Method and system for static DIFFIE-HELLMAN security against Cheon resistance

By selecting curves with specific Cheon resistance characteristics in the elliptic curve Diffie-Hellman cryptographic system, the security vulnerability problem of static Diffie-Hellman key exchange in some cases is solved, and effective resistance to Cheon attacks is achieved.

CN114866238BActive Publication Date: 2025-05-20MALIKIE INNOVATIONS LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210517133.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2016-05-03
Filing Date
2017-02-14
Publication Date
2025-05-20
Estimated Expiration
2037-02-14

AI Technical Summary

Technical Problem

Static Diffie-Hellman key exchange has security vulnerabilities in some cases, especially when the factor of group size q exists, Cheon attacks can effectively crack the protocol.

Method used

By selecting an elliptic curve Diffie-Hellman cryptographic system with specific Cheon resistance characteristics, it is ensured that q-1 and q+1 do not have the characteristics of being easy to factorize, thereby resisting Cheon attacks. Specific measures include selecting curves from multiple curves such that q-1 = cr and q+1 = ds, where r and s are prime numbers, and c and d are integer Cheon cofactors, such that cd ≤ 48.

Benefits of technology

It effectively improves the Cheon resistance of the static elliptic curve Diffie-Hellman cryptographic system, enhances its resistance to Cheon attacks, and thus improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114866238B_ABST
    Figure CN114866238B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method and system for Cheon-resistant static DIFFIE‑HELLMAN security. The method includes: providing a system for communicating messages between a pair of communicators, the messages being exchanged according to ECDH instructions executable on computer processors of the respective communicators, the ECDH instructions using a curve selected from a plurality of curves, the selection comprising: picking a range of curves; selecting a curve matching a threshold efficiency from the range of curves; excluding curves that may include intentional vulnerabilities within the selected curves; and selecting a curve with Cheon resistance from the selected curves that are not excluded, the selection comprising selecting a curve from an additive group of order q, where q is a prime number such that q‑1=cr, and q+1=ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd≤48.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application with the international filing date of February 14, 2017, international application number PCT / CA2017 / 050175, which entered the Chinese national stage on November 5, 2018, Chinese national application number 201780027865.9, and the invention title of "Method and System for Static Diffie-Hellman Security Against Cheon Resistance". Technical Field

[0002] The present disclosure relates to static groups in the field of cryptography. Background Art

[0003] Diffie-Hellman key exchange is a method for securely exchanging cryptographic keys over a public channel. In various systems, the protocol uses the multiplicative group of integers modulo p, where p is a prime number. The common value g is a primitive root modulo p and is raised to an exponent that is secret on each side of the cryptographic transaction. Due to the properties of the multiplicative group, the exchange of two primitive roots (each raised to the secret of one of the parties) can be combined to form a shared secret between the two parties. Due to the discrete logarithm problem, an eavesdropper cannot easily derive the shared secret.

[0004] Variants or special cases of Diffie-Hellman key exchange utilize elliptic curve cryptography (ECC). In ECC, the group is not the multiplicative group of a finite field, but a subgroup of an elliptic curve. The use of elliptic curves allows for a smaller group size than the multiplicative group to achieve the same security level.

[0005] In some forms of Diffie-Hellman key exchange, a party can reuse the secret value multiple times. This practice can be referred to as static Diffie-Hellman. JungHee Cheon found in the paper "Security analysis of the strong Diffie-Hellman problem." Advances in Cryptology-EuroCrypt 2006, LNCS 4004, pg. 1, Springer, 2006 (which is incorporated herein by reference) that in the group size q, if q - 1 or q + 1 has a factor of a certain size, the static Diffie-Hellman problem is actually much easier than the best-known attacks on the Diffie-Hellman problem. In particular, the Cheon algorithm involves an adversary picking various points Q and seeing the shared secret xQ by having the first participant apply the static private key x to Q. This Cheon attack makes the Diffie-Hellman protocol less secure. Brief Description of the Drawings

[0006] The present disclosure will be better understood with reference to the accompanying drawings, in which:

[0007] Figure 1 is a block diagram showing participants using a cryptographic module to exchange information;

[0008] Figure 2 is a data flow diagram showing the establishment of a shared secret in an elliptic curve Diffie-Hellman system;

[0009] Figure 3 is a process diagram showing the process of selecting a Cheon-resistant curve;

[0010] Figure 4 is a data flow diagram showing the establishment of a shared secret in an elliptic curve Diffie-Hellman system using specific criteria; and

[0011] Figure 5 is a block diagram of a simplified computing device capable of implementing embodiments of the present disclosure. Detailed Description

[0012] The present disclosure provides a method for providing Cheon-resistant security for a static elliptic curve Diffie-Hellman cryptographic system (ECDH), the method comprising: providing a system for message communication between a pair of communicators, the messages being exchanged according to ECDH instructions executable on a computer processor of the respective communicator, the ECDH instructions using a curve selected from a plurality of curves, the selection comprising: picking a range of curves; selecting a curve from the range of curves that matches a threshold efficiency; excluding curves within the selected curve that may include intentional vulnerabilities; and selecting a curve with Cheon resistance from the non-excluded selected curves, the selection comprising selecting a curve from an additive group of order q, where q is a prime number such that q - 1 = cr and q + 1 = ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd ≤ 48.

[0013] The present disclosure further provides a method for providing Cheon-resistant security for a static elliptic curve Diffie-Hellman cryptographic system (ECDH), the method comprising: providing a system for message communication between a pair of communicators, the messages being exchanged according to ECDH instructions executable on a computer processor of the respective communicator, the ECDH instructions using a curve comprising the following: an additive group of order q, where q is a prime number such that q - 1 = cr and q + 1 = ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd ≤ 48; of the form y 2 = x3 The affine equation of y = x^3 + ix, where The length is 454 bits; the field size p = 2 454 +(3 x 17 x 11287) 2 ; the order q = 2 452 +(7 x 41117) 2 ; r = (q – 1) / 8; and s = (q + 1) / 6.

[0014] The present disclosure further provides a computing device for providing Cheon-resistant security for a static Elliptic Curve Diffie-Hellman cryptosystem (ECDH). The computing device includes a processor for executing program instructions, and the processor is configured to: provide a system for message communication between a pair of communicators, where the messages are exchanged according to ECDH instructions executable on the computer processors of the respective communicators, and the ECDH instructions use a curve selected from a plurality of curves. The selection includes: picking a range of curves; selecting a curve from the range of curves that matches a threshold efficiency; excluding curves within the selected curve that may include intentional vulnerabilities; and selecting a curve with Cheon resistance from the non-excluded selected curves. The selection includes selecting a curve from an additive group of order q, where q is a prime number such that q - 1 = cr and q + 1 = ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd ≤ 48.

[0015] The present disclosure further provides a computing device for providing Cheon-resistant security for a static Elliptic Curve Diffie-Hellman cryptosystem (ECDH). The computing device includes a processor for executing program instructions, and the processor is configured to: provide a system for message communication between a pair of communicators, where the messages are exchanged according to ECDH instructions executable on the computer processors of the respective communicators, and the ECDH instructions use a curve including the following: an additive group of order q, where q is a prime number such that q - 1 = cr and q + 1 = ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd ≤ 48; in the form of y 2 = x 3 ^3 + ix, where The length is 454 bits; the field size p = 2 454 +(3 x 17 x 11287) 2 ; the order q = 2 452 +(7 x 41117) 2 ; r = (q – 1) / 8; and s = (q + 1) / 6.

[0016] Now refer to Figure 1, which shows a system 10 for message communication between a pair of communicators. Specifically, in Figure 1 , a pair of communicators A and B are connected by a data communication link 12. Each of communicators A and B has a cryptographic module or unit 14 that performs public-key cryptographic operations according to an established protocol to allow secure communication through link 12. The cryptographic unit 14 operates within a cryptographic domain, and the parameters of the cryptographic domain are shared by other entities.

