-ROM), a compact disk (CD-ROM), a hard disk, a memory, a network, or a portable media item read by an appropriate drive or via an appropriate connection, including encoding such as with one or more bar codes or other related codes stored on one or more such computer-readable media and readable by an appropriate reader device.
[0136] In addition, in some embodiments, some or all of the methods and / or functionalities may be implemented or provided in other manners, such as at least in part in firmware and / or hardware, including but not limited to one or more application-specific integrated circuits (ASICs), digital signal processors, discrete circuit systems, logic gates, standard integrated circuits, controllers (e.g., by executing appropriate instructions, and including microcontrollers and / or embedded controllers), field programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), etc., as well as devices employing RFID technology, and various combinations thereof.
[0137] The various embodiments described above can be combined to provide further embodiments. Aspects of the embodiments can be modified, if necessary to employ concepts of the various patents, applications, and publications to provide further embodiments.
[0138] These and other changes can be made to the embodiments in light of the above detailed description. In general, in the following claims, the terms used should not be construed to limit the claims to the specific embodiments disclosed in the specification and claims, but should be construed to include all possible embodiments and the full scope of equivalents to which such claims are entitled. Therefore, the claims are not limited by this disclosure.
Claims
1. A method for generating a key, comprising: Using an encryption circuit system to generate N first ECC key pairs r(i), R(i) using K second ECC key pairs p(k), P(k), where ECC represents elliptic curve cryptography, where i varies from 1 to N and k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first ECC key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows: Where A(i,j) represents the general term of a matrix A of size N*K, and all submatrices of size K*K are invertible; and Using the encryption circuit system to perform an encryption operation that uses one or more pairs of ECC keys in the first ECC key pairs.
2. The method according to claim 1, comprising: Initializing the N first ECC key pairs before applying the linear combination.
3. The method according to claim 2, wherein during the initialization, the N first ECC key pairs are respectively set to zero and the point at infinity.
4. The method according to claim 2, wherein during the initialization, the N first ECC key pairs are initialized to the values taken by the last generated first ECC key pair.
5. The method according to claim 2, wherein during the initialization, the N first ECC key pairs (r(i), R(i)) are initialized to the values taken by one of the last generated W pairs of keys (r(i-j), R(i-j)), where j <= W, j < i, and j >= 1.
6. The method according to claim 1, wherein the matrix A is a Vandermonde matrix.
7. The method according to claim 1, wherein the first ECC key pairs and the second ECC key pairs are formed by a scalar and a point on an elliptic curve.
8. The method according to claim 1, wherein the encryption operation comprises: Generating a digital signature; Generating a key agreement; Or Generating a combination of the digital signature and generating the key agreement.
9. The method according to claim 1, comprising: Generating the K second ECC key pairs; And Storing the generated K second ECC key pairs.
10. An electronic device, comprising: A memory; And An encryption circuit system coupled to the memory, wherein the encryption circuit system in operation: Uses K second ECC key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where ECC represents elliptic curve cryptography, where i varies from 1 to N and k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first ECC key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows: Where A(i,j) represents the general term of a matrix A of size N*K, and all submatrices of size K*K are invertible; and Performs an encryption operation using one or more pairs of ECC keys in the first ECC key pairs.
11. The electronic device according to claim 10, wherein in operation, the encryption circuit system: initializes the N first ECC key pairs before performing the linear combination.
12. The electronic device according to claim 11, wherein during the initialization, the N first ECC key pairs are respectively set to zero and the point at infinity.
13. The electronic device according to claim 11, wherein during the initialization, the N first ECC key pairs are initialized to the values taken by the last generated first ECC key pair.
14. The electronic device according to claim 11, wherein during the initialization, the N first ECC key pairs (r(i), R(i)) are initialized to the values taken by one of the W key pairs (r(i - j), R(i - j)) generated last, where j <= W, j < i, and j >= 1.
15. The electronic device according to claim 10, wherein matrix A is a Vandermonde matrix.
16. The electronic device according to claim 10, wherein the encryption operation includes: generating a digital signature; generating a key agreement; or a combination of generating the digital signature and generating the key agreement.
17. The electronic device according to claim 10, wherein in operation, the memory: stores the generated K second ECC key pairs.
18. An electronic system, comprising: functional circuitry; and an encryption circuit system coupled to the functional circuitry, wherein in operation, the encryption circuit system: uses K second ECC key pairs p(k), P(k) to generate N first ECC key pairs r(i), R(i), where ECC represents elliptic curve cryptography, where i varies from 1 to N and k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first ECC key pairs is a linear combination of the ECC key pairs in the second ECC key pairs, as follows: where A(i,j) represents the general term of matrix A of size N*K, and all sub - matrices of size K*K are invertible; and performs an encryption operation using one or more pairs of ECC keys in the first ECC key pairs.
19. The electronic system according to claim 18, wherein in operation, the encryption circuit system: initializes the N first ECC key pairs before performing the linear combination.
20. The electronic system according to claim 18, wherein matrix A is a Vandermonde matrix.
21. The electronic system according to claim 18, comprising a processor coupled to the functional circuitry and the encryption circuit system, wherein in operation, the processor exchanges data with the encryption circuit system.
22. A non - transient computer - readable medium having content that configures an encryption circuit system to perform a method, the method comprising: K second ECC key pairs p(k), P(k) are used to generate N first ECC key pairs r(i), R(i), where ECC stands for elliptic curve cryptography, where i varies from 1 to N, k varies from 1 to K, where K is less than N, and each pair of keys r(i), R(i) in the first ECC key pair is a linear combination of the ECC key pairs in the second ECC key pair, as follows: where A(i,j) represents the common entry of the matrix A of size N*K, and all sub-matrices of size K*K are invertible; and An encryption operation is performed using one or more pairs of ECC keys in the first ECC key pair.
23. The non-transitory computer-readable medium of claim 22, wherein the method comprises: Before applying the linear combination, the N first ECC key pairs are initialized.
24. The non-transitory computer-readable medium of claim 22, wherein the content comprises instructions executable by the encryption circuitry.
Citation Information
Patent Citations
Encryption and / or decryption key device, system, and method
CN111737705A
Method for accelerating cryptographic operations on elliptic curves
US20020044649A1