Apparatus and method for generating public key and generating and verifying signature
By combining the Montgomery curve and the technical means of distorting the Edwards curve, scalar multiplication calculation on the elliptic curve is solved, and the existing digital signature schemes are implemented to achieve a more efficient digital signature process.
Patent Information
- Application Number
- CN202380077642.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-09
- Filing Date
- 2023-11-08
- Publication Date
- 2025-06-27
AI Technical Summary
The existing digital signature schemes have shortcomings in computing performance and resources, especially in the process of public key generation, signature generation and signature verification, which makes it difficult to meet the needs of efficient authentication.
By combining the technical means of Montgomery curve and the distorted Edwards curve, the double rational equivalence relationship is used to transfer the scalar multiplication on the elliptic curve from the distorted Edwards curve to the Montgomery curve for calculation, and transform it through homologous mapping to achieve more efficient computing performance.
This method significantly improves the computational performance of public key generation, signature generation, and signature verification, reduces the risk of side channel attacks and failure attacks, and is compatible with existing EdDSA processes and devices.
Smart Images

Figure CN120226006A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to authentication in the field of cryptography, and more particularly to elliptic curve cryptography. Background Art
[0002] Public key cryptography, or asymmetric cryptography, involves key pairs, each key pair including a private key known only to the key owner and an associated public key that can be distributed to others without compromising security.
[0003] Elliptic-curve cryptography (ECC) is a special form of public key cryptography that relies on elliptic curves over finite base fields. An elliptic curve is a smooth projective algebraic curve of genus one over the finite field that includes specific points. The ECC principle exploits the intractability of finding the discrete logarithm of a random elliptic curve element relative to a publicly known base point (i.e., the Elliptic Curve Discrete Logarithm Problem (ECDLP)).
[0004] In this regard, as is known to those skilled in the art, the addition of two different points on an elliptic curve involves the intersection of a line defined by the two points with the elliptic curve, while adding the same point to itself (referred to as point doubling) involves the intersection of the tangent to the elliptic curve at that point with the elliptic curve. Elliptic curve point multiplication then specifies the repeated addition of a point to itself along the curve, with the multiplication having a scalar integer factor that is the number of times the point appears in the addition (i.e., the number of additions plus one). For example, in point doubling, the factor value is 2, which is the smallest possible value. Hereinafter, this scalar-point multiplication will generally be referred to as "scalar multiplication".
[0005] The discrete logarithm problem amounts to identifying the multiplicative scalar factor (the multiplicand) from the scalar product point obtained from the iteratively added points. Since the addition of two points (which can be the same point) on the curve has no obvious relationship with the positions of the added points on the curve, repeating this addition operation makes finding the multiplicative factor complex enough to be intractable in practice.
[0006] ECC has particularly interesting applications in authentication, where digital signatures are used to verify the authenticity (created by a known sender) and integrity (no message tampering) of digital messages, collectively referred to hereinafter as message authenticity. Digital signature schemes rely on asymmetric cryptography and typically consist of three parts: 1 / key pair generation, including the random or pseudo-random selection of a private key and the determination of a public key associated with the private key; 2 / signature generation applied to a given message by means of the private key; and 3 / signature verification to check the message authenticity based on the public key and the signature.
[0007] In the ECC method developed for digital signatures, the Elliptic Curve Digital Signature Algorithm (ECDSA) exploits the discrete logarithm problem by using an elliptic curve and a base point of prime order on the curve. The creation of the key pair involves a randomly selected private key integer and a derived public key curve point, which is given by scalar multiplication of the base point by the private key. Then, the signature of a given message (consisting of a pair of numbers) is obtained by an algorithm applied to the message and involving the base point, the private key integer, and a nonce value (i.e., an arbitrary number provided for use only once in a cryptographic communication, which consists of a randomly selected integer, as known to those skilled in the art). For security and to avoid leakage, the nonce value is updated for each different signature. On the signature verification side, using the retrieved signature and the public key, the message authenticity is checked by verifying the equality of terms involving the corresponding scalar multiplication of the base point and the public key curve point.
[0008] Deriving signatures deterministically from messages and keys has been proposed instead of introducing a randomly selected integer as the nonce value, as described by the IETF (the Internet Engineering Task Force) in RFC6979 (Request For Comments) "Deterministic Usage of the Digital Signature Algorithm (DSA) and the Elliptic Curve Digital Signature Algorithm (ECDSA)" (T. Pornin, ISSN 2070-1721, 2013). Thus, the potentially exposed ECDSA random number generation is bypassed, enabling the enhancement of system security against, for example, faulty random number generators.
[0009] Another ECC method, the Edwards-curve Digital Signature Algorithm (EdDSA), is based on a twisted Edwards curve over a finite field of prime order and a base point on that curve. It also uses a private key integer and a public key curve point, where the latter is given by scalar multiplication of the base point by an integer factor derived from the private key. The signature consists of a curve point and a digital pair, both computed in a deterministic manner from the message, the private key, and the base point (the nonce value is deterministically derived from the private key and the message). The signature verification relies on verifying the equality of terms involving the corresponding scalar multiplications of the base point, the public key curve point, and the signature curve point, with the relevant integer factors derived from the message, the signature, and the public key. The EdDSA process is standardized by the IETF in RFC 8032, "Edwards Curve Digital Signature Algorithm (EdDSA)" (S. Josefsson and I. Liusvaara, ISSN 2070-1721, 2017). In addition to being deterministic, due to the concept of its robust design, it eliminates the risk of many implementation pitfalls.
[0010] An elliptic curve can generally be represented as a plane algebraic curve in standard form (corresponding to the zero set of a polynomial in two variables), involving two affine coordinates and two coefficients, called the short Weierstrass form. The associated special point lies at infinity and corresponds to the additive identity. In this form, two coefficients are chosen such that the curve is non-singular (has no cusps or self-intersections), and the characteristic of the field defining the curve is different from 2 and 3 (the characteristic is defined as the smallest number of times the multiplicative identity is added to obtain the additive identity, with the current multiplicative identity corresponding to the base point). A normal form representation of a non-singular elliptic curve over a field of characteristic equal to 2 or 3 is also possible, but it requires more than two coefficients (three coefficients for characteristic 3 and five coefficients for characteristic 2).
[0011] However, alternative expressions are widely used and facilitate the implementation of various computational methods.
[0012] Among the various elliptic curves (i.e., elliptic curve expressions) that have attracted attention and interest due to their efficiency and reliability in digital authentication, two families have been particularly exploited: Montgomery curves and Edwards curves.
[0013] The Montgomery curve is appreciated, especially because it enables regular and particularly efficient calculations using projective homogeneous coordinates instead of the affine coordinates (where the first two projective coordinates are given by multiplying the affine coordinates by an introduced third projective coordinate), thus avoiding costly field inversion operations. More precisely, the symmetry allows calculations to be based on only two of the three projective coordinates, and a particular algorithm called the Montgomery ladder, described for example by P.L. Montgomery in "Speeding the Pollard and Elliptic Curve Methods of Factorization", (Math. of Computation, Vol. 48, No 177, pp. 243-264, 1987), allows scalar-point multiplication to be performed in a fixed time, whether in different point addition modes or in the double point mode. This latter property proves advantageous for thwarting side-channel attacks, in which an attacker exploits time or power consumption measurements to extract information.
[0014] The twisted Edwards curve is important in public key ECC and is at the heart of the EdDSA method - the (simple) Edwards curve corresponds to a particular twisted Edwards curve that uses only one coefficient instead of two. They offer the advantageous property of having a general addition formula that applies to different points as well as double points (i.e., a unified addition law), thus simplifying protection against side-channel attacks. Moreover, addition calculations generally prove to be particularly fast. As with Montgomery curves, using projective homogeneous coordinates instead of the affine coordinates can avoid costly field inversion operations.
[0015] The elliptic curves in their Montgomery form and twisted Edwards form are birationally equivalent (except for singular points), which means that a conversion from either of these forms to the other can be achieved by a rational map, i.e., based on a function defined by a rational fraction over the finite field of the function field curve (i.e., an algebraic fraction whose numerator and denominator are both polynomials with coefficients in that finite field), thus deriving an isomorphism between the Montgomery curve and the twisted Edwards curve. The rational map can also convert the Montgomery curve and the twisted Edwards curve into their corresponding Weierstrass forms, although the reverse rational map requires some specific conditions. The birational equivalence between the Montgomery curve and the twisted Edwards curve helps to develop corresponding methods in both forms.
[0016] As is known to those skilled in the art, twisted Edwards curves are now more often used for digital signatures, especially due to the existence of a particularly efficient algorithm for double-base scalar multiplication (i.e., scalar multiplication involving computing two scalar multiplications and adding the results). On the other hand, Montgomery curves tend to be preferred in Diffie-Hellman key exchange schemes (Elliptic-Curve Diffie Hellman, ECDH, meaning "Elliptic Curve Diffie Hellman") for quickly establishing a secure channel between two parties to determine a symmetric key cipher for subsequent exchanges, especially due to the existence of a very simple, constant-time, and fast scalar multiplication (single-base, i.e., without further addition of the scalar product results).
[0017] For example, Curve25519 is a Montgomery curve defined over a prime field defined by the prime 2 255 -–19 (hence the name), and may provide 128-bit security (corresponding to a 256-bit key size), while Curve448 is defined over a prime field defined by the Solinas trinomial prime 2 448 –2 224 -1, and may provide 224-bit security. The corresponding ECDH functions are named X25519 and X448 respectively. Both are particularly described by the IETF in RFC 7748, "Elliptic Curves for Security", (A. Langley et al., ISSN 2070-1721, 2016).
[0018] Similarly, Ed25519 is an EdDSA signature scheme that uses a twisted Edwards curve that is birationally equivalent to Curve25519, and is suitable for public keys 256 bits long and signatures 512 bits long, while Ed448 is an EdDSA signature scheme that uses a twisted Edwards curve that is birationally equivalent to Curve448, and is suitable for public keys 456 bits long and signatures 912 bits long. Both are particularly described by the IETF in RFC 8032 cited above. For convenience, in the following text, Ed25519 will be used to refer to the twisted Edwards curve that is birationally equivalent to Curve25519.
[0019] Publication "Lightweight EdDSA Signature Verification for the Ultra-Low-Power Internet of Things", ( Johann et al., Springer International Publishing, pp. 263-282 (XP047617485)), discloses a comparison of two implementations of EdDSA verification.
[0020] Given the high demand for security and authentication efficiency in terms of computational speed and resources, it seems desirable to further enhance the available digital signature schemes beyond the current schemes based on twisted Edwards curves such as EdDSA and, to some extent, Montgomery curves. SUMMARY OF THE INVENTION
[0021] The object of the present disclosure is to provide a series of digital signature schemes that are suitable for potentially further improving the computational performance, whether for public key generation, signature generation, or signature verification, compared to existing methods based on twisted Edwards curves.
[0022] A further object of the present disclosure is to provide a family of methods that enable compatibility with existing EdDSA processes and devices (such as Ed25519) and other digital signature solutions based on twisted Edwards curves. The present disclosure also aims to protect the computation by potentially reducing the risk of side-channel attacks and fault attacks.
[0023] The present disclosure can be applied, either alone or cumulatively, to any digital signature step, including public key generation, signature generation, and signature verification.
[0024] PRELIMINARY DEFINITIONS
[0025] In the present disclosure, "digital communication" refers to the transmission and reception of data in the form of a digital bit stream or a digitized analog signal, which can be through a point-to-point or point-to-multipoint communication channel, or by recording data on a storage medium and retrieving data from that medium. The relevant communication channel can be in any form, such as a wireless channel using radio, microwave, or infrared spectrum, optical fiber, copper wire, or a computer bus. The relevant storage medium can also be in any form, such as an optical disc, magnetic tape, HDD (hard disk drive), SSD (solid state drive), semiconductor memory, flash memory, DNA / RNA molecule.
[0026] "Modular arithmetic" is an integer arithmetic system based on a modulus (an integer greater than 1), where two numbers are said to be congruent modulo the modulus (also denoted "mod" the modulus) if their difference is divisible by the modulus. This defines an equivalence relation compatible with the operations of addition, subtraction, and multiplication (or integer powers greater than 1). Additionally, the "modular inverse operation" of an integer amounts to finding the modular multiplicative inverse of that integer such that the product of the two numbers is equal to 1 modulo the modulus. As long as the modulus is prime, the modular inverse operation is possible for all integers not congruent to zero. In digital computing, the modular inverse operation is typically much more demanding than addition, subtraction, or multiplication, so it is effective to avoid them whenever possible. Typically and purely indicatively, in modular arithmetic on 256 bits, one addition or subtraction may require 208 cycles, one multiplication or squaring may require 480 cycles, while one modular inverse operation may require approximately 100,000 cycles. In the context of ECC, the finite field that defines an elliptic curve satisfies modular arithmetic.
[0027] "Affine coordinates" are the coordinates of a point within an affine coordinate system in an affine space, which includes an origin in the affine space and a linear basis of the associated vector space. In ECC, an elliptic curve is determined as a plane curve over a finite field that extends in an affine space with an affine coordinate system. "Homogeneous coordinates" refer to the coordinates of points in a geometric space where multiplying all point coordinates by the same non-zero scalar does not change the point. In particular, they allow representing points at infinity using finite coordinates. Homogeneous coordinates can be derived from affine coordinates by adding a dimension (through a supplementary homogeneous coordinate) and multiplying the existing affine coordinates by that supplementary homogeneous coordinate. Alternatively, they can be derived by dividing the existing affine coordinates by the supplementary (non-zero) homogeneous coordinate. In the following, according to some widely used notations, a colon is used instead of a comma to distinguish homogeneous coordinates from affine coordinates. For example, (x,y) represents affine coordinates, and (X:Y:Z) represents homogeneous coordinates, where x = X / Z and y = Y / Z.