[0017] In one example, communicators A and B utilize Diffie-Hellman (DH) key exchange. Specifically, the Diffie-Hellman key exchange uses an abelian group, which is an algebraic system with a binary operation and that obeys certain axioms.

[0018] The group originally proposed by Diffie and Hellman is called the multiplicative group of the finite field of size p, where p is a prime number. Using such a multiplicative group, the set of numbers {1, 2,..., p - 1} can have a binary operation defined as multiplication modulo p, which means multiplication after computing the remainder after division by p. This group is well-known mathematically and was applied by Diffie and Hellman to cryptography.

[0019] For illustrative purposes, consider the small prime number p = 5. The binary operation, multiplication modulo p for this group can be represented in the following table:

[0020]

[0021] Table 1: Binary operation, multiplication modulo 5

[0022] In this group, we have, for example, 2 × 4 = 3. Specifically, the normal multiplication 2 × 4 = 8, but in this group, the remainder is computed modulo 5, which gives 3 since 8 = 1 × 5 + 3.

[0023] For any element g of the group and some positive integer x, we can define g by applying the binary operation between x copies of g x . This operation is called exponentiation of the group, and g is called the base, and x is called the exponent. In the case where the group is the multiplicative group of a finite field, exponentiation of the group is also called modular exponentiation.

[0024] Thus, for illustration, let p = 5, as shown in Table 1 above. If g = 2 and x = 6, then in modular exponentiation, g x = 2 6 = 4. This is because, under normal exponentiation, 2 6 = 64 and the remainder of 64 modulo 5 is 4.

[0025] Even when close to 2 256In large groups, algorithms such as the square-and-multiply algorithm can also be used to perform group exponentiation very efficiently. This algorithm requires at most log 2 (x) group operations to compute g x ^x. In groups of size 2 256 ^128, group exponentiation employs 512 or fewer group operations, which is generally practical.

[0026] The discrete logarithm is the inverse of group exponentiation. If y = g x ^x, then the discrete logarithm of y with base g is x. Computing the discrete logarithm is a "hard" problem in some groups. The difficulty of this problem is crucial for the security of Diffie-Hellman key exchange and related public-key cryptography algorithms, which is known as the discrete logarithm problem (DLP). "Hard" is a term in cryptography and generally means, as used herein, that it must be beyond the capabilities of an adversary and must prevent the system from being broken as long as the security of the system is considered important. Mathematically, the term may mean that the solution to the problem is not solvable in asymptotic polynomial time.

[0027] Thus, public-key cryptography depends on the DLP being hard.

[0028] Referring again to Figure 1 , in the Diffie-Hellman key exchange, contributor A generates a secret exponent x, and contributor B generates a secret exponent y. A sends A = g x ^x to B, and B sends B = g y ^y to A. Contributor A computes z = B x ^x and contributor B computes w = A y ^y. Since z = g xy ^(xy) = w, the computed values are equal, so both contributors compute the same shared value w = z.

[0029] For groups in which the discrete logarithm problem is hard, it is generally considered difficult for an adversary E to compute z and w from g, A, and B. This problem is now called the Diffie-Hellman problem (DHP). The DHP can be solved by solving the DLP: Given A = g x ^x, find x by solving the DLP, and then compute B x ^x by group exponentiation to solve the DHP, since w = z = B x ^x. Thus, the DHP is no harder than the DLP. The DHP may be easier than the DLP, but in some cases, the DLP can be solved by solving the DHP, although the transformation may be more costly.

[0030] The above is the basic general form of the Diffie-Hellman key exchange.

[0031] After describing the Diffie-Hellman key exchange, ElGamal introduced a method of using the same Diffie-Hellman group for digital signatures, which allows contributors A and B to be confident in each other's messages. ElGamal also clarified that the Diffie-Hellman key exchange can be used to construct a public-key encryption scheme. In one example, contributor B can use a fixed Diffie-Hellman private key, while contributor A can use an ephemeral private key, which has only one key for each message it wishes to send to contributor B.

[0032] Elliptic Curve Cryptography

[0033] Elliptic Curve Cryptography (ECC) can be regarded as a special case of the Diffie-Hellman system for public-key cryptography.

[0034] In ECC, the group is not the multiplicative group of a finite field, but a subgroup of an elliptic curve. As mentioned above, one reason for using ECC is that for groups of the same size, the DLP in ECC is harder than the DLP in classical DH groups. This allows smaller groups to be used for the same security level. Although the use of elliptic curve (EC) groups is slower than the use of finite field (FF) groups of the same size, since EC groups can be much smaller for the same security level, they can have a similar speed to FF groups of the same security.

[0035] Generally, a curve is any set of one-dimensional points. An algebraic curve is defined by a polynomial equation. A plane curve is a curve embedded in a plane. A simple example of a plane algebraic curve is a circle in the (x, y) plane with the equation x 2 +y 2 = 1.

[0036] According to the mathematical theory called algebraic geometry, each curve has a number called its genus. Genus 0 curves include straight lines, circles, ellipses, parabolas, and hyperbolas. Generally, genus 0 curves are any curves whose points can be reversibly transformed into numbers using only rational functions in both directions of the transformation. For example, by mapping the point (x, y) to the number w = y / (x + 1), the circle has genus 0. This mapping can be inverted by (x,y) = ((1–w 2 ) / (1+w 2 ),2w / (1+w 2 ).

[0037] Therefore, genus 0 curves can have only components in the real (x, y) plane. Although hyperbolas seem to have two components, these components are connected to the projection line in the extended part of the plane, which considers the asymptotes to act like points at infinity.

[0038] The simplest curve class after genus 0 curves is genus 1 curves. These are also traditionally called elliptic curves because they originated from measuring the arc length of ellipses.

[0039] The simple form of an elliptic curve is a plane cubic curve. A plane cubic curve is a curve defined by a cubic equation in the plane. A small class of cubic curves has genus 0, and these exceptions are called singular cubic curves. Otherwise, most cubic plane curves have genus 1.

[0040] The traditional form of the cubic equation for an elliptic curve is the Weierstrass cubic, which includes equations such as y 2 = x 3 + ax + b, where a and b are fixed numbers, and (x, y) are the coordinates of a point in the plane.

[0041] Other types of cubic equations are also of interest for research and can be useful in ECC.

[0042] The theory of algebraic geometry defines a group on the set of points of an elliptic curve. More generally, each curve has an associated group, called its Jacobian group. For genus 0 curves, the size of the group is 1, so it is not very interesting or useful for cryptography. For genus 2 or higher curves, the groups are very complex, but these groups have been considered for use in cryptography.

[0043] The Jacobian group of a plane cubic curve is defined as follows. The point O is fixed as the group identity. By convention, this elliptic curve is written using addition as the binary operation. So, instead of writing xy for the group operation applied to group elements x and y, we write X + Y for group elements X and Y.

[0044] To add points X and Y, form the line L passing through X and Y. If X and Y are the same point, pick the line tangent to the curve passing through X. Since the curve is cubic, this line intersects the curve at 0, 1, or 3 points, where a tangent counts as two points and an inflection point counts as 3 points.

[0045] Since the line L already intersects the curve at two points, it must intersect the curve at 3 points. Two of these points are X and Y, and the third is the point Z.

[0046] The same process can be carried out on another point O and Z to obtain another point, which is used as the definition of X + Y.

[0047] Since elliptic curves are traditionally written using addition instead of multiplication for their group operations, the previous terminology and notation for DH groups can be adjusted. Writing g xThe previous group exponentiation operation is now called scalar multiplication and is written as xG. Additionally, the discrete logarithm is sometimes called the "elliptic curve discrete logarithm problem" (ECDLP) to avoid confusion with discrete logarithm problems in other groups.

[0048] Elliptic curve Diffie-Hellman (ECDH) groups used in cryptography represent the coordinates of points over a finite field. Thus, both finite field Diffie-Hellman groups (FFDH groups) and ECDH groups use finite fields. In FFDH groups, the group elements are non-zero finite field elements. In ECDH groups, the group elements are typically a pair of finite field elements that together satisfy a cubic equation. The finite field used in ECDH groups is often called the base field of the curve and the ECDH group. In some embodiments, the term domain of definition is also used.