[0028] "Projective coordinates" are typically (but not always) used as a synonym for homogeneous coordinates. Currently, they are more generally defined as the coordinates used in projective geometry, i.e., the study of geometric properties that are invariant under projective transformations (also called homographies, i.e., isomorphisms of projective spaces, which are affine spaces with points at infinity such that each direction of parallel lines is associated with a point at infinity). Projective coordinates can be composed, for example, of homogeneous coordinates or Jacobian coordinates (such that for affine coordinates (x,y), the projective coordinates are X, Y, Z such that x = X / Z 2 and y = Y / Z 3 ).
[0029] "Extended coordinate representation" currently refers to a transformation and extension of affine coordinates that enables the avoidance or reduction of division when solving target equations, thus reducing modular inversions in related modular arithmetic. They include homogeneous coordinates, other projective coordinates, and further system representations. In the context of ECC, extended coordinate representations are applicable to solving polynomial equations that define elliptic curves in affine systems and have proven to be particularly useful for computational performance. The same notation (with colons) mentioned above for homogeneous coordinates will now be used more generally for extended coordinate representations. For example, (x,y) are affine coordinates and homogeneous coordinates can be given by (X:Y:Z), where x = X / Z and y = Y / Z; Jacobian coordinates are given by (X:Y:Z), where x = X / Z 2 and y = Y / Z 3 ; López-Dahab coordinates are given by (X:Y:Z), where x = X / Z and y = Y / Z 2 ; Modified Jacobian coordinates are given by (X:Y:Z:T), where x = X / Z 2 , y = Y / Z 3 , T = aZ 4 ; Chudnovsky Jacobian coordinates are given by (X:Y:Z:T:U), where x = X / Z 2 , y = Y / Z 3 , T = Z 2 , U = Z 3 . The term "extended coordinate representation" can further refer to any combination of the above systems.
[0030] In the context of ECC, "an elliptic curve" can be defined as a plane curve over a finite field (also known as a Galois field) that can be defined in an affine coordinate system with parameters a and b, corresponding to affine coordinates (x,y), as (short Weierstrass form):
[0031] y 2 = x 3 + ax + b (1)
[0032] And is equipped with a specific point at infinity. The finite field gives a set of points on the curve, which form a group with the point at infinity as the additive identity. In the prime case, the finite field consists of the integers modulo a prime p. The elliptic curve further provides a "base point" G, also called a "generator", which is used in combination with the addition law on the elliptic curve and is associated with the finite field to generate the relevant points on the elliptic curve. The points generated by the base point form a cyclic subgroup, the number of whose elements is the "order" n of G (i.e., the smallest positive number of G's that when added together give the point at infinity (i.e., the additive identity)). The order n divides the cardinality of the finite field (by Lagrange's theorem), and the ratio is called the "co-factor" h. The "field parameters" in ECC are the elements that define an elliptic curve, including the constants a and b, the prime p in the prime case, the base point G, the order n, and the co-factor h.
[0033] "Code exponentiation", hereinafter simply referred to as "exponentiation", in ECC refers to reconstructing an elliptic curve point by decoding a number obtained by previously encoding a point. This is performed by relying on the fact that the point belongs to the elliptic curve - for example, the decoded number includes the bits of the y - coordinate and another bit gives the sign of the x - coordinate. Converting an elliptic curve point to a number facilitates the transmission of information and reduces its associated size. ECC exponentiation is used in particular for transmitting public keys, or parts of signatures that belong to elliptic curve points, and is a relatively expensive computation. Typically and purely indicatively, in a modular operation on 256 bits, one exponentiation may require 110,000 cycles.
[0034] "Montgomery ladder" is an ECC algorithm that can compute scalar multiplication in a fixed time regardless of the value of the scalar multiplicand. Thus, it can protect against potential side-channel attacks based on time or power leakage. It was disclosed in the aforementioned pioneering article by P.L. Montgomery dedicated to factoring large numbers and is applicable to various types of elliptic curves, including Montgomery curves and twisted Edwards curves. In the case of Montgomery curves, K. Okeya and K. Sakurai further developed it more completely in "Efficient Elliptic Curve Cryptosystems from a Scalar Multiplication Algorithm with Recovery of the y-Coordinate on a Montgomery-Form Elliptic Curve", (CHES 2001, LNCS 2162, pp. 126-141, 2001). When applied to Montgomery curves, the application of the said Montgomery ladder appears to be particularly effective because only the first affine coordinate x (i.e., the first and third projective homogeneous coordinates U and Z) is required, and the second affine coordinate y is not needed. However, since the latter may be necessary, specific methods for recovering it have been developed, especially as described in the aforementioned article by K. Okeya and K. Sakurai. The particularity of this recovery includes using the affine coordinates (u, v) of point P as input, as well as the first and third homogeneous coordinates (U1, Z1) and (U2, Z2) of two corresponding ladder points P1 and P2, and points P, P1, and P2 are linked by point addition (P2 = P1 + P).
[0035] An "isomorphism" between two elliptic curves is a structure-preserving mapping between these structures, i.e., a "homomorphism" that can be inverted by an inverse mapping. A homomorphism between elliptic curves is an isomorphism if and only if it is bijective.
[0036] A "rational function" over a field is a function that can be defined by a rational fraction over that field, which consists of an algebraic fraction where both the numerator and denominator are polynomials with coefficients in that field.
[0037] A "rational map" from a first elliptic curve to a second elliptic curve is a morphism from a non-empty subset of the said first elliptic curve to the second elliptic curve. It can be written in coordinates using rational functions.
[0038] Such a rational map is a "birational map" if there exists a rational map from the second elliptic curve to the first elliptic curve which is the inverse of the aforementioned rational map. This birational map induces an isomorphism from a non-empty open subset of the first elliptic curve to a non-empty open subset of the second elliptic curve, and in this case the first elliptic curve and the second elliptic curve are said to be birationally equivalent.
[0039] An "isogeny" from a first elliptic curve defined over a field and having a first point at infinity and a second elliptic curve having a second point at infinity is a non-constant morphism of curves from the first elliptic curve to the second elliptic curve which maps the first point at infinity to the second point at infinity. It should be noted that an isogeny is not necessarily an isomorphism since it may have a non-trivial kernel. Such an isogeny can be represented by rational functions in each affine coordinate.
[0040] The first and second elliptic curves having an isogeny are said to be isogenous.
[0041] The "degree" of an isogeny is given by the maximum of the degrees of the polynomials at the numerator and denominator of the x-affine coordinate. The terms "adapted to" and "configured to" are used extensively in the present disclosure and cover initial configuration, subsequent adaptation or supplementation of the device, or any combination thereof, whether implemented by physical means or software means (including firmware).
[0042] The term "processor" should not be construed as being limited to hardware capable of executing software and generally refers to a processing device which may for example include a computer, a microprocessor, an integrated circuit or a programmable logic device (PLD). The processor may also include one or more graphics processing units (GPUs), whether used for computer graphics and image processing or other functions. Furthermore, the instructions enabling the execution of the associated and / or generated instructions and / or data may be stored on any processor-readable medium such as an integrated circuit, a hard disk, a CD (compact disc), an optical disc such as a DVD (digital versatile disc), a RAM (random access memory) or a ROM (read-only memory). The instructions may in particular be stored in hardware, software, firmware or any combination thereof.
[0043] In the following description, additional terms will be defined, specified or commented on wherever useful.
[0044] Object of the Invention
[0045] An object of the present disclosure is in particular to provide a device for generating a public key from a private key in elliptic curve cryptography (ECC). The device comprises:
[0046] At least one input terminal, adapted to receive data representing a private key, and at least one parameter, the parameter defining a first elliptic curve over a finite field and a first base point thereon, the finite field having a field order, the first elliptic curve being of the twisted Edwards curve type,
[0047] At least one processor, configured to compute data representing a public key from the data representing the private key by obtaining a scalar multiplication of the first base point by a scalar derived from the private key on the first elliptic curve,
[0048] At least one output terminal, adapted to provide the data representing the public key for securing digital communications.
[0049] According to the present disclosure:
[0050] At least one input terminal is adapted to receive at least one parameter, the parameter defining a second elliptic curve birationally equivalent to the first elliptic curve by an isomorphism, and a second base point located on the second elliptic curve and corresponding to the first base point with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type,
[0051] At least one processor is configured to continue by performing a scalar multiplication of the second base point by at least one adjustment scalar on the second elliptic curve, the adjustment scalar being selected from: the scalar derived from the private key, and at least one quotient obtained by dividing the scalar by at least one adjustment integer greater than 1 and performing a modulo field order operation; when the adjustment scalar is the scalar, the adjustment integer value is 1; and is configured to convert the resulting point of the scalar multiplication on the second elliptic curve to the scalar multiplication on the first elliptic curve by at least one isogeny, the at least one isogeny having a degree respectively equal to the at least one adjustment integer, and mapping the second base point to a scalar multiplication of the first base point by the at least one adjustment integer respectively.
[0052] Thus, the scalar multiplication on the first elliptic curve is obtained indirectly, i.e., through the scalar multiplication on the second elliptic curve and the conversion to the first elliptic curve.
[0053] Thus, the device for generating the public key relies on a combination of the Montgomery curve method and the twisted Edwards curve method. Unexpectedly, compared with existing alternatives based on Montgomery curves, Edwards curves, or other families of elliptic curves, the present solution involves the joint consideration of two elliptic curves. Moreover, in terms of input and result, the device for generating the public key behaves substantially like a traditional device relying on a twisted Edwards curve, such as using the EdDSA algorithm. In particular, due to the isomorphism relationship between the Montgomery curve and the twisted Edwards curve, the scalar multiplication performed on the Montgomery curve and converted back to the twisted Edwards curve can be exactly equal to the corresponding scalar multiplication performed on the twisted Edwards curve.
[0054] In this regard, the device can be fully integrated into an existing authentication system based on the twisted Edwards curve. However, the background computing operations may be substantially modified because, contrary to the above observations regarding input and result, they involve scalar multiplications that may be performed entirely on the Montgomery curve through a round-trip process. This surprising hybrid can significantly improve the computational performance of public key generation in some embodiments, compared with traditional devices based on a single twisted Edwards curve, thus extending the respective advantages of the Montgomery curve and the twisted Edwards curve schemes considered separately.
[0055] This scalar multiplication on the Montgomery curve can be further performed using a regular scalar point multiplication algorithm with invariance (Montgomery ladder), which can reduce the risk of side-channel attacks. Moreover, using the Montgomery ladder on the Montgomery curve (instead of on the twisted Edwards curve) can achieve a globally reduced code size in some modes compared to a pure Edwards curve implementation, and may thus be particularly suitable for low-cost devices.
[0056] In contrast, accelerating the Edwards curve calculation to a high-efficiency level is also achievable, but this requires a significant increase in RAM and code, resulting in a higher-cost device.
[0057] In some embodiments, the first elliptic curve and the second elliptic curve are defined over a finite field with a prime order (i.e., a prime field). In alternative embodiments, they are defined over a binary field.
[0058] When the adjustment integer value is 1, since the first elliptic curve and the second elliptic curve are birationally equivalent by isomorphism, at least one processor can be configured to convert the resulting point from the second elliptic curve to the first elliptic curve through the inverse mapping of the isomorphism.
[0059] In some embodiments, the Montgomery curve and the associated twisted Edwards curve utilized have known domain parameters, particularly including first and second base points. Thus, scalar multiplication can be directly performed on the second elliptic curve without performing preliminary calculations on the first elliptic curve. Therefore, only one direction of conversion may be required, i.e., from the second elliptic curve to the first elliptic curve - which involves the resulting point.
[0060] In a variant, at least some of the domain parameters of the Montgomery curve and / or the associated twisted Edwards curve utilized need to be constructed and kept consistent between the two curves. In some implementations of such a variant, data regarding the first base point is particularly communicated so that the second base point can be determined.
[0061] In some implementations, the adjustment integer is always 1 such that the adjusted scalar is the scalar itself, and the isogeny mapping from the Montgomery curve to the twisted Edwards curve is the inverse of the isomorphism.
[0062] In other implementations, at least one processor is configured such that the adjustment integer is greater than 1 and a valid value is obtained from data stored, data input by a user, or data received via a communication network before the calculation.
[0063] In still an alternative mode, at least one processor is configured to process at least two adjustment integers (preferably including 1) and select the adjustment integer utilized based on a received instruction (e.g., an instruction input by a user via a user interface or an instruction received from a communication network).
[0064] Another object of the present disclosure is a device for generating a signature associated with a message from a private key in ECC. The device includes:
[0065] At least one input end, adapted to receive data representing the private key and the message, and at least one parameter that defines a first elliptic curve over a finite field and a first base point thereon, the finite field having a field order, the first elliptic curve being of the twisted Edwards curve type, at least one processor, configured to calculate data representing the signature from the data representing the private key and the message by obtaining a scalar multiplication of the first base point by a nonce value on the first elliptic curve,
[0066] At least one output end, adapted to provide data representing the signature for protecting digital communication.