[0049] As mentioned above, one advantage of ECDH groups is that the discrete logarithm problem seems to be harder for group sizes than FFDH groups. Thus, if we pick ECDH groups and FFDH groups where the discrete logs are roughly the same difficulty and too hard to solve for any practical algorithm, then generally the ECDH group will be faster for users.

[0050] One of the main reasons that FFDLP is easier than ECDLP is that FFDH groups have a better notion of element size. These notions of size in FFDLP allow discrete logarithms by breaking large elements into combinations of smaller elements, and the discrete logarithms of the smaller elements are easier to find. This general strategy for solving FFDLP is sometimes called index calculus or sieving. No efficient index calculus algorithms have been found for typical elliptic curve groups.

[0051] In most ECDH groups, the best-known algorithm for computing discrete logarithms is the generic group algorithm. The generic group algorithm applies to any group and simply uses the group operations as a black box. The speed of the generic group algorithm for computing discrete logarithms is limited. Specifically, if the group has size divisible by a prime n, then computing the discrete logarithm with the generic group algorithm requires at least approximately n 1 / 2 groups.

[0052] Some rare cases of elliptic curves have discrete logarithms that are easier to solve. These can be solved using the Menezes, Okamoto, Vanstone (MOV) attack and the Satoh, Araki, Semaev, Smart (SASS) attack. These rare cases can be easily detected, and the standards for ECC explicitly avoid attacks on these special cases.

[0053] In addition to the difficult discrete logarithm problem, secure ECC needs to avoid side-channel attacks. Side channels can occur when the implementation of ECDH and other algorithms leaks additional information, such as information about communicators A and B.

[0054] In static Diffie-Hellman, as described below, security against side channels is desired. This is defined as follows. Assume that communicator A has a secret key m and a static DH module that computes mP for any input P in a given static Diffie-Hellman security group. Further assume that the module leaks absolutely no other information about m (so the module has no side channels or computes signatures without m). In this case, communicator A can use the module in any protocol set without exposing m. Additionally, even if the protocols are insecure and they may compromise each other, they do not expose m.

[0055] It is noted that implementing such ECDH without side channels is required. In some embodiments, it is found that certain algorithms are easier to implement without side channels, and one such algorithm is the Montgomery ladder.

[0056] An efficient form of the Montgomery ladder uses an equation of the following form: by 2 = x 3 + ax 2 + x.

[0057] The above equation is cubic and generally defines an elliptic curve. The above Montgomery ladder equation is not common in the Weierstrass equation and has not historically been preferred for the mathematical treatment of elliptic curves because it is slightly less general than the Weierstrass equation.

[0058] In elliptic curve cryptography, the equation is defined over a finite field, rather than over the usual numbers on the real line. Typically, the finite field is a prime field and has integers modulo a prime p. This helps ensure that points in the group are easily represented in a finite amount of information and also helps ensure that the discrete logarithm problem is difficult.

[0059] Most of the efficiency of ECC users depends on the choice of p because the algorithm involves computing remainders modulo p. By picking p close to a power of two or other special forms, the speed of ECC in software almost doubles compared to a random prime p.

[0060] For example, the use of ECDH is provided to obtain a shared secret on a public connection. Now refer to Figure 2 .

[0061] In Figure 2In this case, communicator A and communicator B wish to communicate securely over a common channel 12. Communicators A and B agree to use Elliptic Curve Diffie-Hellman to obtain a shared secret for communication.

[0062] Specifically, communicator A can select the curve and parameters and transmit them to communicator B to ensure the use of the same curve among the parties.

[0063] In addition, each of communicators A and B has a secret integer value, which can be considered as the private key of each communicator. Thus, communicator A has the secret integer m, while communicator B has the secret integer n.

[0064] The shared parameters can include p, which is a prime number indicating the order of the field F p The parameters a and b are values from the Weierstrass equation y 2 = x 3 + ax + b. The parameters further include a group generator G of order q.

[0065] Referring again to Figure 2 , at the start of the session, communicator A sends the parameters p, a, b, G, q to communicator B in message 212. Message 212 further includes the value mG, which can be considered as the public key for communicator A.

[0066] Communicator B receives message 212 and extracts the parameters. Then, communicator B provides back to communicator A in message 220 the value nG, which can be considered as the public key of communicator B.

[0067] Communicator B further uses the curve with its private key and the public key of communicator A to calculate the shared secret nmG.

[0068] Similarly, communicator A uses the curve with its private key and the public key of communicator B to calculate the shared secret mnG.

[0069] Since nmG = mnG, communicators A and B now have a shared secret.

[0070] Eavesdropper 230 can see all the communications between communicators A and B. Thus, eavesdropper 230 will know the curve parameters and the public keys mG and nG. However, due to the discrete logarithm problem, the eavesdropper will not be able to calculate the shared secret nmG.

[0071] This disclosure relates to the determination of curves and curve parameters.

[0072] Point counting

[0073] One of the main challenges in selecting an elliptic curve group for a cipher is determining its size. While Elliptic Curve Diffie-Hellman (ECDH) can operate without knowing the size of the group, due to the Pohlig-Hellman and Pollard rho algorithms, its security depends on the largest prime factor of the group size. In particular, using ECDH with a group of unknown size n carries the risk that the largest prime factor of n is too small.

[0074] Other cryptographic applications of elliptic curve groups, such as digital signatures, may require direct knowledge of the group size to function properly.

[0075] Schoof-Elkies-Atkin (SEA) is a general method for determining the size of an elliptic curve group. Using the SEA method to count the number of points on a random elliptic curve over a finite field of the size required for a secure cipher typically takes within one second for a 256-bit curve and within one minute for a larger curve over a 512-bit field.

[0076] Based on this, point counting is practical unless a very large number of elliptic curves need to be tried to meet strict criteria. However, in the embodiments described herein, curves are sought that need to meet very strict criteria. These rather strict criteria may mean that millions of curves need to be tried and one million minutes is approximately two years.

[0077] Some elliptic curves over a finite field are special in the sense that their fundamental discriminant D has a small value. The fundamental discriminant is the number that relates the size n of the curve to the size p of the underlying field. Such curves are typically described as having complex multiplication (CM) and are called CM curves. CM curves are rare, and typically random curves have very large discriminants D.

[0078] Knowing p and D allows one to quickly determine n. Additionally, if D is small, curves with fundamental discriminant D can be found. This is part of complex multiplication.

[0079] One form of the CM method is to fix p and try various small Ds until a curve with suitable properties is found. Searching using the CM method is much faster than searching using the SEA method.

[0080] Another variant of the CM method fixes D to a very small value, in which case finding a curve is trivial. Then the method searches for different possible values of p. This method is faster because it avoids the slowest step of the previous CM method, which is finding a curve from various small Ds. The main drawback of this method is that various p values need to be considered.

[0081] The embodiments described herein utilize the above method with fixed D and varying p. Since the method is fast, it can be used to find curves that meet very strict criteria.

[0082] Static Diffie-Hellman problem

[0083] In some forms of Diffie-Hellman key exchange, communicator A will reuse the secret value multiple times. This practice can be referred to as static Diffie-Hellman.

[0084] Examples of static Diffie-Hellman include ElGamal encryption and its variant Elliptic Curve Integrated Encryption Scheme (ECIES), the recently proposed Optimal Layer Security (OPTLS) key negotiation algorithm for Transport Layer Security (TLS) 1.3, and the Ford-Kaliski cryptographic strengthening scheme.

[0085] Therefore, the static Diffie-Hellman problem is a variant of the general Diffie-Hellman problem where the adversary attempts to exploit the repeated reuse of the secret value.