[0067] According to the present disclosure:
[0068] At least one input is adapted to receive at least one parameter that defines a second elliptic curve birationally equivalent to a first elliptic curve by an isomorphism, and a second base point that lies on the second elliptic curve and corresponds to the first base point with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type.
[0069] At least one processor is configured to proceed by performing a scalar multiplication of the second base point by at least one adjusted nonce value on the second elliptic curve, the adjusted nonce value being selected from: the nonce value, and at least one quotient obtained by dividing the nonce value by at least one adjustment integer greater than 1 and performing a modulo field order operation; the adjustment integer value being 1 when the adjusted nonce value is the nonce value; and is configured to convert the resulting point of the scalar multiplication on the second elliptic curve to a scalar multiplication on the first elliptic curve by at least one isogeny, the at least one isogeny having a degree respectively equal to the at least one adjustment integer and mapping the second base point to a scalar multiplication of the first base point by the at least one adjustment integer respectively.
[0070] The device for generating a signature raises similar comments as those above regarding the device for generating a public key. Similarly, the scalar multiplication on the first elliptic curve is obtained indirectly, i.e., through the scalar multiplication on the second elliptic curve and the conversion to the first elliptic curve. Furthermore, the generation is rooted in the twisted Edwards curve scheme but relies on scalar multiplication based on Montgomery curves, through a round-trip process between the twisted Edwards curve and the Montgomery curve.
[0071] Similarly, the computational performance may also be significantly enhanced in some embodiments.
[0072] Similarly, the conversion back from the Montgomery curve to the twisted Edwards curve can be obtained by the inverse mapping of the isogeny between the twisted Edwards curve and the Montgomery curve, and the field parameters can be known in advance such that the computation can start directly on the second elliptic curve, and / or in some embodiments, the first elliptic curve and the second elliptic curve are defined over a prime field.
[0073] Furthermore, the comments regarding the adjustment integer elaborated for the device for generating a public key also apply to the device for generating a signature.
[0074] In a particular embodiment, the device for generating a signature includes the device for generating a public key as defined above.
[0075] Combining these two devices may be particularly attractive as their respective performances can be cumulated by first generating a public key (on the transmission or storage side) and then using it (on the reception or retrieval side) to check the authenticity of messages by generating signatures (on the transmission or storage side) associated with these messages. Such a combination may also be interesting in terms of implementation by optionally sharing mutualized functions, such as in particular for switching between two elliptic curve schemes and / or performing scalar multiplication on Montgomery curves.
[0076] In any case, this combination of the two devices is optional and either of them can exist in place of the other.
[0077] In some embodiments, the nonce value is deterministically derived from the private key and the message and may also be derived from the order of the base point (in the first or second elliptic curve), as is particularly practiced in the EdDSA algorithm.
[0078] In alternative embodiments, the nonce value is randomly generated, as is particularly practiced in some ECDSA modes.
[0079] In the device for generating the public key or the device for generating the signature, according to some embodiments, at least one processor is configured to perform scalar multiplication on a second elliptic curve in an extended coordinate representation involving at least three coordinates instead of two coordinates in the affine representation. This extended coordinate representation is adapted to switch between the affine representation on the first elliptic curve and the extended coordinate representation on the second elliptic curve such that the scalar multiplication on the second elliptic curve is performed in the extended coordinate representation without a modular inversion operation. Then, at least one processor is further configured to convert the extended coordinate representation of the resulting point on the second elliptic curve to the affine representation of the scalar multiplication on the first elliptic curve.
[0080] Doing so can provide the usual benefit of avoiding modular inversion operations in scalar multiplication, which are performed on the second elliptic curve instead of the expected first elliptic curve. In a particular embodiment, the performance can then reach a high level.
[0081] Retrieving the affine representation of the scalar multiplication on the first elliptic curve from the second elliptic curve may require at least one modular inversion operation. However, it can be remembered that in traditional processing on twisted Edwards curves, recovering the affine representation of the scalar product from the projective homogeneous representation usually already involves at least one modular inversion operation.
[0082] In certain embodiments that rely on an extended coordinate representation, the latter is a projective coordinate representation in which a point defined by three or more coordinates remains invariant under multiplication of these coordinates by the same coefficient, and at least one processor is configured to convert the extended coordinate representation of the resulting point on a second elliptic curve to an affine representation of a scalar multiplication on a first elliptic curve with a single modular inversion operation.
[0083] The projective coordinate representation corresponding to homogeneous coordinates then enables the reconstruction of the affine coordinates of the resulting point on the first elliptic curve with no more modular inversion operations than would be required if the scalar multiplication were performed entirely on the first elliptic curve. This may open the way for significant computational gains.
[0084] This particularly attractive feature proves to be a consequence of the fundamental homogeneous property of homogeneous coordinates.
[0085] The present disclosure further relates to a device for verifying a signature associated with a message in ECC, the device comprising:
[0086] At least one input adapted to receive data representing a signature, a public key, and a message, and at least one parameter defining a first elliptic curve and a first base point located on the first elliptic curve, the first elliptic curve being of the twisted Edwards curve type, the signature including a scalar part associated with a check value and a curve point part representing a check curve point of the first elliptic curve, and the public key representing a public key point of the first elliptic curve, at least one processor configured to verify the consistency between the signature and the message by an equation check corresponding to the first elliptic curve, the equation check involving terms based respectively on the signature curve point part, a scalar multiplication based on the first base point multiplied by a base point multiplier derived from at least the signature scalar part, and a scalar multiplication based on the public key point multiplied by a public key multiplier derived from at least the signature curve point part, at least one of the base point multiplier and the public key multiplier also being derived from the message,
[0087] At least one output adapted to provide an authentication result of the equation check for securing digital communications.
[0088] According to the present disclosure:
[0089] At least one input is adapted to receive at least one parameter defining a second elliptic curve that is birationally equivalent to the first elliptic curve by an isomorphism, and a second base point located on the second elliptic curve and corresponding to the first base point with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type,
[0090] At least one processor is configured to determine, from a public key, a converted public key point of a public key point corresponding to a first elliptic curve relative to an isomorphic second elliptic curve, is configured to perform scalar multiplications of a second base point by a base point multiplier and the converted public key point by a public key multiplier on the second elliptic curve, and is configured to perform an equality check on the same curve among the first elliptic curve and the second elliptic curve based on the scalar multiplications and a check curve point.
[0091] The equality check "corresponds to" the first elliptic curve because its result is the same as the result performed on the first elliptic curve, whether performed effectively on the first elliptic curve or on the second elliptic curve. The relevant scalar multiplications are performed on the second elliptic curve, based on at least the conversion of the public key point from the first elliptic curve to the second elliptic curve and the availability of the second base point in the second elliptic curve.
[0092] On the one hand, the match between the equality check performed by the disclosed device (by migrating at least scalar multiplications from a twisted Edwards curve to a Montgomery curve) and, on the other hand, an equality check that relies entirely on a twisted Edwards curve (including scalar multiplications) is based on the isomorphism between the twisted Edwards curve and the Montgomery curve.
[0093] In some embodiments, the first elliptic curve and the second elliptic curve are defined over a prime field.
[0094] In some embodiments, the parameters defining the first elliptic curve and the first base point include a simple flag pointing to the identity of a selected twisted Edwards curve. Similarly, in some embodiments that can be combined with the foregoing embodiments, the parameters defining the second elliptic curve and the second base point include a simple flag pointing to the identity of a selected Montgomery curve.
[0095] In alternative embodiments, at least partial field parameters of the utilized Montgomery curve and / or the associated twisted Edwards curve need to be constructed and kept consistent between the two curves. In some embodiments of this variant, data about the first base point is particularly communicated so that the second base point can be determined.
[0096] The curve point part of the signature can be a code number that needs to be exponentiated to construct the check curve point. Similarly, in some embodiments, the public key is a code number that needs to be exponentiated to construct the public key point.
[0097] Once the scalar multiplications of the second base point by the base point multiplier and the converted public key point by the public key multiplier are performed on the second elliptic curve, the equality check is performed on the first elliptic curve or the second elliptic curve.
[0098] More precisely, in the first set of embodiments, equality checking is performed on the twisted Edwards curve by converting two product points resulting from scalar multiplication from the Montgomery curve back to the twisted Edwards curve. This conversion back can be obtained through the inverse mapping of the isomorphism between the twisted Edwards curve and the Montgomery curve. Then, equality checking can be performed on the twisted Edwards curve in the conventional manner, as if all computations were taking place on this curve. In this regard, the Montgomery curve can appear as a background tool for selectively performing the round-trip computations for scalar multiplication without in any way affecting all other computations performed on the twisted Edwards curve. This implementation pattern can be highly compatible with existing ECC systems, especially those involving the EdDSA or ECDSA algorithms.
[0099] In the second set of embodiments, equality checking is performed on the Montgomery curve by converting the check curve point from the twisted Edwards curve to the Montgomery curve. This solution is more surprising than the previous one because, although seemingly entirely based on a twisted Edwards curve, the basic computations for signature verification are performed on another curve and can yield the expected results. This implementation pattern is particularly suitable for the EdDSA scheme.
[0100] In the first or second set of embodiments described above, the device for verifying signatures can significantly enhance the computational performance in some embodiments by assigning the scalar multiplication task to the Montgomery curve side, as its efficiency can be improved compared to performing the same computation on the twisted Edwards curve side.
[0101] In some embodiments, equality checking involves scalar multiplication of a base point by a check value and scalar multiplication of a public key point by a scalar value derived from the curve point portion, the public key, the message, and optionally the base point order (in the first or second elliptic curve). These are consistent with the EdDSA process.
[0102] In alternative embodiments, equality checking involves scalar multiplication of a base point by a number derived from the message, the check value, and optionally the base point order, and scalar multiplication of a public key point by a number derived from the check curve point, the check value, and optionally the base point order. These are consistent with the ECDSA process.
[0103] The device for verifying signatures can be combined with a device for generating public keys and / or a device for generating signatures that conform to the present disclosure. Embodiments of such a combination may be attractive in terms of synergy and consistency, and the same computational modules may be used in a reciprocal manner for various functions, such as scalar multiplication on the Montgomery curve and / or conversion between elliptic curves.
[0104] However, in an alternative embodiment, the device for verifying the signature is not combined with the device for generating the public key or the device for generating the signature that conforms to the present disclosure. Then the development can be concentrated on signature verification.
[0105] The main commonality among the ECC device for generating the public key, the device for generating the signature, and the device for verifying the signature according to the present disclosure is that the involved scalar multiplication is transferred from the relevant twisted Edwards curve to the corresponding Montgomery curve that is birationally equivalent thereto.
[0106] This transfer is based on continuous back-and-forth conversions between the twisted Edwards curve and the Montgomery curve, where one direction of these conversions may be implicit and does not require dedicated computations. In particular, in the device for generating the public key and the device for generating the signature, the conversion from the twisted Edwards curve to the Montgomery curve may be implicit because the base point of the considered Montgomery curve is already available. Additionally, in the device for verifying the signature, the conversion back from the Montgomery curve to the twisted Edwards curve may be implicit because the equality check is performed on the Montgomery curve while being equivalent to the equality check performed on the twisted Edwards curve (i.e., having the same result).
[0107] In some embodiments of the device for verifying the signature, at least one processor is configured to determine, in a second elliptic curve, a converted public key point and a check curve point corresponding to a first elliptic curve relative to a converted check curve point that is isomorphic, using an extended coordinate representation involving at least three coordinates on the second elliptic curve, the extended coordinate representation being adapted to switch between an affine representation involving two coordinates on the first elliptic curve and the extended coordinate representation on the second elliptic curve, and being configured to perform scalar multiplication and equality check without modular inversion in the extended coordinate representation on the second elliptic curve.
[0108] In these embodiments (which belong to those in which the equality check is performed on the Montgomery curve), by using the extended coordinate representation for scalar multiplication and equality check, a high degree of efficiency can be ensured. Then modular inversion can be completely avoided in these computations, just as can be conventionally achieved while remaining on the twisted Edwards curve through the extended coordinate representation, but in some embodiments, the performance of scalar multiplication is significantly improved.
[0109] The remarkable power of using the extended coordinate representation on the Montgomery curve for equality checking without modular inversion is demonstrated to be due on the one hand to the isomorphism between the twisted Edwards curve and the Montgomery curve, which enables equations of interest to be expressed in a similar way on both curves, and on the other hand to the properties of the extended coordinate representation, which enables the conversion of affine coordinates to the extended coordinate representation on the Montgomery curve without modular inversion.
[0110] In some embodiments, at least one processor is configured to convert an affine representation of a public key point in a first elliptic curve into a projective homogeneous coordinate representation in a second elliptic curve involving at least three coordinates without requiring a modular inverse operation, the projective homogeneous coordinate representation being such that a point defined by the three or more coordinates remains unchanged by multiplying the coordinates by the same coefficient.
[0111] The use of projective homogeneous coordinates enables this transformation to be performed without the need for modular inversion operations due to their homogeneous properties, and may therefore provide further improved performance.
[0112] These embodiments may be combined with the aforementioned embodiments involving an extended coordinate representation, which is then composed of a projective homogeneous coordinate representation.