[0086] Static Diffie-Hellman groups protect some cryptographic protocols against certain types of failures. Specifically, an additive group of order q is a static Diffie-Hellman group if there is no efficient algorithm that can use an oracle A for computing A(P) = aP (for any input P in the group) to find the function of the secret a for a uniformly random secret integer a ∈ {0, 1, 2,..., q - 1}. Quantitatively: if there is no algorithm that takes at most c group operations and makes at most o queries to the oracle A, then the group is (c, o, s) static Diffie-Hellman secure, with at least a success rate s in finding the secret a.

[0087] Diffie-Hellman group security is provided by three concepts. First, a discrete pair array is a group where the discrete logarithm problem (computing a from aP) is infeasible, and discrete logarithm security quantifies the difficulty of the problem.

[0088] Second, Diffie-Hellman security quantifies the difficulty of the Diffie-Hellman problem (computing abP from aP and bP), and Diffie-Hellman groups are those groups with a hard Diffie-Hellman problem.

[0089] Third, Diffie-Hellman group and security are defined similarly.

[0090] Cheon attack

[0091] As described above, the Cheon attack shows that if the group size q is such that q - 1 or q + 1 has a factor of a certain size, the static Diffie-Hellman problem is actually much easier than the best-known attacks against the Diffie-Hellman problem.

[0092] The Cheon algorithm involves the adversary picking various points Q and seeing the communicator A share the secret xQ by having the communicator A apply her static private key x to Q.

[0093] Some Diffie-Hellman protocols are thought to hinder the Cheon attack in arbitrary groups. The communicator A can, for example, apply a key derivation function to xQ to obtain a key k, and then the communicator A discards xQ. If the key derivation function is one-way, this may hinder the Cheon algorithm in practice. Nevertheless, it may be safer to rely on the Cheon algorithm being infeasible in the first place rather than relying on the key derivation function and the secure deletion of xQ.

[0094] In other words, picking groups in which the Cheon attack is infeasible provides a second layer of defense against the Cheon attack, where the first layer of defense would be the key derivation function itself.

[0095] In other cases, such as in the Ford-Kaliski cryptosystem, xQ can be public. However, for these groups, the need to resist the Cheon attack is much stronger.

[0096] Thus, according to an embodiment of the present disclosure, a Cheon-resistant curve is a curve with group size q such that both q - 1 and q + 1 avoid factoring conditions that would make the Cheon algorithm faster than Pollard rho.

[0097] Based on the above, the Cheon resistance is defined as follows. If q is prime, the additive group of order q is near-optimal Cheon-resistant, and for prime numbers r and s and integers c and d, q - 1 = cr and q + 1 = ds such that cd ≤ 48. The pair (c, d) is the Cheon cofactor of the group.

[0098] Above, the condition on the Cheon cofactor (c, d) is arbitrary and chosen for simplicity. In alternative embodiments, more complex definitions can be provided. For example, for each prime q, consider the best parameters of the Cheon algorithm. Let c be the cost c of the optimal version of the Cheon algorithm for a universal group of size q. Let q = log q (c). Now consider the set of candidate prime numbers q that may be suitable for implementing static Diffie-Hellman. For example, the set may be all prime numbers of a certain bit length. Let γ+ The maximum value of γ for all candidate values of q. Under certain definitions of a small upper bound for εq, an alternative definition of an almost-optimal Cheon-resistant group size q is γ q = (1 - ∈ q )γ q + . This alternative definition, while incomplete, is already almost too complex for any practical application, so the above definition is simpler.

[0099] Breaking cryptographic algorithms

[0100] Another consideration in curve selection is to avoid cryptographic algorithms that are deliberately broken to be vulnerable to secret attacks. A known countermeasure against breaking cryptographic algorithms is to select algorithms with a very compact overall description. Compact algorithms tend to prevent the possibility of attackers modifying algorithm parameters through trial and error. In this case, the trial-and-error search may force relatively large weak parameters, so they are not as compact as more honest parameters. As used herein, "honest" means parameters or algorithms that are not specifically selected to be weak. This countermeasure is commonly referred to as "no silver bullet". Recently, it has been called "rigidity" with a slightly different meaning.

[0101] Thus, according to another embodiment of the present disclosure, compact algorithms are selected. Although selecting compact algorithms does not prevent all breakages, in some cases, the weakest algorithm versions have the smallest parameter values and are therefore more compact and more honest algorithm versions. The main countermeasure against this form is to correctly identify the weak versions of the algorithms. In other words, utilize traditional cryptanalysis. The second countermeasure is to prove the equivalence of any assumed attack over any value of the algorithm parameters.

[0102] Based on the above, given that Cheon-resistant curves are desired and some protocols need to rely on the security of the static Diffie-Hellman problem, the present disclosure provides elliptic curves that are more likely to have optimal static Diffie-Hellman security, subject to other characteristics of the curves.

[0103] Conversely, one does not want to sacrifice important properties of Diffie-Hellman, whether security or efficiency. Therefore, the challenge lies in improving the evidence of Cheon resistance of the static Diffie-Hellman group without affecting other characteristics.

[0104] According to an embodiment of the present disclosure, a very specific set of criteria can be established to address the main defect proposed by most other elliptic curve proposals, namely the risk of a weak static Diffie-Hellman problem.

[0105] ​In particular, there are various criteria for both the security and efficiency of elliptic curves. These include resistance to common elliptic curve attacks such as: large bit lengths to resist Pollard rho attacks; small cofactors to resist Pohlig-Hellman attacks; high embedding degrees to resist MOV attacks; the order of the curve not being equal to the order of the field to resist SASS attacks; and cofactors divisible by 4 for better side-channel resistance and efficiency.

[0106] However, these basic criteria do not address the risk of the weak static Diffie-Hellman problem. Accordingly, additional criteria are added to the above basic criteria according to the present disclosure, and in order to achieve strong static Diffie-Hellman security, Cheon's attack is resisted almost optimally for bit lengths.

[0107] Since Cheon-resistance is an advanced security property, the present disclosure provides an emphasis on security rather than efficiency. Thus, according to the present disclosure, instead of selecting the most efficient or the smallest sufficiently secure curve, a range of more secure or larger sufficiently efficient curves are considered. Among these curves, the following criteria are utilized to seek efficiency: sufficiently small bit lengths are practical; relatively efficient for bit lengths, including field sizes close to powers of two and efficient endomorphisms.

[0108] Furthermore, according to embodiments of the present disclosure, some effort or a byproduct of the above criteria is applied to address the problem of deliberately vulnerable cryptographic algorithms. These factors include the factor of curve compactness. In particular, the parameters of all curves are compact and can be represented in a compressed form. Additionally, the curve is compact by ensuring that the curve has not been maliciously manipulated.

[0109] These vulnerabilities are addressed by being easy to generate and regenerate. Thus, according to the embodiments described below, it only takes a few seconds to check each candidate curve on an older PC model rather than months on a server cluster.

[0110] According to the above, in one embodiment, an elliptic curve providing approximately optimal Cheon-resistance has complex multiplication by i indicating superior Boneh-Boyen static Diffie-Hellman security and allows a Bernstein ladder with a 454-bit length, referred to herein as Crib454. However, this curve is merely an example, and the principles described herein can be applied to find other curves that match the described criteria.

[0111] The criteria for Crib454 are based on security and efficiency as described below.

[0112] The CRIB454 curve is described using the following criteria:

[0113] p = 2 454 +(3 x 17 x 11287) 2

[0114] q = 2 452 +(7 x 41117) 2

[0115] r = (q - 1) / 8

[0116] s = (q + 1) / 6

[0117] The above criteria are possible prime numbers.

[0118] In addition, an elliptic curve with an affine equation is defined as: y 2 = x 3 + ix.

[0119] The above curve has n = 4q points on a field F of size p p , including the point at infinity. Generally, i ≡ (-1) 1 / 2 mod p. In this regard, i ≡ 2 227 / (3 × 17 × 11287) mod p.

[0120] The above criteria provide an example of a curve that can be used according to the present disclosure. Other curves based on the factors provided below can also be used.