[0113] In a set of embodiments in which the equality check is performed on a Montgomery curve, according to an advantageous mode, not only the public key points but also the check curve points are converted from the twisted Edwards curve in affine coordinates to the Montgomery curve in projective homogeneous coordinates without modular inversion. In this way, the converted check curve points can be used to perform the equality check entirely on the Montgomery curve in projective homogeneous coordinates, again possibly without modular inversion.
[0114] According to a more specific embodiment involving projective homogeneous coordinate representation in a Montgomery curve, at least one processor is configured to perform scalar multiplication on a second elliptic curve by a modified Montgomery ladder method by processing coordinates fully expressed in projective homogeneous coordinate representation.
[0115] This approach is in stark contrast to the usual and expected use of the Montgomery ladder, where affine coordinates are input for processing. This can be done by multiplying the terms of the algorithm by the square of the third homogeneous coordinate, Z 2 to achieve.
[0116] An advantageous potential feature of these particular embodiments is the ability to input a third homogeneous value Z different from 1 for the scalar multiplication. Furthermore, working entirely with homogeneous coordinates, rather than traditionally inputting affine coordinates into the calculation, may eliminate the need for modular inversion when performing the Montgomery ladder.
[0117] In a particular mode of a device for verifying a signature, at least one processor is configured to perform an EdDSA process on a first elliptic curve by a second elliptic curve. A basepoint multiplier then corresponds to a check value, and a public key multiplier is derived from a curve point component, a public key, and a message.
[0118] In this regard, the disclosed device can strongly rely on existing EdDSA methods, whether the equality check is performed on a Montgomery curve (for potentially higher efficiency) or on a twisted Edwards curve (for enhanced integration compatibility after converting the obtained double-base scalar multiplication point from the Montgomery curve).
[0119] In some modes of a device for generating a public key, a device for generating a signature, and / or a device for verifying a signature, the first elliptic curve and the second elliptic curve are respectively birationally equivalent elliptic curves Ed25519 and Curve25519 defined over a prime field defined by the prime 2 255 –19, and the first elliptic curve Ed25519 is defined in affine coordinates x,y as:
[0120] -x 2 + y 2 = 1 – (121665 / 121666) x 2 y 2 (2) and is associated with a first basepoint whose ordinate y is equal to 4 / 5, and the second elliptic curve Curve25519 is defined in affine coordinates u,v as:
[0121] v 2 = u 3 + 486662 u 2 + u (3)
[0122] and is associated with a second basepoint whose abscissa u is equal to 9.
[0123] These elliptic curves may prove particularly suitable for the disclosed device and refer to established domain parameters, thus simplifying calculations by avoiding in particular the determination of suitable basepoints.
[0124] Curve25519 and Ed25519 each have a cofactor equal to 8 (i.e., the number of elements in the cyclic subgroup generated by the basepoint is 1 / 8 of the prime field).
[0125] In an alternative embodiment, the device for generating a public key, the device for generating a signature, and the device for verifying a signature alternatively or also apply where the first elliptic curve and the second elliptic curve are respectively the birationally equivalent elliptic curves Ed448 and Curve448 defined over Solinas trinomial primes.
[0126] Another object of the present disclosure is a method for generating a public key from a private key in ECC, the method comprising: receiving data representing the private key, and at least one parameter defining a first elliptic curve over a finite field and a first base point thereon, the finite field having a field order, the first elliptic curve being of the twisted Edwards curve type,
[0127] computing, with at least one processor, data representing the public key, the data being derived from the data representing the private key by obtaining, on the first elliptic curve, a scalar multiplication of the first base point by a number derived from the private key,
[0128] providing the data representing the public key for securing a digital communication.
[0129] According to the present disclosure, the method comprises:
[0130] receiving at least one parameter defining a second elliptic curve that is birationally equivalent to the first elliptic curve by an isomorphism, and a second base point located on the second elliptic curve and corresponding to the first base point with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type,
[0131] continuing, with at least one processor, by performing, on the second elliptic curve, a scalar multiplication of the second base point by an adjusted scalar selected from: the scalar derived from the private key, and a quotient obtained by dividing the scalar by an adjustment integer greater than 1 and taking the modulus of the field order; when the adjusted scalar is the scalar, the adjustment integer value is 1; and converting, by an isogeny mapping, the resulting point of the scalar multiplication on the second elliptic curve to a scalar multiplication on the first elliptic curve, the isogeny mapping having a degree equal to the adjustment integer and mapping the second base point to a scalar multiplication of the first base point by the adjustment integer.
[0132] The method for generating a public key is preferably performed by a device for generating a public key according to any embodiment of the present disclosure.
[0133] A further object of the present disclosure is a method for generating a signature associated with a message from a private key in ECC, the method comprising:
[0134] receiving data representing the private key and the message, and at least one parameter defining a first elliptic curve over a finite field and a first base point thereon, the finite field having a field order, the first elliptic curve being of the twisted Edwards curve type,
[0135] Compute data representing a signature with at least one processor, the data being derived from data representing a private key and a message, by obtaining a scalar multiplication of a first base point on a first elliptic curve by a nonce value,
[0136] Provide the data representing the signature for securing digital communications.
[0137] According to the present disclosure, the method comprises:
[0138] Receive at least one parameter defining a second elliptic curve birationally equivalent to the first elliptic curve by an isomorphism, and a second base point located on the second elliptic curve and corresponding to the first base point with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type,
[0139] With at least one processor, continue by performing a scalar multiplication of the second base point by an adjusted nonce value on the second elliptic curve, the adjusted nonce value being selected from: the nonce value, and the quotient obtained by dividing the nonce value by an adjustment integer greater than 1 and performing a modulo field order operation; when the adjusted nonce value is the nonce value, the adjustment integer value is 1; and convert the resulting point of the scalar multiplication on the second elliptic curve to a scalar multiplication on the first elliptic curve by a homology map having a degree equal to the adjustment integer and mapping the second base point to a scalar multiplication of the first base point by the adjustment integer.
[0140] The method for generating a signature is preferably performed by a device for generating a signature according to any embodiment of the present disclosure.
[0141] A further further object of the present disclosure is a method for verifying a signature associated with a message from a public key in ECC, the method comprising:
[0142] Receive data representing the signature, the public key, and the message, and at least one parameter defining a first elliptic curve and a first base point located on the first elliptic curve, the first elliptic curve being of the twisted Edwards curve type, the signature including a scalar part associated with a check value and a curve point part representing a check curve point of the first elliptic curve, and the public key representing a public key point of the first elliptic curve,
[0143] Verify the consistency between the signature and the message with at least one processor, by an equation check corresponding to the first elliptic curve, the equation check involving terms based respectively on the signature curve point part, on a scalar multiplication of the first base point by a base point multiplier derived from at least the signature scalar part, and on a scalar multiplication of the public key point by a public key multiplier derived from at least the signature curve point part, at least one of the base point multiplier and the public key multiplier also being derived from the message,
[0144] Provide the authentication result of the equation check for securing digital communications.
[0145] According to the present disclosure, the method includes:
[0146] receiving at least one parameter that defines a second elliptic curve that is birationally equivalent to a first elliptic curve by an isomorphism, and a second base point that lies on the second elliptic curve and corresponds to the first base point with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type,
[0147] using at least one processor, determining, from a public key, a converted public key point of a public key point corresponding to the first elliptic curve with respect to the isomorphic second elliptic curve, performing scalar multiplications of the second base point by a base point multiplier and the converted public key point by a public key multiplier on the second elliptic curve, and performing an equality check on the same curve among the first elliptic curve and the second elliptic curve based on the scalar multiplications and a check curve point.
[0148] The method for verifying a signature is preferably performed by a device for verifying a signature according to any embodiment of the present disclosure.
[0149] Furthermore, the present disclosure relates to a computer program that includes software code adapted to perform, when executed by a processor, the method for generating a public key, the method for generating a signature, and / or the method for verifying a signature according to the present disclosure.
[0150] The present disclosure further relates to a non-transitory program storage device that is readable by a computer and tangibly embodies an instruction program executable by the computer to perform the method for generating a public key, the method for generating a signature, and / or the method for verifying a signature according to the present disclosure.
[0151] Such a non-transitory program storage device may be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor device, or any suitable combination of the foregoing. It should be understood that the following, while providing more specific examples, is merely an illustrative and non-exhaustive list, as will be readily understood by those of ordinary skill in the art: a portable computer disk, a hard disk, a ROM, an EPROM (erasable programmable ROM), a flash memory, a portable CD-ROM (compact disc ROM). BRIEF DESCRIPTION OF THE DRAWINGS
[0152] The present disclosure will be better understood, and other specific features and advantages will become apparent when reading the following description of specific and non-limiting illustrative embodiments, which description refers to the accompanying drawings, in which:
[0153] Figure 1 shows cross-communication of public keys between two corresponding communication entities;
[0154] Figure 2 shows Figure 1The transmission of a signed message between two communication entities after each has obtained the public key of the other entity;
[0155] Figure 3A is a block diagram schematically showing a device for generating a public key in accordance with the present disclosure, which device is utilized by at least one communication entity of Figure 1 and Figure 2 ;
[0156] Figure 3B is a block diagram schematically showing Figure 3A a sub-device of a device for generating a public key, the sub-device including a scalar multiplication function;
[0157] Figure 4A is a block diagram schematically showing a device for generating a signature in accordance with the present disclosure, which device is utilized by at least one communication entity of Figure 1 and Figure 2 ;
[0158] Figure 4B is a block diagram schematically showing Figure 4A a sub-device of a device for generating a signature, the sub-device including a scalar multiplication function;
[0159] Figure 5 is a block diagram of a device dedicated to a scalar multiplication function, which device is utilized in some embodiments of a device for generating a public key of Figure 3A , a device for generating a signature of Figure 4A , or a device that combines the functions of Figure 3A and Figure 3B ;
[0160] Figure 6 is a block diagram schematically showing a device for generating a public key and for generating a signature associated with the generated public key, which device is in accordance with the present disclosure and includes Figure 5 a device dedicated to a scalar multiplication function;
[0161] Figure 7A is a block diagram schematically showing a device for verifying a signature in accordance with the present disclosure, which device is utilized by at least one communication entity of Figure 1 and Figure 2 ;
[0162] Figure 7B is a block diagram schematically showing Figure 7A a sub-device of a device for verifying a signature, the sub-device including a double-base scalar multiplication and an equality checking function;
[0163] Figure 8A is a block diagram schematically showing a variant of a device for verifying a signature in accordance with the present disclosure, which device is by Figure 1and Figure 2 is utilized by at least one communication entity;
[0164] Figure 8B schematically represents Figure 8A a block diagram of a sub-device of a device for verifying a signature, the sub-device including double base scalar multiplication;
[0165] Figure 9 shows successive steps performed by a device for generating a public key as shown by Figure 3A a flowchart;
[0166] Figure 10 shows successive steps performed by a device for generating a public key and a device for generating a signature as shown by Figure 6 a flowchart;
[0167] Figure 11 shows successive steps performed by a device for verifying a public key as shown by Figure 8A a flowchart;
[0168] Figure 12 schematically shows a device integrating Figure 3A , Figure 3B , Figure 4A , Figure 4B , Figure 5 , Figure 6 , Figure 7A , Figure 7B , Figure 8A and Figure 8B or a functional means of a part of the device.
[0169] In the drawings, the figures are not drawn to scale and identical or similar elements are designated by the same reference numerals. Detailed Description
[0170] All of the examples and conditional language recited herein are intended for pedagogical purposes to aid the reader in understanding the principles of the disclosure and the contributions made by the inventors to furthering the art, and are to be construed as not being limited to such specifically recited examples and conditions.
[0171] Moreover, all statements recited herein, including the principles, aspects, and embodiments of the disclosure, as well as specific examples thereof, are intended to cover their structural and functional equivalents. Additionally, it is intended that such equivalents include both currently known equivalents and equivalents developed in the future, i.e., any elements developed that perform the same function regardless of structure.
[0172] Thus, for example, those skilled in the art will understand that the block diagrams presented herein can represent a conceptual view of an illustrative circuit embodying the principles of the present disclosure. Similarly, it will be understood that any flowchart, process schematic, etc. represents various processes that can be substantially represented in a computer-readable medium and thus executed by a computer or processor, whether or not such computer or processor is explicitly shown.
[0173] The functions of the various elements shown in the figures can be provided by using dedicated hardware as well as hardware capable of executing software in association with appropriate software. When provided by a processor, these functions can be provided by a single dedicated processor, a single shared processor, or multiple individual processors, some of which may be shared.
[0174] It should be understood that the elements shown in the figures can be implemented in various forms of hardware, software, or a combination thereof. Preferably, these elements are implemented in a combination of hardware and software on one or more appropriately programmed general-purpose devices, which may include a processor, a memory, and an input / output interface.
[0175] Authentication computing
[0176] The present disclosure relates to secure communication between entities, enabling the authentication of transmitted messages. These entities can include individuals, as well as organizations or objects. Additionally, the communication can occur via one or more wired (e.g., Ethernet), wireless (e.g., WiFi, WiMax - representing Worldwide Interoperability for Microwave Access, or Bluetooth), and / or cellular telecommunications (e.g., UMTS - representing Universal Mobile Telecommunications System, LTE - representing Long Term Evolution, or 5G) networks, or via message storage and retrieval. It involves digital communication as defined above, and authentication utilizes message signatures to check their authenticity.
[0177] For illustration, as Figure 1 shown, a first entity α, which is equipped with a private key Kpriv-α that was previously generated randomly and kept confidential and is inaccessible outside entity α, is generating a public key Kpub-α associated with the private key Kpriv-α to form a key pair and making it available to a second entity β. For example, the public key Kpub-α is transmitted to entity β via a network or a group of two or more networks Net. For security, the public key Kpub-α can be accompanied by a digital certificate Cert-α, i.e., a digital document that attests to the authenticity of the public key Kpub-α and typically includes information about the key, the identity of the subject (i.e., the key owner), and the digital signature of the issuer (i.e., the organization that verified the certificate content).
[0178] The public key Kpub-α may not be communicated by entity α, but instead may be transmitted to entity β, for example, by a centralized system that collects and distributes public keys. Additionally, the public key Kpub-α may be distributed in a secure manner such that it is only available to a selected group of entities and is not easily accessible to others. Further, the public key Kpub-α may not be provided to entity β via network telecommunications, but instead may be recorded on a carrier and later retrieved by entity β by extracting it from the carrier.
[0179] Similarly, entity α obtains the public key Kpub-β from entity β, and this public key is part of a key pair belonging to entity β, which includes the public key Kpub-β and a secure private key Kpriv-β that is only accessible to entity β. The transmission of the public key Kpub-β can be accomplished, for example, via the same network Net as the transmission of the public key Kpub-α to entity β or via other communication media, along with a digital certificate Cert-β. Thus, messages can be authenticated bidirectionally between entities α and β.
[0180] Once equipped with each other's public keys Kpub-α and Kpub-β, entities α and β are ready to authenticate messages msg-β and msg-α received from entities β and α respectively, with associated signatures sgn-β and sgn-α, as Figure 2 shown. Messages msg-α and msg-β can be communicated via the same network Net as used for signature transmission or a recording medium, or by other means. Additionally, the received public key Kpub-α or Kpub-β can be retained and used for multiple subsequent received messages msg-α and msg-β until a new key pair is generated, thereby communicating updated public keys for subsequent message transmissions.
[0181] Entities α and β are equipped with dedicated devices for authentication computations, including public key generation and signature generation on the message sender side, and signature verification on the message receiver side. These devices are based on elliptic curve cryptography (ECC), more specifically on twisted Edwards curves. The specific choice of these curves affects the composition of the public keys derived from the private keys, as well as the composition of the signatures suitable for verification via these public keys. The authentication process can specifically conform to the EdDSA scheme. In an alternative mode, they conform to ECDSA.
[0182] These three authentication aspects, namely public key generation (and thus key pair generation), signature generation, and signature verification, will be elaborated below in connection with devices that can be utilized by one or both of entities α and β. First, it should be noted that the implementation of any one of them does not require the implementation of the others, and there is sufficient freedom in this regard. In particular, entity α can be equipped with one or more of these public devices, while there is no such implementation within entity β, and vice versa. Additionally, any one of the devices for public key generation, the device for signature generation, and the device for signature verification can be implemented without the other devices, and similarly, any combination of any two of them can be implemented without the third. Moreover, these devices provide full compatibility with the ECC authentication process based on twisted Edwards curves, whether traditional, already publicly available, or to be developed in the future.
[0183] The common feature among these devices depends on the utilization of Montgomery curves for each selected twisted Edwards curve. These two curves are birationally equivalent, enabling an isomorphism to be defined between them. More precisely, while the twisted Edwards curve has field parameters Para Ed that include, in particular, the base point G Ed , the Montgomery curve has field parameters Para M that include, in particular, the base point G M , and the aforementioned isomorphism connects the base point G Ed with the base point G M . In each of these devices, some or all of the scalar multiplication calculations on the twisted Edwards curve are shifted to the birationally equivalent Montgomery curve, but any appropriate cross-conversions between the two elliptic curves are required.
[0184] Each device for public key generation, signature generation, and signature verification is preferably an apparatus, or a physical part of an apparatus, that is designed, configured, and / or adapted to perform the mentioned functions and produce the mentioned effects or results. In alternative embodiments, any one of these devices is embodied as a set of apparatuses or physical parts of apparatuses, whether grouped in the same machine or in different, possibly remote machines. These devices can, for example, have functions distributed over a cloud infrastructure and be provided to users as cloud-based services, or have remote functions accessible via an API.
[0185] The devices for public key generation, signature generation, and signature verification can be integrated in the same apparatus or group of apparatuses of a digital authentication system associated with, for example, entity α or β. In other embodiments, the structure of any one of these three devices can be completely independent of the structure of one or both of the other two devices.
[0186] These devices can be applied in various fields, including, for example, IoT (Internet of Things) and blockchain.
[0187] This disclosure relates to asymmetric cryptography and involves the use of key pairs. However, it is also related to symmetric cryptography, as long as ECC scalar multiplication involves authentication calculations - for example, when generating a symmetric key or verifying a message with that key.
[0188] These devices will now be described in detail. Hereinafter, a module should be understood as a functional entity rather than a physically separate component in terms of matter. Thus, they can be embodied as grouped in the same tangible and specific component, or distributed into several such components. In addition, each of these modules may itself be shared between at least two physical components. Additionally, the modules are implemented in hardware, software, firmware, or any combination thereof. They are preferably embodied within at least one processor of the device.
[0189] Device for public key generation
[0190] As Figure 3A and Figure 3B shown, the device 1 for public key generation interacts with the user interface 18 through which the user can input and retrieve information. The user interface 18 includes any suitable means for inputting or retrieving data, information, or instructions, and in particular may include any or several of the following means well-known to those skilled in the art: visual, tactile, and / or audio capabilities of a screen, keyboard, trackball, touchpad, touchscreen, speaker, voice recognition system.
[0191] The device 1 is further connected to one or more local or remote databases 19 from which information can be retrieved or received, and to which information can be recorded. The database 19 can take the form of a storage resource obtainable from any suitable type of storage device, which may in particular be RAM or EEPROM (electrically erasable programmable read-only memory), such as flash memory, possibly within a solid-state drive (SSD). In a variant embodiment, the relevant information can be transmitted to the device 1 via a telecommunications network (such as, in particular, the network Net), for example streamed to the device 1.
[0192] The device 1 is adapted to receive as input the private key Kpriv and the domain parameters Para related to the twisted Edwards curve Ed , including in particular the base point G Ed . The private key Kpriv is typically stored locally and protected against intrusion. The device 1 is further adapted to receive the domain parameters Para related to the birationally equivalent Montgomery curve M , including in particular the base point G Msuch that the isomorphisms defined between twisted Edwards curves and Montgomery curves connect the base points G Ed and G M to each other.
[0193] Device 1 may be adapted to receive, from the user interface 18, data indicating a twisted Edwards curve selected by the user to be exploited in the authentication, and provide a default selection, such as Ed15519. In other modes (preferably in combination with the previous mode), device 1 is adapted to receive such data giving the twisted Edwards curve from a central system or from another entity, for compatibility and / or consistency purposes. Then, device 1 may be configured to retrieve from the database 19 the domain parameters Para Ed .
[0194] Device 1 may be adapted to determine, from, for example, a correspondence table, the identity of the Montgomery curve birationally equivalent to the twisted Edwards curve, and retrieve from the database 19 the domain parameters Para M . In other modes (preferably in combination with the previous mode), device 1 is configured to directly compute the domain parameters Para M from the information related to the considered twisted Edwards curve.
[0195] Twisted Edwards curves are generally defined over a field K of characteristic different from 2, by the following equation involving affine coordinates (x, y) and non-zero parameters a and d in K:
[0196] a x 2 + y 2 = 1 + d x 2 y 2 (4)
[0197] where a ≠ d, and the case where a = 1 is called the untwisted Edwards domain.
[0198] Montgomery curves are generally defined over a field K of characteristic different from 2, by the following equation involving affine coordinates (u, v) and non-zero parameters A and B in K:
[0199] B v 2 = u 3 + A u 2 + u (5)
[0200] where A ≠ ±2, B ≠ 0 and B(A 2 – 4) ≠ 0.
[0201] The birational equivalence between a twisted Edwards curve with parameters a, d and a Montgomery curve with parameters A, B is given by:
[0202] A = 2(a + d) / (a – d), B = 4 / (a – d) (6)
[0203] a = (A + 2) / B, d = (A – 2) / B (7)
[0204] The respective affine coordinates (x, y) and (u, v) of the twisted Edwards curve and the Montgomery curve are then linked by the following mapping equations, where the number c is defined as:
[0205]
[0206] where, when the field K is a quotient structure, c can be defined as the quadratic residue of the term inside the square root:
[0207]
[0208] Points such as x = 0 or y = 1 and u = -1 or v = 0 are excluded.
[0209] In a preferred embodiment, the twisted Edwards curve is of the Ed25519 type as defined above with respect to equation (2). The relevant parameters are then (using hexadecimal notation):
[0210] - Prime field p = 2 255 –19
[0211] - Order (n) =
[0212] 0x1000000000000000000000000000000014DEF9DEA2F79CD65812
[0213] 631A5CF5D3ED
[0214] - Cofactor (h) = 0x08
[0215] - Parameter a = -1 mod p =
[0216] 0x7FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEC
[0217] - Parameter d =
[0218] 0x52036CEE2B6FFE738CC740797779E89800700A4D4141D8AB75EB4DCA135978A3
[0219] - Base point G in affine coordinates (x, y) Ed =
[0220] o 0x216936D3CD6E53FEC0A4E231 FDD6DC5C692CC760952
[0221] 5A7B2C9562D608F25D51A
[0222] o 0x66666666666666666666666666666666666666666666666 66666666666666658
[0224] A Montgomery curve corresponding to the above Ed25519 curve is Curve25519, as previously represented by equation (3). The relevant parameters are then (using hexadecimal notation):
[0225] - Prime field p = 2 255 –19
[0226] - Order (n) =
[0227] 0x1000000000000000000000000000000014DEF9DEA2F79CD65812631A5CF5D3ED
[0228] - Cofactor (h) = 0x08
[0229] - Parameter A = 0x76D06
[0230] - Parameter B = 0x01
[0231] - Base point G in affine coordinates (u, v) M =
[0232] o 0x09
[0233] o 0x20AE19A1B8A086B4E01EDD2C7748D14C923D4D7E6D7
[0234] C61B229E9C5A27ECED3D9
[0235] Device 1 is adapted to output a key pair formed with the private key Kpriv and can be passed based on the domain parameter ParaEd The conventional ECC process for a defined twisted Edwards curve derives the public key Kpub therefrom, as is known to those skilled in the art. However, as will be described below, the determination of this public key Kpub Ed is achieved by computations performed on a Montgomery curve determined by the domain parameters Para Ed . The resulting public key Kpub M is, for example, recorded in the database 19 for subsequent use and / or directly provided to other entities via the network Net. Ed
[0236] The device 1 for public key generation includes an input module 11 adapted to receive the private key Kpriv and the domain parameters Para Ed and Para M , and an output module 16 adapted to provide the public key Kpub Ed .
[0237] The device 1 further includes a module 12 for scalar determination, which is configured to compute an integer scalar s dedicated to performing ECC point multiplication by the base point G Ed from the private key Kpriv. The scalar s can be obtained by applying a cryptographic hash function to the base point G Ed , which can particularly belong to the family known as Secure Hash Algorithm or SHA and is published by NIST (National Institute of Standards and Technology) as a FIPS standard (meaning "Federal Information Processing Standard"). The scalar s can further be obtained by selecting a part of the bits of the hash value derived from the base point G Ed , for example, representing half of the bits of the most significant byte or MSB.
[0238] A module or sub-device 10 (to be elaborated in more detail below) downstream of the scalar determination module 12 is used to produce the scalar multiplication s.G Ed .
[0239] The device 1 further includes a module 14 for encoding the elliptic curve point produced by the scalar multiplication s.G Ed into encoded digits forming the public key Kpub Ed . This can be done particularly by retaining the entire y coordinate of s.G Ed and adding a bit giving the sign of the x coordinate of s.G Ed .
[0240] For example, the twisted Edwards curve is Ed25519:
[0241] - The private key Kpriv has 32 random bytes,
[0242] - The module 12 for scalar determination is configured to compute a hash value h using SHA-512 belonging to the SHA-2 set from the private key Kpriv (internal state size and output size: 64 bytes, block size: 1024 bits),
[0243] - The module 12 for scalar determination is further configured to derive a scalar s from the hash value h as the 32 most significant bytes (i.e., 256 bits) - denoted as s = h.32MSB,
[0244] - The encoding module 14 is configured to compute the public key Kpub of 256 bits based on the point with affine coordinates (x, y) generated by the scalar multiplication s.G Ed by selecting the sign bit of the x coordinate as the bit numbered 255 (denoted as "b255"), and selecting the y coordinate as the bits numbered 254 to 0 respectively (denoted as "b254...0"). Ed 。
[0245] In a variant implementation, for example, using ECDSA instead of EdDSA, the encoding module 14 may be absent or inactive because the public key can be directly communicated in the form of the curve point giving s.G Ed 。
[0246] The sub-device 10 for generating the scalar multiplication s.G Ed as shown, is configured to receive data on the domain parameters Para Figure 3B and Para Ed and the scalar s in the sub-input module 101, optionally convert the base point G M to the base point G Ed through the module 102, perform the scalar multiplication s.G M through the scalar multiplication module 103, derive the scalar multiplication s.G M by converting the elliptic curve point s.G M on the Montgomery curve to the elliptic curve point s.G Ed on the twisted Edwards curve through the conversion module 104, and provide the result of this multiplication through the sub-output module 106. Ed 。
[0247] In some embodiments, the domain parameters Para M of the Montgomery curve already include the base point G M which can be obtained, for example, from the database 19. The module 102 is then absent or inactive.