[0121] For ease of generation, efficiency, and compactness, specific criteria require complex multiplication (CM). In addition, the complex multiplication of i is selected because this multiplication provides a very efficient endomorphism and matches the cofactor 4 criterion. Alternative linear endomorphism curves have complex multiplication of the cube root of unity, but they have a cofactor of 3, which may be less desirable.

[0122] Although it has been proposed in the art that curves with complex multiplication are risky, no attack on CM curves has been achieved in 30 years, which provides strong evidence that CM curves are as good as non - CM curves. In fact, two reasons why CM curves may provide better security than non - CM curves include, first, an efficient endomorphism allows the use of larger curves, which increases the difficulty of known attacks at a given efficiency level and may provide a margin of error for a mild attack on CM. In this case, a mild attack is only slightly better than the Pollard rho attack.

[0123] Secondly, CM curves belong to a special class of curves that may avoid some problems of most non-CM curves. For example, considering the resistance to the Pohlig-Hellman attack, it is strongest for a special type of approximate prime (low cofactor) DH group. There are other examples to show that special curves may be safer than non-CM curves.

[0124] Over a given prime finite field, there are only a few elliptic curves, up to isogeny, with complex multiplication by i. Some of these have cofactors divisible by 8 and should thus be avoided. This usually corrects the curve equation, up to isogeny.

[0125] For Cheon-resistant security, embodiments of the present disclosure attempt to select a nearly optimal Cheon resistance relative to the curve size, as this can be regarded as the strongest evidence of having strong static Diffie-Hellman security. To achieve this nearly optimal Cheon resistance, the Cheon cofactor is then defined to be almost minimal. In the notation of Crib454, the selected Cheon cofactors are 8 and 6, since r = (q - 1) / 8 and s = (q - 1) / 6. Above, the order of the group is prime q, and r and s are primes related to q.

[0126] The specific Cheon cofactor pair (8, 6) is selected instead of (1, 1) or (6, 8) or (2, 24) for two reasons. First, due to the divisibility properties of the numbers involved, some pairs like (1, 1) are not possible. In fact, the product of the numbers in the pair should be divisible by 12, since the product of two numbers adjacent to any prime greater than or equal to 5 is divisible by 12.

[0127] Specifically, if q is such a prime, then either q - 1 or q + 1 must be divisible by 3. Both q - 1 and q + 1 are even, and one must be divisible by 4.

[0128] Secondly, a prime p of a special form is chosen, which is the size of the base field. Specifically, the special form is a quasi-Fermat prime, as this form allows for reasonably good efficiency in its size. This special form means that the first Cheon cofactor can be divisible by 8, and the product of the Cheon cofactors can be divisible by 48.

[0129] The general criterion for p is that it is simple, compact, and efficient. The specific criterion is that p is a power of two plus or minus a small number. In some embodiments, the smaller the number, the better. p being a power of two plus or minus a small number makes p very simple, compact, and efficient. The specific criterion for p being a quasi-Fermat prime, which is a power of two plus a small number (not negative), seems to be imposed by an abbreviated form of the CM method.

[0130] The abbreviated form of the CM method is another criterion. In this form of the CM method, the usual step of determining q from p via the Cornacchia algorithm is replaced by a simpler formula, where both p and q are computed from some given integers. The abbreviated method is faster than the usual CM method because it avoids the Cornacchia's algorithm, which helps with the reproducibility of the method.

[0131] The abbreviated method also results in a more compact form of p and q, which helps argue that the curve has not been manipulated because it lacks any randomly observed parameters.

[0132] The last specific criterion is to define how to measure the proximity to a power of two. For this, a simple and natural rule is picked. Instead of using the absolute difference as a measure of proximity, the relative difference is used. Specifically, the relative difference is the absolute difference divided by the exponent to the power of two.

[0133] For example, in Crib454, p = 2 454 +(3×17×11287) 2 , so the relative difference is (3×17×11287) 2 / 454. The relative difference is more natural than the absolute difference because of the prime number theorem, which gives a heuristic prediction of the probability of a number being prime. Under this heuristic, the rarity of primes is a function of the relative difference, not the absolute difference.

[0134] The proximity to a power of two is the last one and thus given the lowest priority among the criteria. Thus, the other criteria are determined first, but all the previous criteria can be represented in the formula. Thus, it just performs calculations, mostly consisting of primality tests. This generates a list of candidate curves. Among the suitable curves, the one with the smallest relative difference is selected.

[0135] A computer algorithm for performing the above is provided in Appendix A. The computer code in Appendix A verifies the Crib454 criterion, but can be easily adjusted by those skilled in the art to produce other curves that satisfy the above criteria.

[0136] In addition, reference can be made to Figure 3 to summarize the above. Specifically, Figure 3 A flowchart showing the derivation of a curve with near-optimal Cheon resistance is shown.

[0137] Figure 3 The process of starts at box 310 and proceeds to box 312, where a range of curves are picked. Specifically, the size of the curve can be determined at box 312 to meet the minimum security requirements for ECDH applications.

[0138] From block 312, the process proceeds to block 320, where the range of curves from block 312 is further reduced to select curves with a threshold efficiency. In particular, the selected curves as described above should be small enough to be practical. Additionally, the domain size should be close to a power of two. Further, the selection at block 320 should limit the curves to those that exhibit effective endogeny.

[0139] From block 320, the process proceeds to block 330, where the curves selected at block 320 are further reduced to eliminate curves that may exhibit vulnerability. In particular, at block 330, the selected curves are reduced to those that are compact and not vulnerable to malicious manipulation. Additionally, the curves are reduced to those that are easy to generate.

[0140] Starting from block 330, the process proceeds to block 340, where Cheon resistance is ensured by ensuring that the curves avoid factoring conditions that would make the Cheon algorithm faster than Pollard rho.

[0141] Then, the process proceeds to block 350 and ends.

[0142] Using the Crib454 parameters above, now refer to Figure 4 . Specifically, Figure 4 illustrates an Figure 2 embodiment where the general parameters of the curve specifically replace the Crib454 parameters.

[0143] Thus, Communicator A communicates with Communicator B over a secure channel. In an Figure 4 embodiment, Communicator A sends message 412, which includes p = 2 454 +(3x17x11287) 2 and q = 2 452 +(7x41117) 2 . Additionally, a = i and b = 0. G is any fixed point on the curve as long as it has order q.

[0144] Communicator A further sends the public key mG in its message 412 to Communicator B. However, in other embodiments, the public key may be sent in a subsequent message.

[0145] Communicator B sends its public key nG to Communicator A in message 420.

[0146] At this point, due to the curve parameters and the public keys, each of Communicators A and B can compute the shared secret, while eavesdropper 430 cannot compute the shared secret due to the discrete logarithm problem. Additionally, due to the Cheon resistance built into the curve parameters, eavesdropper 430 will not be able to use the Cheon attack.

[0147] The above can be implemented using any computing device. For example, regarding Figure 5 a simplified computing device is provided.

[0148] In Figure 5 device 510 includes a processor 520 and a communication subsystem 530, where the processor 520 and the communication subsystem 530 cooperate to execute the methods of the above embodiments.

[0149] The processor 520 is configured to execute programmable logic, which can be stored on the device 510 together with data, and is shown as a memory 540 in the example of Figure 5 The memory 540 can be any tangible, non-transitory computer-readable memory medium. The computer-readable storage medium can be a tangible or transient / non-transient medium, such as optical (e.g., CD, DVD, etc.), magnetic (e.g., tape), flash drive, hard disk drive, or other memories known in the prior art.

[0150] Alternatively, or in addition to the memory 540, the device 510 can access data or programmable logic from an external storage medium, for example, through the communication subsystem 530.

[0151] The communication subsystem 530 allows the device 510 to communicate with other devices or network elements.

[0152] In one embodiment, the communication between the various elements of the device 510 can be through an internal bus 560. However, other forms of communication are also possible.

[0153] The structures, features, appendages, and alternatives of the specific embodiments described herein and shown in the drawings are intended to generally apply to all teachings of the present disclosure, including all embodiments described and illustrated herein, as long as they are compatible. In other words, unless otherwise stated, the structures, features, appendages, and alternatives of a specific embodiment are not intended to be limited to that specific embodiment.