[0248] In a variant embodiment, the sub-device 10 is configured to compute, for itself, the domain parameters of a Montgomery curve that is birationally equivalent to the twisted Edwards curve of interest, including the base point G M . These parameters can then be stored in the database 19 and retrieved later whenever needed when dealing with the twisted Edwards curve.
[0249] The sub-device 10 itself can have an autonomous structural form, such as an IC (integrated circuit) component. In an advantageous embodiment, the scalar multiplication module 103 is configured to use the projective homogeneous coordinates (U:V:Z) associated with the affine coordinates (u,v), starting from the input affine coordinates (uM,vM) of the base point G M , where:
[0250] U M = u M .Z M , V M = v M .Z M , Z M = 1 (11)
[0251] This can be done by applying the Montgomery ladder to U and Z, thereby obtaining the resulting pair (U,Z) of the desired scalar multiplication s.G M and recovering the second homogeneous coordinate V associated with the point from this pair (U,Z) by, for example, the method set forth in the above-cited reference by K. Okeya and K. Sakurai.
[0252] In an advantageous embodiment, the conversion module 104 is configured to convert the projective homogeneous coordinates (U:V:Z) of the resulting point represented on the Montgomery curve to the affine coordinates (x,y) of the same point represented on the twisted Edwards curve, which point is equal to s.G Ed .
[0253] For example, the calculation is performed as follows, depending on the projective homogeneous coordinates (X:Y:Z') of the point s.G Ed :
[0254] -Montgomery projective (U:V:Z) to Edwards projective (X:Y:Z')
[0255]
[0256] -Edwards projective (X:Y:Z') to Edwards affine (x,y)
[0257]
[0258] The proof of the correlation of Equation (13) is due to the following correspondence with the birational equivalence relation expressed in Equation (10):
[0259]
[0260] Therefore, in such a suitable embodiment, with respect to the domain parameters Para Ed and Para M the required data can be reduced to the base point G M and the conversion coefficient c.
[0261] It is worth noting that the entire conversion calculation requires no more than one modular inverse operation (Z') in addition to six multiplications.
[0262] The reader will appreciate the significant performance enhancement that the sub-device 10 may provide compared to performing the scalar multiplication s.G entirely on the twisted Edwards curve via the Montgomery ladder. The latter is based on the projective homogeneous coordinates (X:Y:Z) of the base point G Ed where X = x·Z, Y = y·Z and Z = 1, and X, Y and Z are used in the ladder. It also involves converting back to the affine coordinates (x,y) (x = X / Z, y = Y / Z) once the result of the scalar multiplication is obtained in the projective homogeneous coordinates, thus requiring one modular inverse operation (Z). It can also be remembered that the Montgomery ladder can be much faster on the Montgomery curve than on the twisted Edwards curve. For illustration, the scalar multiplication s.G Ed performed entirely on the twisted Edwards curve Ed25519 (hereinafter referred to as the "Ed25519 ladder" for brevity) typically requires 5357 multiplications and 1 inversion, considering that each bit requires 21 modular multiplications in the ladder, processing 255 bits, and requires 2 multiplications and 1 modular inverse operation to convert the projective coordinates to the affine coordinates. In contrast, the scalar multiplication s.G Ed performed via the Montgomery curve Curve25519 (hereinafter referred to as the "Curve25519 ladder" for brevity) typically requires 2829 multiplications and 1 inversion, considering that each bit requires 11 modular multiplications in the ladder, processing 255 bits, requires 18 multiplications (more precisely 16 multiplications and 2 squarings) to recover the V coordinate, and requires 6 multiplications and 1 modular inverse operation to convert the projective coordinates in the Montgomery curve to the affine coordinates in the twisted Edwards curve. Therefore, the performance gain reaches approximately 47%. In an alternative embodiment, the twisted Edwards curve and the Montgomery curve are defined over a field of order p, and the base point G of the Montgomery curve Ed is MMap to the base point G of the twisted Edwards curve through a homology mapping of degree L Ed L times, where L is an integer equal to 2 or greater. The integer L is adjusted, for example, retrieved from the database 19, input by the user through the user interface 18, or received through the network Net.
[0263] Module 12 is then configured to replace the scalar s with s / L mod p, such that the sub-module 103 of module 10 multiplies it by the base point G M . In addition, the sub-module 104 is then configured to convert the resulting point from the Montgomery curve to the twisted Edwards curve by using an L-homology mapping instead of an isomorphism as above.
[0264] The solution developed above using the inverse mapping of the isomorphism corresponds to the value of the integer L being 1.
[0265] Device 1 can be equipped with a conversion function associated with a single value of the integer L. In a variant, it is equipped with a conversion function associated with at least two values, one of which may be L = 1. Then, device 1 can be configured to select the integer L among the possible values based on, for example, a command input by the user or data received through the network Net.
[0266] Device for signature generation
[0267] As Figure 4A and Figure 4B shown, the device 2 for signature generation interacts with the user interface 28 and one or more databases 29 in a manner similar to the device 1 for public key generation.
[0268] Device 2 is adapted to be equipped with a private key Kpriv and a message msg, as well as domain parameters Para associated with a twisted Edwards curve Ed , including in particular the base point G Ed . Device 2 is further adapted to receive domain parameters Para associated with a birationally equivalent Montgomery curve M , including in particular the base point G M , such that the isomorphism defined between the twisted Edwards curve and the Montgomery curve interconnects the base point G Ed and G M .
[0269] The above observations regarding the private key Kpriv and the domain parameters Para Ed and Para M and their associated base points G Ed and G M for device 1 also apply to device 2 and will not be repeated here.
[0270] Optionally, device 2 is also adapted to receive a public key Kpub corresponding to the private key Kpriv and based on the parameters Para associated with the concerned twisted Edwards curve Ed . It may have been previously generated by device 1, stored in database 29, and retrieved from that / those databases when a signature sgn needs to be generated. Alternatively, as long as the private key Kpriv and the public key Kpub Ed form a key pair suitable for message authentication, it can be determined or obtained in any other way. Ed
[0271] Device 2 is further adapted to generate a signature sgn associated with the message msg and derived from the private key Kpriv so that it can later be authenticated by the corresponding public key Kpub Ed . For example (see Figure 2 ), device 2 can be used by entity α, which can thus sign the message msg to be sent to entity β, send it together with the associated signature sgn, so that entity β can use the public key Kpub Ed to authenticate the message msg through appropriate signature verification. In this regard, entity β must already have the public key Kpub Ed (see Figure 1 ) and share the same authentication reference with entity α, such as an elliptic curve of ECC type and the domain parameters Para Ed .
[0272] The device 2 for signature generation includes an input module 21 adapted to receive the private key Kpriv and in some embodiments the public key Kpub Ed , the message msg and the domain parameters Para Ed and Para M , and an output module 26 adapted to provide a signature sgn associated with the message msg, the signature sgn being in the form of a number (R, S) comprising two parts R and S, as follows.
[0273] The module 23 for nonce value determination downstream of the input module 21 is configured to determine a nonce value r for generating the two parts R and S of the signature sgn.
[0274] Device 2 also includes a module or sub-device 20 for generating the scalar multiplication r.G Ed , which will be elaborated in more detail below.
[0275] Module 24 is configured to encode the elliptic curve point generated by this scalar multiplication r.G Ed into an encoded number forming part R of the signature sgn.
[0276] In addition, a downstream module 25 for signature calculation is configured to calculate a signature S, which includes a part R and another part S derived from the private key Kpriv, the nonce value r, the message msg, the base point order n, and the part R.
[0277] In some of the currently described modes, signature generation conforms to the EdDSA process. Thus, and as is known to those skilled in the art, module 23 is configured to calculate the nonce value r in the following manner:
[0278] - Apply a cryptographic hash function (which may particularly belong to the SHA family) to the private key Kpriv to obtain a hash value h,
[0279] - Select a part of the bits of the hash value h, such as half of the bits representing the least significant byte or LSB, denoted as Prefix below,
[0280] - Concatenate the part Prefix of the hash value h and the message msg to obtain a number modulo the base point G Ed of order n, i.e., (Prefix||msg) mod n,
[0281] - Perform a further hash calculation on the concatenated number to obtain the nonce value r.
[0282] - Module 25 is then configured in the EdDSA process to:
[0283] - Calculate a number k by concatenating the part R, the public key Kpub Ed and the message msg, and applying a hash function to the resulting concatenation (R||Kpub Ed ||msg),
[0284] - Derive the part S of the signature sgn by calculating (r + k.s) mod n.
[0285] The public key Kpub Ed can be directly received by device 2. In an alternative embodiment, device 2 is configured to calculate the public key Kpub Ed , which can be done by any method known to those skilled in the art, or as done above for device 1. Embodiments combining the features of device 1 and device 2 will be described more specifically below.
[0286] For example:
[0287] - The hash function is SHA-512,
[0288] - The part Prefix includes 32 LSBs, such that Prefix = h.32LSB,
[0289] - The nonce value r = SHA-512(Prefix||msg) mod n,
[0290] - The signature part R is a 256-bit number obtained by encoding the result of the scalar multiplication r.G Ed (with affine coordinates (x, y)), by choosing the sign bit of the x coordinate as b255, and choosing the y coordinate as b254…0,
[0291] - k = SHA-512(R||Kpub Ed ||msg),
[0292] - The signature part S = (r + k.s) mod n,
[0293] - The signature sgn = (R, S).
[0294] In an alternative embodiment, other authentication methods than EdDSA are utilized. For example, device 2 is configured to apply an ECDSA authentication process, which may include (and as is known to those skilled in the art) the following specific functions relative to those described above:
[0295] - Randomly generate a nonce value r with module 23,
[0296] - With module 24, calculate the scalar multiplication r.G through module 20 Ed The resulting curve point, and retain the x coordinate of this point modulo n as the first signature part R, and
[0297] - With module 25, calculate the most significant bit z of the hash value of the message msg (the number of these bits corresponds to the order n) and the second signature part S, calculated as r-1·(z + R.Kpriv) mod n, which is equivalent to making the scalar s equal to the private key Kpriv, such that sgn = (R, S).
[0298] Thus, contrary to the EdDSA scheme, the public key Kpub Ed is not utilized in ECDSA.
[0299] In an alternative ECDSA mode, module 23 is configured to deterministically generate a nonce value from the private key Kpriv and the message msg.
[0300] Device 2 may have multiple authentication capabilities and can thus perform, for example, both EdDSA and ECDSA functions.
[0301] The sub-device 20 for generating the scalar multiplication r.G Ed as Figure 4B shown, is configured to receive information about the domain parameters Para Ed and ParaM and data of the nonce value r, optionally converting the base point G through module 202 Ed to base point G M , performing scalar multiplication r.G through scalar multiplication module 203 M , through conversion module 204 by converting the elliptic curve point r.G on the Montgomery curve M to an elliptic curve point r.G on the twisted Edwards curve Ed to derive the scalar multiplication r.G Ed , and providing the result of this multiplication through sub-output module 206.
[0302] In some embodiments, the domain parameters Para of the Montgomery curve M already include the base point G M , which can be obtained, for example, from database 29. Module 202 is then absent or inactive.
[0303] In a variant embodiment, the sub-device 20 is configured to calculate itself the domain parameters of a Montgomery curve that is birationally equivalent to the concerned twisted Edwards curve, including the base point G M . These parameters can then be stored in database 29 and retrieved later whenever needed when related to the twisted Edwards curve.
[0304] Since its working manner may be the same as that of sub-device 10, the reader is referred to the above disclosure of the latter for further description.
[0305] In fact, in view of the mechanism of performing scalar multiplication s.G through sub-device 10 Ed and performing scalar multiplication r.G through sub-device 20 Ed may be the same, the same entity can be utilized. This entity constituting device or sub-device 30, as Figure 5 shown, can take the form of, for example, an autonomous function (such as a computer program) or a structural (such as an IC component) element. It can be integrated in a device for generating a public key (such as device 1 in particular), integrated in a device for generating a signature (such as device 2 in particular), or mutually utilized in a device having both functions as follows.
[0306] Device 30 includes an input module 301 adapted to receive a scalar ρ and a base point G M , an optional module 302 for converting the base point G Ed to base point G M , a scalar multiplication module 303 configured to perform scalar multiplication ρ·G M , and configured to convert the elliptic curve point ρ·G on the Montgomery curveM Convert to an elliptic curve point ρ·G on a twisted Edwards curve Ed to derive the scalar multiplication ρ·G Ed a conversion module 304, and an output module adapted to provide the resulting point.
[0307] It will be clear to the reader that all the observations made above regarding sub-devices 10 and 20 are also valid for device 3 and are therefore not repeated here.
[0308] Device 3, which combines public key generation and signature generation, as Figure 6 shown, utilizes sub-device 30 to determine the scalar multiplications s.G Ed and r.G Ed .
[0309] Based on the previous definitions and characteristics, device 3 includes an input module 31 adapted to receive a private key Kpriv, a message msg, domain parameters Para Ed and Para M , and to receive the public key Kpub associated with the private key Kpriv when it is already available Ed a message msg, domain parameters Para
[0310] It further includes a module 32 for scalar determination and a module 33 for nonce value determination, which are respectively configured to determine a scalar s and a nonce value r.
[0311] Sub-device 30 is arranged downstream of module 32 and module 33 and is configured to receive relevant data regarding domain parameters Para Ed and Para M , including the base point G M , the scalar s and the nonce value r, and to produce the scalar multiplications s.G Ed and r.G Ed based on calculations on a Montgomery curve.
[0312] Device 3 further includes an encoding module 34, which is configured to encode s.G Ed as the public key Kpub Ed when the public key Kpub Ed is not yet available, and to encode r.G Ed as the signature part R.
[0313] Module 35 is configured to calculate the signature sgn corresponding to the message msg, by receiving the signature part R and, when required by the authentication method (especially for EdDSA), the public key Kpub Ed , as well as the message msg, the nonce value r, the scalar s and the base point order n, and to derive the signature part S such that sgn = (R,S).
[0314] The device 3 further comprises a device adapted to provide a public key Kpub Ed and an output module 36 of the signature sgn associated with the message msg.
[0315] Furthermore, device 3 interacts with a user interface 38 and one or more databases 39 , similar to the user interfaces and databases of devices 1 and 2 .
[0316] It is worth noting that the public key Kpub is generated Ed The calculations related to the signature sgn are not necessarily performed within the framework of the same step, but can be done successively and selectively. For example, the device 3 can be used only to generate the public key Kpub after randomly generating a new private key Kpriv. Ed , so that the public key Kpub Ed is stored in database 39 until needed for signature generation. Device 3 may alternatively be used only for the generation of a signature based on a previously calculated public key Kpub Ed Signature generation is performed until the private key Kpriv needs to be updated or due to different domain parameters Para associated with the utilized twisted Edwards curve Ed And you need to calculate the new public key Kpub Ed Device 3 can also be used to generate a public key Kpub for a given message msg Ed and signed sgn.
[0317] In an alternative embodiment, the twisted Edwards curve and the Montgomery curve are defined on a domain of order p, and the base point G of the Montgomery curve is M Mapped to the base point G of the twisted Edwards curve by a homology map of degree L Ed L times, where L is an integer equal to 2 or greater. The adjustment integer L is retrieved, for example, from the database 29 or 39, input by a user through the user interface 28 or 38, or received through the network Net. The modules 22 and 23, or modules 32 and 33, are then configured to replace the scalar s and the nonce value r with s / L mod p and r / L mod p, respectively, so that the submodule 203 of the module 20 or the submodule 303 of the module 30 multiplies them by the base point G M Furthermore, the submodule 204 or 304 is then configured to convert the resulting points from the Montgomery curve to the twisted Edwards curve by using an L-homologous mapping instead of the isomorphism as above. The solution developed above using the inverse mapping of the isomorphism corresponds to the integer L having a value of 1.
[0318] Device 2 or device 3 may be equipped with a conversion function associated with a single value of the integer L. In a variant, it is equipped with a conversion function associated with at least two values, one of which may be L = 1. Then, device 2 or device 3 may be configured to select the integer L among the possible values based on, for example, a command input by the user or data received via the network Net.
[0319] Device for signature verification
[0320] Device 4 for signature verification, as Figure 7A and Figure 7B shown, may be utilized in cooperation with one of devices 1, 2, and 3, or may have no relation to these devices. It may in particular be utilized by entity β when receiving a signed message msg from entity α to authenticate the message (see Figure 2 ).
[0321] Device 4 interacts with the user interface 48 and one or more databases 49 in a manner similar to that of devices 1, 2, and 3 described previously.
[0322] Device 4 is adapted to receive the message msg and the associated signature sgn comprising two parts R and S, as well as the public key Kpub associated with the signature sgn and possibly already available to entity β in a previous step Ed (see Figure 1 ). Device 4 is further adapted to receive the domain parameters Para of a twisted Edwards curve Ed (including in particular the base point G Ed ), as well as the parameters Para M including in particular the base point G M corresponding to a Montgomery curve birationally equivalent to the considered twisted Edwards curve.
[0323] For example, the public key Kpub Ed and the message msg together with its signature sgn are received from entity α via the network Net, while the domain parameters Para Ed and Para M are locally available in the database and can be retrieved when authentication calculations are required.
[0324] As is known to those skilled in the art, although the private key can be determined randomly, the public key Kpub Ed and the signature sgn are closely related to the authentication scheme, and in the case of this ECC, particularly depend on the domain parameters Para Edand the ECC signature process utilized, such as in particular EdDSA or ECDSA. In this regard, flags or other indicators pointing to the selected type of twisted Edwards curve and / or ECC signature process can also be received by device 4 from entity α or from a centralized system. This can, for example, take the form of metadata in a packet header. In a variant embodiment, the ECC mode has been agreed upon between the communication entities, so no conventional associated transmission is required.
[0325] Device 4 is configured to output an authentication decision in the form of a binary result Auth. The latter is, for example, "true" or 1 in case of successful authentication and "false" or 0 in case of failure.
[0326] More precisely, device 4 for signature verification includes an input terminal 41 adapted to receive a message msg, a signature sgn, a public key Kpub Ed and domain parameters Para Ed and Para M and an output terminal 46 adapted to generate the result Auth.
[0327] Device 4 is further equipped with a modular exponentiation module 42 configured to recover, in the considered twisted Edwards curve, the check curve point R' Ed and the public key point Kpub' Ed respectively from the signature part R and the public key Kpub Ed . This is typically done by inverting the encoding calculations described above for encoding modules 14, 24, and 34. For example, if the public key Kpub Ed is a 256-bit number generated by selecting the sign bit of the x coordinate as b255 and the y coordinate as b254…0 in s.G Ed , the public key point Kpub' is obtained by retrieving y and reconstructing x from the twisted Edwards curve equation and the obtained x sign. Ed . The encoding process can be known to device 4 as something shared between the communication entities or derived from an indicator transmitted, for example, by entity α that sends the public key Kpub Ed or the message msg.
[0328] Device 4 also includes a scalar determination module 44 configured to calculate a scalar k from the received signature sgn, public key Kpub Ed , message msg, and base point order n.
[0329] In a particular mode, such as in particular based on the EdDSA scheme, the scalar k can be obtained by:
[0330] - concatenating the signature part R, the public key Kpub Ed and the message msg, and
[0331] - Apply a hash function to the connected numbers and take the result value modulo the base point order n, for example
[0332] k = SHA-512(R||Kpub Ed ||msg) mod n
[0333] The downstream sub-device 40 is configured to perform calculations related to checking equations, that is, to verify whether two calculated terms are the same. If the response is affirmative, the result Auth is set to true, and if the response is negative, it is set to false.
[0334] The authentication check is equivalent to verifying whether the following relationship is satisfied:
[0335] S.G Ed + k0.Kpub’ Ed = R’ Ed , k0 = n – k (14)
[0336] However, the sub-device 40 is configured to perform this verification on the Montgomery curve instead of the twisted Edwards curve:
[0337] S.G M + k0.Kpub’ M = R’ M , k0 = n -– k (15)
[0338] Due to the isomorphism between these elliptic curves, this yields the same result, where Kpub’ M and R’ M are respectively the conversions of Kpub’ Ed and R’ Ed from the twisted Edwards curve to the corresponding Montgomery curve.
[0339] More precisely, the sub-device 40 includes a sub-input module 401 adapted to receive the signature part S, the verification curve point R’ Ed and the public key point Kpub’ Ed , the scalar k0, and related information related to the domain parameters Para Ed and Para M , and a sub-output module 406 adapted to provide the result Auth.
[0340] The sub-device 40 further includes a conversion module 402 configured to convert the verification curve point R’ Ed and the public key point Kpub’ Ed from the twisted Edwards curve to the points R’ M and Kpub’ in the Montgomery curve respectivelyM for computing the double - base scalar multiplication S.G M +k0.Kpub’ M Module 403, and an equation checking module 405, which is configured to verify whether equation (15) is satisfied and produce an appropriate result Auth.
[0341] In some modes, the base point G M is already known and retrievable from database 49, so the conversion module 402 does not need to perform its determination. In a variant mode, the conversion module 402 is adapted to calculate the base point G Ed and Kpub’ Ed in addition to R’ Ed by converting the base point G M from the twisted Edwards curve to the Montgomery curve.
[0342] The sub - device 40 enables a significant computational gain in some embodiments, due to the potential efficiency of scalar multiplication on the Montgomery curve compared to the twisted Edwards curve. The module 403 for computing the double - base scalar multiplication can further utilize an efficient computational technique specifically for double - base scalar multiplication, rather than performing scalar multiplication for each term (S.G M and k0.Kpub’ M ) and then their addition. Such an approach can specifically include the "Shamir trick", as described by C. Doche and L. Imbert in "The Double - Base Number System in Elliptic Curve Cryptography", 42nd Asilomar Conference on Signals, Systems, and Computers, pp. 777 - 780, Pacific Grove, October 2008.
[0343] Furthermore, performing the equation check on the Montgomery curve instead of the twisted Edwards curve avoids the additional computations required to convert the point data from the Montgomery curve back to the twisted Edwards curve before performing such verification.
[0344] Specific embodiments are described below in connection with the choice of coordinate system. In an advantageous related mode, the conversion module 402 has the following functions. Checking the curve points R’ Ed and the public - key point Kpub’ Ed are respectively represented by the affine coordinates (x R ,y R ),(x K ,y K)Given. The latter is respectively converted into the projective homogeneous coordinates (U R :V R :Z R ) and (U K :V K :Z K ) in the Montgomery curve through the following conversion calculations from Edwards affine coordinates (x, y) to Montgomery projective coordinates (U:V:Z):
[0345]
[0346] The module 403 for calculating the double - base scalar multiplication is then configured to perform the calculation using the projective homogeneous coordinates to obtain the curve point S.G represented by the projective homogeneous coordinates (U0:V0:Z0) in the Montgomery curve M +k0.Kpub’ M .
[0347] Some implementation schemes constructed based on some modified versions of the Montgomery ladder and these projective coordinates can provide particularly efficient processing. In such an implementation scheme, the scalar multiplication algorithm applied to the Montgomery curve utilizes the input projective homogeneous coordinates (U:V:Z) of the point P, rather than using the affine coordinates (u, v) as usual, while using the traditional first ladder point P1 and the second ladder point P2, whose respective homogeneous coordinates are (U1:V1:Z1) and (U2:V2:Z2). The related algorithm for P1 recovery (P1 rec) is derived from the Montgomery ladder on the Montgomery curve as follows, where P2 = P1 + P, referring to the representation set forth by K. Okeya and K. Sakurai in their above - cited article:
[0348]
[0349] such that the relationship (U1 rec :V1 rec :Z1 rec )=(U1:V1:Z1) holds.
[0350] Then the related algorithm can be written as:
[0351] Input: U, V, Z, U1, Z1, U2, Z2
[0352] Output: U1 rec ,V1 rec ,Z1 rec
[0353]
[0354]
[0355] As those skilled in the art will observe, the algorithm is obtained by multiplying the equations of the existing Montgomery ladder by Z 2 .
[0356] Notably, the algorithm works without the need for modular inversion, even though the input Z is not equal to 1, which is contrary to the conventional Montgomery ladder scheme where the input Z is set to 1. Considering that this process is applied to the derived points R' Ed and Kpub' Ed , this proves to be particularly valuable.
[0357] Furthermore, another notable feature is the use of the input projective homogeneous coordinates U, V, and Z instead of the affine coordinates u and v. This also enables calculations to be performed without the need for modular inversion, provided that the curve points R' Ed and Kpub' Ed are given by their homogeneous coordinates (the latter are also used for the base point G M ).
[0358] In fact, the introduced algorithm only requires 14 multiplications and 1 squaring, without the need for modular inversion, while the Montgomery ladder scheme applied to the Montgomery curve requires 12 multiplications and 1 squaring. Therefore, this adaptation may still be quite attractive compared to performing scalar multiplication in the twisted Edwards curve. Based on the utilization of projective homogeneous coordinates, module 405 is configured to directly verify the authenticity of equation (15) in the Montgomery curve, without the need to convert back to the twisted Edwards curve or to affine coordinates, by:
[0359] U0.Z R = U R .Z0, V0.Z R = V R .Z0 (18)
[0360] Indeed, equation (18) is equivalent to checking for the affine coordinates (x0, y0) corresponding to the projective homogeneous coordinates (U0:V0:Z0):
[0361] u0 = U0 / Z0 = U R / Z R = u R , v0 = V0 / Z0 = V R / Z R = v R
[0362] Therefore, modular inversion is not involved in the verification of this equation (18).
[0363] Generally speaking, by leveraging the above - disclosed scheme that relies on projective homogeneous coordinates, EdDSA signature verification can be performed end - to - end without any modular inversion operations.
[0364] Although the sub - device 40 is currently part of device 4, it can be implemented in an autonomous form, functionally (e.g., dedicated software) and / or structurally (e.g., specific IC components).
[0365] The following is combined with Figure 8A and Figure 8B Other embodiments related to signature verification are described. The device 5 for signature verification is similar to device 4, but the difference is that the equality check is performed on a twisted Edwards curve instead of a Montgomery curve.