[0154] In addition, those skilled in the art will understand other features and advantages of the present disclosure.

[0155] The embodiments described herein are examples of structures, systems, or methods having elements corresponding to the elements of the technology of the present application. This written description can enable those skilled in the art to manufacture and use embodiments having alternative elements that also correspond to the elements of the technology of the present application. Therefore, the intended scope of the technology of the present application includes other structures, systems, or methods that are not different from the technology of the present application described herein, and also includes other structures, systems, or methods that do not have a substantial difference from the technology of the present application as described herein.

[0156] Appendix A

[0157] Code for generating CRIB454

[0158] / / strong_ecdh.cc

[0159] / / Dan Brown

[0160] / / 2015-August-25

[0161] / / Compile using:

[0162] / / g++-O3 strong_ecdh.cc-lntl

[0163] / / Try to find triples(t,z,u)with u=+ / -1,such that the following

[0164] / / numbers:

[0165] / / p=2^(2t)+(12z+2u+1)^2

[0166] / / q=2^(2t-2)+(6z+u)^2

[0167] / / r=(q-1) / 8

[0168] / / s=(q+1) / 6

[0169] / / are prime.(If t,z,u are integers and t>=3,then p,q,r,s are

[0170] / / integers.)

[0171] / / Note t-1loosely corresponds to"security level"

[0172] / / Like t>=127for sufficient DH security.

[0173] / / Like t<=300for practical DH performance.

[0174] / / Look at smaller and larger t just for completeness.

[0175] / / For efficiency, make |z| as small as possible.

[0176] / / Try |z| < t^d for d = 1, 2, 3, 4, getting successively more hits.

[0177] #include<NTL / ZZ.h>

[0178] using namespace std;

[0179] using namespace NTL;

[0180] / / T_MAX is the maximum size of t, a constant

[0181] / / Z_ABS is the maximum size |z|: e.g., an expression in t

[0182] #if 0

[0183] #elif 1 / / Crib454 is the only non - trivial hit

[0184] / / Slowly test for medium |z|

[0185] / / Found Crib454 in ~4sec on old PC

[0186] #define Z_ABS t*t / /

[0187] #define T_MAX 400 / / Took ~30sec to 1.5min on old PC

[0188] / / 500 / / Took ~2 - 5min on old PC

[0189] / / Don't expect any non - trivial hits, since not enough z

[0190] / / Got five trivial hits plus

[0191] / / (t, z, u) = (227, -47970, 1)

[0192] / / yielding the interesting elliptic curve Crib454!

[0193] / / other test parameters given below...

[0194] #elif 0

[0195] / / Quickly test for smaller|z|,but larger t.

[0196] #define Z_ABS t

[0197] #define T_MAX / *1024 / / Took~10 sec on oldPC* / \

[0198] 3072 / / Took~7 min on old PC.

[0199] / / Don’t expect(m)any hits for non-trivial t.

[0200] / / Trivially small hits:

[0201] / / (t,z,y)=(3,2,1)--->(p,q,r,s)=(593,137,17,23)

[0202] / / (t,z,u)=(6,-2,-1)--->(p,q,r,s)=(4721,1193,149,199)#elif 0 / / Allowslightly larger|z|than for Crib454

[0203] #define Z_ABS 10*t*t / /

[0204] #define T_MAX 300 / / Took~1.5 min on old PC

[0205] / / new hit:(t,z,u)=(173,-125658,-1) 20

[0207] #elif 1

[0208] / / __SLOWLY__test for medium|z|

[0209] / /

[0210] / / !!!---very slow,eg>30min---!!!

[0211] / /

[0212] #define Z_ABS t*t*t

[0213] #define T_MAX 300 / / took~46min on old PC

[0214] / / Decent chance of a hit for each t.

[0215] / / Most interesting outputs: / / log_t(|z|)

[0216] / / (t,z,u)=(116,-1330894,1) / / 2.966

[0217] / / (t,z,u)=(159,-522010,1) / / 2.597

[0218] / / (t,z,u)=(161,-3559998,-1) / / 2.969

[0219] / / (t,z,u)=(173,-125658,-1) / / 2.278

[0220] / / (t,z,u)=(224,-2710302,-1) / / 2.737

[0221] / / (t,z,u)=(227,-47970,1) / / 1.987

[0222] / / (t,z,u)=(289,13349730,1) / / 2.895

[0223] #else

[0224] / / Sanity check:

[0225] #define Z_ABS t*t*t*t

[0226] #define T_MAX 128

[0227] #endif

[0228] / / Expect many hits...needto limit#per t.

[0229] / / Got 7 hits at t=32.

[0230] / / For<=256-bit field,the most interesting example:

[0231] / / (t,z,u)=(127,-10402698,-1)

[0232] / / Convert|z|bound into a string.

[0233] #define STRING_1(x)#x

[0234] #define STRING_2(x)STRING_1(x)

[0235] #define Z_STRING STRING_2(Z_ABS)

[0236] / / Following NTL style guide to use long instead of int.

[0237] bool five_or_more_test(long t, long z, long u)

[0238] {

[0239] / / for meaning of t,z,u,see comments in function mod_test.

[0240] / / uncomment this to remove sieving test...

[0241] / / return true; / / Much slower!

[0242] / / Sieving risks knocking trivially small t...

[0243] / / so let’s skip sieving for small t

[0244] if(t <= 15){

[0245] / / note r >= 2^(2t-5).

[0246] / / If t>20,then r>2^35

[0247] / / If t>15,then r>2^25

[0248] return true;

[0249] }

[0250] #define SIEVE_MAX ((sizeof(primes)) / (sizeof(long)))

[0251] const long primes[] = {

[0252] / / what is the most efficient set of primes to put here?

[0253] / / the savings are achieved by avoiding big integer math...

[0254] / / it’s silly to include the list of primes in the code

[0255] / / should instead generate them at a start-up.

[0256] / / it seems to make sense to sieve pretty far given the NTL

[0257] / / primality testing interface.Although NTL could try trial

[0258] / / division,which should not be significantly slower than the

[0259] / / stuff here,it will also do Miller--Rabin on one of p,q,r,s

[0260] / / before doing trial division on the others.

[0261] 5,7,

[0262] 11,13,17,19,23,29,31,37,41,43,47,

[0263] 53,59,61,67,71,73,79,83,89,97,

[0264] 101,103,107,109,113,127,131,

[0265] 137,139,149,151,157,163,167,

[0266] 173,179,181,191,193,197,199,

[0267] 211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,

[0268] 307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,

[0269] 401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,

[0270] 503,509,521,523,541,547,557,563,569,571,577,587,593,599,

[0271] 601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,

[0272] 701,709,719,727,733,739,743,751,757,761,769,773,787,797,

[0273] 809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,

[0274] 907,911,919,929,937,941,947,953,967,971,977,983,991,997,

[0275] / *The following does not help too much,except for larger t* /

[0276] 1009, 1013, 1019, 1021, 1031, 1033, 1039, 1049, 1051, 1061, 1063, 1069, 1087,

[0277] 1091, 1093, 1097, 1103, 1109, 1117, 1123, 1129, 1151, 1153, 1163, 1171, 1181,

[0278] 1187, 1193, 1201, 1213, 1217, 1223, 1229, 1231, 1237, 1249, 1259, 1277, 1279,

[0279] 1283, 1289, 1291, 1297, 1301, 1303, 1307, 1319, 1321, 1327, 1361, 1367, 1373,

[0280] 1381, 1399, 1409, 1423, 1427, 1429, 1433, 1439, 1447, 1451, 1453, 1459, 1471,

[0281] 1481, 1483, 1487, 1489, 1493, 1499, 1511, 1523, 1531, 1543, 1549, 1553, 1559,

[0282] 1567, 1571, 1579, 1583, 1597, 1601, 1607, 1609, 1613, 1619, 1621, 1627, 1637,

[0283] 1657, 1663, 1667, 1669, 1693, 1697, 1699, 1709, 1721, 1723, 1733, 1741, 1747,

[0284] 1753, 1759, 1777, 1783, 1787, 1789, 1801, 1811, 1823, 1831, 1847, 1861, 1867,

[0285] 1871, 1873, 1877, 1879, 1889, 1901, 1907, 1913, 1931, 1933, 1949, 1951, 1973,

[0286] 1979,1987,1993,1997,1999,2003,2011,2017,2027,2029,2039,2053,2063,

[0287] 2069,2081,2083,2087,2089,2099,2111,2113,2129,2131,2137,2141,2143,

[0288] 2153,2161,2179,2203,2207,2213,2221,2237,2239,2243,2251,2267,2269,

[0289] 2273,2281,2287,2293,2297,2309,2311,2333,2339,2341,2347,2351,2357,

[0290] 2371,2377,2381,2383,2389,2393,2399,2411,2417,2423,2437,2441,2447,

[0291] 2459,2467,2473,2477,2503,2521,2531,2539,2543,2549,2551,2557,2579,

[0292] 2591,2593,2609,2617,2621,2633,2647,2657,2659,2663,2671,2677,2683,

[0293] 2687,2689,2693,2699,2707,2711,2713,2719,2729,2731,2741,2749,2753,

[0294] 2767,2777,2789,2791,2797,2801,2803,2819,2833,2837,2843,2851,2857,

[0295] 2861,2879,2887,2897,2903,2909,2917,2927,2939,2953,2957,2963,2969,

[0296] 2971,2999,3001,3011,3019,3023,3037,3041,3049,3061,3067,3079,3083,

[0297] };

[0298] long index;

[0299] static long last_t = -1;

[0300] static long powers[SIEVE_MAX];

[0301] if (t != last_t) {

[0302] / / compute 2^(2t-4) modulo each prime in primes.

[0303] long prime;

[0304] if (t != 1 + last_t) {

[0305] / / do a full computation...

[0306] long t_reduced;

[0307] for (index = 0; index < SIEVE_MAX; index++) {

[0308] prime = primes[index];

[0309] / / reduce t by Fermat’s little theorem

[0310] t_reduced = (2 * t - 4) % (prime - 1);

[0311] / / compute power by repeated doubling...

[0312] / / for larger moduli, would need square and multiply

[0313] powers[index] = 1;

[0314] for (long i = 0; i < t_reduced; i++) {

[0315] powers[index] += powers[index];

[0316] powers[index] %= prime;

[0317] }

[0318] }

[0319] } else {

[0320] / / t == 1 + last_t;

[0321] / / just do an update of the last computation...

[0322] for (index = 0; index < SIEVE_MAX; index++) {

[0323] prime = primes[index];

[0324] / / double twice...

[0325] for (long i = 0; i < 2; i++) {

[0326] powers[index] += powers[index];

[0327] powers[index] %= prime;

[0328] }

[0329] }

[0330] }

[0331] last_t = t;

[0332] }

[0333] / / now powers[index] is 2^(2t - 4) mod primes[index].

[0334] for (index = 0; index < SIEVE_MAX; index++) {

[0335] long power = powers[index];

[0336] long prime = primes[index];

[0337] long tester;

[0338] / / check for small factors in 3s

[0339] / / recall 3s=2^(2t - 3)+1+3z(6z + 2u)

[0340] tester = 2 * power+1+3 * z*(6 * z + 2u);

[0341] if(0 == tester % prime){

[0342] return false;

[0343] }

[0344] / / check for small factors in 2*r

[0345] / / recall 2r=2^(2t - 4)+z(9z + 3u)

[0346] tester = power+z*(9 * z + 3u);

[0347] if(0 == tester % prime){

[0348] return false;

[0349] }

[0350] / / check for small factors in q

[0351] / / recall q=2^(2t - 2)+(6z + u)^2

[0352] tester = 4 * power+(6 * z + u)*(6 * z + u);

[0353] if(0 == tester % prime){

[0354] return false;

[0355] }

[0356] / / check for small factors in p

[0357] / / recall p=2^(2t)+(12z + 2u + 1)^2

[0358] tester = 16 * power+(12 * z + 2 * u + 1)*(12 * z + 2 * u + 1);

[0359] if(0 == tester % prime){

[0360] return false;

[0361] }

[0362] }

[0363] return true; / / sieving passed

[0364] }

[0365] bool mod_test(long t, long z, long u)

[0366] {

[0367] / / Quickly check p,q,r,s for small prime factors, without any big

[0368] / / integer math.

[0369] / / Primes 2 and 3 are special cases handled in this function,

[0370] / / because divisions by 2 and 3 are involved, we must work modulo

[0371] / / powers of 2 and 3.

[0372] / / Primes 5 and larger handled more systematically by a call to

[0373] / / another function.

[0374] / / Here are the definitions of p,q,r,s in terms of t,z,u.

[0375] / / p=2^(2t)+(12z+2u+1)^2

[0376] / / q=2^(2t-2)+(6z+u)^2

[0377] / / r=2^(2t-5)+z(9z+3u) / 2

[0378] / / s = (2^(2t - 3) + 1) / 3 + z(6z + 2u)

[0379] / / Ensure that p, q, r, s are odd.

[0380] / / Each of p, q, s is even + odd = odd. Only r must be checked.

[0381] / / We only need that z(9z - 3u) is not divisible by four.

[0382] / / Working mod 4, we see that we z(z + u) = 2 mod4. We know

[0383] / / it will be 0 or 2 (or -2 for %), so we eliminate 0.)

[0384] if (0 == (z * (z + u)) % 4) {

[0385] return false;

[0386] }

[0387] / / Second ensure that r and s are not divisible by 3.

[0388] / / Mod 3:

[0389] / / p = 1 + (2u + 1)^2 = 1 + (0 or 1) = 1 or 2

[0390] / / q = 1 + (1 or 2)^2 = 1 + 1 = 2

[0391] / / r = 2 + 0 = 2

[0392] / / So, p, q, r are not divisible by 3.

[0393] / / To handle s , we consider 3s mod 9, and check that it is 3 or 6,

[0394] / / or really that it is not 0.

[0395] / / Mod 9: 3s = 2^(2t - 3)+1 + 6uz.

[0396] / / we can compute(2^(2t - 3)+1)mod9 by table lookup.

[0397] if(0 == ((long[]){0, 6, 3}[t % 3]+6 * u * z) % 9){

[0398] return false;

[0399] }

[0400] / / Finally,let’s sieve modulo small primes.

[0401] return five_or_more_test(t, z, u);

[0402] }

[0403] long prime_test(long t, long z, long u)

[0404] {

[0405] ZZ p, q, r, s;

[0406] long y;

[0407] y = 6 * z+u;

[0408] / / to do:

[0409] / / insteadof calling power2_ZZ below,we should instead

[0410] / / re-use previous value and then double

[0411] / / also we shouldavoid the the /

[0412] / / these efficiencies are probably dominatedby the

[0413] / / cost of calling ProbPrime...so we defer them.

[0414] p = power2_ZZ(2*t)+(2*y + 1)*(2*y + 1);

[0415] q = power2_ZZ(2*t - 2)+y*y;

[0416] r = (q - 1) / 8;

[0417] s = (q + 1) / 6;

[0418] / / The modular tests and the form of y should ensure that the

[0419] / / divisions above are exact.

[0420] if(ProbPrime(s)&&ProbPrime(r)&&ProbPrime(q)&&ProbPrime(p)){

[0421] cout << "\r(t,z,u) = ("

[0422] << t << "," << z << "," << u << ")"

[0423] << "" << "\b\b\b\b\b\b\b" / / over - write "progress"

[0424] << "\t" / / since,tab does not over - write. ;

[0426] if(t >= 127){

[0427] cout << "probably generates q - strong ECDH parameters,\n";

[0428] }else{

[0429] cout << "too small,otherwise special...\n";

[0430] }

[0431] return 1;

[0432] }

[0433] return 0;

[0434] }

[0435] long test_t_z_u(long t, long z, long u)

[0436] {

[0437] / / first do some small-integer modular tests:

[0438] if (mod_test(t, z, u)) {

[0439] / / If the small integer tests pass, then do big-integer primality

[0440] / / tests:

[0441] return prime_test(t, z, u);

[0442] }

[0443] return 0;

[0444] }

[0445] long test_t_z(long t, long z)

[0446] {

[0447] long hits = 0;

[0448] hits += test_t_z_u(t, +z, +1);

[0449] hits += test_t_z_u(t, +z, -1);

[0450] if (z > 0) {

[0451] hits += test_t_z_u(t, -z, +1);

[0452] hits += test_t_z_u(t, -z, -1);

[0453] }

[0454] return hits;

[0455] }

[0456] int main()

[0457] {

[0458] long t, z, hits;

[0459] long t_max = T_MAX;

[0460] long t_min = (T_MAX > 128)? 3 : 126;

[0461] cout

[0462] <<"Looking for an elliptic curve with:\n"

[0463] <<"\n"

[0464] <<"1) complex multiplication by i,\n"

[0465] <<"enabling Gallant--Lambert--Vanstone speed-up.\n"

[0466] <<"Curve equation: y^2 = x^3 + ix.\n"

[0467] <<"\n"

[0468] <<"2) a special field size:\n"

[0469] <<"p = 2^(2t) + (12z + 2u + 1)^2, where u^2 = 1,\n"

[0470] <<"which may be more efficienct than a random field size.\n"

[0471] <<"\n"

[0472] <<"3) cofactor 4, a curve size of 4q, for prime,\n"

[0473] <<"q = 2^(2t - 4) + (6z + u)^2\n"

[0474] <<"which enables Montgomery and Edwards speed-ups.\n"

[0475] <<"\n"

[0476] <<"4) near-optimal Cheon-resistance:\n"

[0477] <<"r=(q - 1) / 8 and s=(q + 1) / 6.\n"

[0478] <<"are both prime.\n"

[0479] <<"\n" ;

[0481] cout

[0482] <<"Testing t with"<<t_min

[0483] <<"<=t<="<<t_max

[0484] <<"and|z|<="Z_STRING".\n";

[0485] for(t=t_min;t<=t_max;t++){

[0486] / / test each z

[0487] for(z=0,hits=0;(z<=Z_ABS)&&(hits<=4);z++){

[0488] hits+=test_t_z(t,z);

[0489] if(0==(z + 1)%100000){

[0490] / / did not check if cerr over - writes any cout hits:(

[0491] cerr<<"\r"<<"Progressed past t=="<<t

[0492] <<",|z|<="<<z<"";

[0493] }

[0494] }

[0495] / / Display current value of t

[0496] cerr<<"\r"<<"Progressed past t<="<<t

[0497] <<"";

[0498] }

[0499] cout << "\n" << "Done!" << "\n";

[0500] return 0;

[0501] }

Claims

1. A method for providing Cheon-resistant security of a static elliptic curve Diffie-Hellman (ECDH) cryptosystem, the method comprising: At a first computing device, selecting a curve for message communication between the first computing device and a second computing device, the selecting comprising: selecting a range of curves that have a threshold efficiency and no intentional holes; and Derivation of a curve having Cheon resistance from the selected range of curves, the derivation comprising derivation of a curve from an additive group of order q, wherein q is a prime number such that q-1=cr, and q+1=ds, wherein r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd≤48; selecting a private key for the first computing device; calculating a public key of the first computing device according to curve parameters of the Cheon-resistant curve and the private key of the first computing device; transmitting the curve parameters of the curve having Cheon resistance and the public key of the first computing device to the second computing device; receiving a public key of the second computing device; computing a shared secret based on the public key of the second computing device and the private key of the first computing device; and Communicating with the second computing device using the shared secret.

2. The method of claim 1, wherein the selecting comprises: A range of curves having lengths matching the threshold safety level is selected.

3. The method of claim 1, wherein the selecting comprises: Pick a curve with a domain size close to a power of two and with efficient endomorphisms.

4. The method of claim 1, wherein the selecting comprises: Exclude curves that are not compact or difficult to generate.

5. The method of claim 1, wherein the curve has the form y 2 =x 3 +ix is ​​the affine equation for The method of claim 5 , wherein the curve has a length of 454 bits.

7. The method according to claim 6, wherein the domain size of the curve is p=2 454 +(3×17×11287) 2 ; Order q = 2 452 +(7×41117) 2 ; r = (q–1) / 8; and s = (q+1) / 6.

8. A computing device for providing Cheon-resistant security of a static elliptic curve Diffie-Hellman (ECDH) cryptosystem, the computing device comprising a hardware processor for executing program instructions, the hardware processor being configured to: Selecting a curve for message communication between the computing device and a second computing device, the selecting comprising: Selecting a range of curves that have threshold efficiency and no intentional holes; as well as Derivation of a curve having Cheon resistance from the selected range of curves, the derivation comprising derivation of a curve from an additive group of order q, where q is a prime number such that q-1=cr, and q+1=ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd≤48; and Select a private key; Calculating a public key based on curve parameters of the Cheon-resistant curve and the private key; transmitting the curve parameters and the public key of the Cheon-resistant curve to the second computing device; receiving a public key of the second computing device; computing a shared secret based on the public key and the private key of the second computing device; as well as Communicating with the second computing device using the shared secret.

9. The computing device of claim 8, wherein the processor is configured to select for use a curve having a length that matches a threshold security level.

10. The computing device of claim 8, wherein the processor is configured to select for use a curve having a domain size close to a power of two and having efficient endomorphisms.

11. The computing device of claim 8, wherein the processor is configured to select by excluding curves that are non-compact or difficult to generate.

12. The computing device of claim 8, wherein the curve has a form y 2 =x 3 +ix is ​​the affine equation for 13. The computing device of claim 12, wherein the curve has a length of 454 bits.

14. The computing device according to claim 13, wherein the domain size of the curve is p=2 454 +(3×17×11287) 2 ; Order q = 2 452 +(7×41117) 2 ; r = (q–1) / 8; and s = (q+1) / 6.

15. A non-transitory computer readable medium storing instruction codes for providing Cheon-resistant security for a static elliptic curve Diffie-Hellman (ECDH) cryptosystem, the instruction codes, when executed by a processor of a first computing device, causing the first computing device to: Selecting a curve for message communication between the first computing device and the second computing device, the selecting comprising: Selecting a range of curves that have threshold efficiency and no intentional holes; as well as Derivation of a curve having Cheon resistance from the selected range of curves, the derivation comprising derivation of a curve from an additive group of order q, where q is a prime number such that q-1=cr, and q+1=ds, where r and s are prime numbers, and c and d are integer Cheon cofactors of the group such that cd≤48; and Select Private Key; Calculating a public key based on curve parameters of the Cheon-resistant curve and the private key; transmitting the curve parameters and the public key of the Cheon-resistant curve to the second computing device; receiving a public key of the second computing device; computing a shared secret based on the public key and the private key of the second computing device; as well as Communicating with the second computing device using the shared secret.

16. The non-transitory computer-readable medium of claim 15, wherein the first computing device is caused to select a curve having a range of lengths that matches a threshold security level.

17. The non-transitory computer-readable medium of claim 15, wherein the first computing device is caused to select by picking a curve having a domain size close to a power of two and having efficient endomorphisms.

18. The non-transitory computer-readable medium of claim 15, wherein the first computing device is caused to select by excluding curves that are non-compact or difficult to generate.

19. The non-transitory computer readable medium of claim 15, wherein the curve has a form of y 2 =x 3 +ix is ​​the affine equation for 20. The non-transitory computer readable medium of claim 19, wherein the curve has a length of 454 bits.

21. The non-transitory computer readable medium of claim 20, wherein the domain size of the curve is p=2 454 +(3×17×11287) 2 .

Citation Information

Patent Citations

  • Method and system for cheon resistant static diffie-hellman security

    CN109074759A