[0366] Therefore, the way device 5 interacts with the user interface 58 and the database 59 is similar to the way device 4 interacts with the user interface 48 and the database 49, and includes an input module 51, an exponentiation module 52, a scalar determination module 53, and an output module 56 that are respectively similar to the input module 41, the exponentiation module 42, the scalar determination module 43, and the output module 46.
[0367] Device 5 also includes a sub - device 50, which is configured to determine the curve point S.G Ed +k0.Kpub’ Ed , but through double - base scalar multiplication on a Montgomery curve instead of a twisted Edwards curve. The downstream module 55 for equality check is responsible for determining whether equation (14) is satisfied based on the received above - mentioned curve point and providing an authentication result Auth, just as done when performing signature verification on a twisted Edwards curve.
[0368] By returning to the twisted Edwards curve for equality check instead of staying on the Montgomery curve as was done previously with device 4, additional calculations are required. However, doing so may have some benefits in certain cases to leverage an existing system - where verification is performed on a twisted Edwards curve.
[0369] More precisely, as Figure 8B shown, the sub - device 50 includes a sub - input module 501 and a sub - output module 506, a conversion module 502, which is configured to convert the public - key point Kpub’ in the twisted Edwards curve Ed to the public - key point Kpub’ in the Montgomery curve M , and is responsible for performing double - base scalar multiplication S.G M +k0.Kpub’ Mmodule 503, and an inverse conversion module 504, which is configured to convert the resulting curve points back to the twisted Edwards curve.
[0370] The conversion module 502 may be further adapted to convert the base point G M when it is not available to the base point G Ed to the base point G M , but the function for converting the verification curve point R' Ed is not required, as the latter is only utilized by the module 55 downstream of the sub-device 50 in the twisted Edwards curve.
[0371] In a specific mode, the conversion module 502 is configured to convert the affine coordinates of the curve points in the twisted Edwards curve to the projective homogeneous coordinates of these points represented in the Montgomery curve, as previously done with the device 4. Similarly, the module 503 is configured to apply the modified Montgomery ladder when calculating the double base scalar product, as described above.
[0372] If projective homogeneous coordinates are utilized, in a specific embodiment, the inverse conversion module 504 is adapted to convert the curve points given by S.G M +k0.Kpub’ M to the corresponding curve points in the twisted Edwards curve by equation (12), where the point is represented by the projective homogeneous coordinates (U0:V0:Z0) there.
[0373] The equation check module 55 is then adapted to directly perform the verification of equation (14) on the twisted Edwards curve in projective coordinates, rather than switching to affine coordinates before verification. By considering the projective homogeneous coordinates (U0:V0:Z0) of the resulting curve points in the twisted Edwards curve and the projective homogeneous coordinates (U Ed :V R :Z R :Z R ) of the verification curve point R', it is necessary to verify equation (18) to determine the authentication result Auth.
[0374] Therefore, modular inverse operations are not involved in the verification of this equation (18).
[0375] In a variant embodiment, the ECDSA scheme is used instead of the EdDSA scheme. The scalar determination module 53 may then be responsible for determining the most significant bit z of the hash value derived from the message msg and calculating two scalars ρ1 = z.S -1 mod n h and ρ2 = R.S -1 mod n.
[0376] The sub-device 50 is then adapted to use the public key Kpub’ EdConvert to the public key Kpub’ in the Montgomery curve M and perform a double - base scalar multiplication ρ1G M +ρ2Kpub’ M and convert the result of these calculations back to the twisted Edwards curve.
[0377] Module 55 is configured to, based on the obtained curve points, corresponding to the double - base scalar multiplication:
[0378] ρ1G Ed +ρ2Kpub’ Ed
[0379] Verify whether its x - coordinate is congruent to R modulo the base - point order n. Depending on whether this congruence holds, the signature is respectively valid or invalid.
[0380] As was done previously with the EdDSA implementation, projective homogeneous coordinates can be advantageously utilized. In a particular related embodiment, the affine coordinates in the twisted Edwards curve are converted to projective homogeneous coordinates in the Montgomery curve, and the modified Montgomery ladder is applied to the scalar multiplication, resulting in:
[0381] ρ1G M +ρ2Kpub’ M
[0382] And the resulting point is converted back to the twisted Edwards curve in projective homogeneous coordinates. Then the above verification can be expressed as X / Z' being congruent to R modulo n based on the resulting homogeneous coordinates (X:Y:Z').
[0383] Although the sub - device 50 is currently part of device 5, it can be implemented autonomously, both functionally (e.g., dedicated software) and / or structurally (e.g., specific IC components).
[0384] Device 4 or device 5 can be integrated with device 1, device 2, or device 3 in the same system and share mutualized functions, especially for the conversion between the twisted Edwards curve and the Montgomery curve and / or scalar multiplication on the Montgomery curve, such as part or all of the modified Montgomery ladder.
[0385] Authentication process
[0386] In the calculation, for generating the public key Kpub Ed on a twisted Edwards curve that is birationally equivalent to a Montgomery curve with a base - point G M and having an available base - point G Ed device 1 can, for example, perform the following process 6, in combination withFigure 9 :
[0387] Determine the scalar s from the private key Kpriv (step 62),
[0388] Produce the result of the scalar multiplication s.G Ed by computing the scalar multiplication s.G on the Montgomery curve M The resulting point (step 603) and convert it to the Edwards curve (step 604), and encode the resulting curve point as the public key Kpub Ed (step 64).
[0389] For use on a twisted Edwards curve that has a base point G Ed and is birationally equivalent to a Montgomery curve with an available base point G M to generate a signature sgn for a message msg and a known public key Kpub Ed Device 2 or device 3 can perform the following process 7, for example (deterministic nonce value, especially for EdDSA), in combination with Figure 10 :
[0390] Determine the scalar s from the private key Kpriv (step 72),
[0391] Determine the nonce value r from the private key Kpriv, the message msg, and the base point order n (step 73),
[0392] Produce the result of the scalar multiplication r.G Ed by computing the scalar multiplication r.G on the Montgomery curve M The resulting point (step 703) and convert it to the Edwards curve (step 704), and encode the resulting curve point as part R of the signature sgn (step 74),
[0393] Calculate the other part S of the signature sgn by using the signature part R, the public key Kpub Ed (not used for the ECDSA scheme), the message msg, the scalar s, the nonce value r, and the order n, thus calculating the signature sgn = (R, S) (step 75).
[0394] For use on a twisted Edwards curve that has a base point G Ed and is birationally equivalent to a Montgomery curve with an available base point G M to verify a signature sgn = (R, S) based on the public key Kpub Ed for a message msg, device 4 or device 5 can perform the following process 8, for example (in the EdDSA scheme), in combination with Figure 11: Decode the R part of the signature sgn to the check curve point R' by exponentiation Ed , and decode the public key Kpub Ed to the public key point Kpub' on the twisted Edwards curve Ed (Step 82).
[0395] Determine the scalar k0 from the signature part R, the public key Kpub Ed , the message msg, and the base point order n (Step 83), determine the curve point generated by the double - base scalar multiplication on the Montgomery curve (Step 80), convert the public key point Kpub' Ed from the twisted Edwards curve to the Montgomery curve as Kpub' M , and for device 4, convert the check curve point R' Ed to R' M (Step 802), and perform the double - base scalar multiplication S.G M + k0.Kpub' M (Step 803).
[0396] Generate an authentication equation S.G Ed + k0.Kpub' Ed = R' Ed for the authenticity authentication result Auth (Step 85), or for device 4, on the Montgomery curve (S.G M + k0.Kpub' M = R' M ) based on the obtained curve point and the converted check curve point R' M , or for device 5, on the twisted Edwards curve based on converting the obtained curve point back to the twisted Edwards curve reversely.
[0397] Authentication device
[0398] Specific device 9, visible in Figure 12 , embodies device 3 for public key and signature generation and device 4 for signature verification as described above. It corresponds, for example, to a mainframe computer, a workstation, a laptop, a tablet, a smartphone, or a head - mounted display (HMD).
[0399] This device 9 is adapted to generate a public key, generate a signature, and verify a signature. It includes the following elements, interconnected with each other via an address and data bus 95 that also transmits clock signals:
[0400] A microprocessor 91 (or CPU);
[0401] Graphics card 92, including a number of graphics processing units (or GPUs) 920 and graphical random access memory (GRAM) 921; due to its highly parallel structure, the GPU is very suitable for performing repetitive calculations on cryptographic data;
[0402] ROM type non-volatile memory 96;
[0403] RAM 97;
[0404] One or more I / O (input / output) devices 94, such as a keyboard, mouse, trackball, webcam; other modes for introducing commands, such as voice recognition, are also possible;
[0405] Power supply 98; and
[0406] Radio frequency unit 99.
[0407] According to a variant, the power supply 98 is located outside the device 9.
[0408] The device 9 also includes a display device 93 of the display screen type, directly connected to the graphics card 92 to display digital communications associated with the cryptographic processes performed by the device 9. The advantage of connecting the display device 93 to the graphics card 92 using a dedicated bus 930 is a greater data transfer bit rate, thus reducing the latency time for displaying the digital communication content. According to a variant, the display device is located outside the device 9 and is connected to the device 9 by a cable or wirelessly to transmit the display signal. The device 9, for example through the graphics card 92, includes a transmission or connection interface for transmitting the display signal to an external display device (such as an LCD or plasma screen or video projector). In this regard, the RF unit 99 can be used for wireless transmission.
[0409] It should be noted that the term "register" used in the following description of the memories 97 and 921 can specify a low-capacity (some binary data) storage area as well as a high-capacity (capable of storing the entire program or all or part of the data representing the calculations or data to be displayed) storage area in each of the memories mentioned. In addition, the registers represented by RAM 97 and GRAM 921 can be arranged and configured in any way, and each of them does not necessarily correspond to adjacent storage locations and can be distributed in other ways (this particularly covers the case where one register includes several smaller registers).
[0410] When the power is turned on, the microprocessor 91 loads and executes the instructions of the program contained in the RAM 97. The random access memory 97 particularly includes:
[0411] In the register 970, the calculation program of the microprocessor 91;
[0412] In register 971, the domain parameters Para of the twisted Edwards curve Ed and the domain parameters Para of the Montgomery curve M ;
[0413] In register 972, the private key Kpriv and the public key Kpub Ed ;
[0414] In register 973, the hash parameter, the scalar s, the nonce value r, the scalar k0;
[0415] In register 974, the signature sgn and the authentication result Auth.
[0416] The algorithm implementing the method steps specific to and as above of the present disclosure is stored in the memory GRAM 921. When power is turned on and once the parameters 971 to 974 are loaded into the RAM 97, the graphics processor 920 of the graphics card 92 loads the appropriate information and parameters into the GRAM 921 and executes the instructions of the algorithm in the form of microprograms.
[0417] The random access memory GRAM 921 particularly includes:
[0418] In register 9211, the scalar s and the base point G M ;
[0419] In register 9212, the scalar multiplication point s.G M and r.G M ;
[0420] In register 9213, the scalar multiplication point s.G Ed and r.G Ed ;
[0421] In register 9214, the exponentiation result Kpub’ Ed and R’ Ed ;
[0422] In register 9215, the converted point Kpub’ M and R’ M ;
[0423] In register 9216, the double-base scalar multiplication S.G M +k0.Kpub’ M .
[0424] As will be understood by those skilled in the art, the presence of the graphics card 92 is not mandatory and can be particularly replaced by full CPU processing.
[0425] In the variant mode, the device 9 may include the functions of the device 1 for generating a public key, the device 2 for generating a signature, and / or the device 5 for verifying a signature.
[0426] Furthermore, the devices 1 to 5 may be implemented in a manner different from stand-alone software, and may utilize a device or a group of devices that only includes a part of the device 9, such as the functions of the sub-devices 10, 20, 30, 40, and / or 50, which may be done, for example, locally or through an API call or through a secure cloud interface.
Claims
1. A device (1, 10; Ed ) for generating a public key (Kpub 3, 30), the device comprising: - At least one input terminal (11, 101; 31, 301), configured to receive data (Kpriv, h, s) representing the private key, and at least one parameter (q, n, a, d, G Ed ), where the at least one parameter defines a first elliptic curve (Ed25519) and a first base point (G Ed ) located on the first elliptic curve, the first elliptic curve being on a finite field having a field order (p), and the first elliptic curve being of the twisted Edwards curve type; - At least one processor configured to compute data representing the public key (Kpub Ed ) from data representing the private key by performing scalar multiplication (s.G Ed ) of the first base point (G Ed ) on the first elliptic curve by a scalar (s) derived from the private key, where the computed data is (s.G Ed , Kpub Ed ); - At least one output terminal (16, 106; 36, 306), configured to provide the data representing the public key for protecting digital communication; Characterized in that: - The at least one input terminal is configured to receive at least one parameter (q, n, A, B, G M ), the at least one parameter defining a second elliptic curve (Curve25519) and a second base point (G M ) located on the second elliptic curve, the second elliptic curve being birationally equivalent to the first elliptic curve (Ed25519) by an isomorphism, the second base point corresponding to the first base point (G Ed ) with respect to the isomorphism, and the second elliptic curve being of the Montgomery curve type; - The at least one processor is configured to: Performing scalar multiplication (s·G M ; s’·G M ) on the second base point (G M ) on the second elliptic curve by at least one adjustment scalar (s; s’), where the at least one adjustment scalar is selected from: the scalar (s) derived from the private key, and at least one quotient (s’) obtained by dividing the scalar (s) by at least one adjustment integer (L) greater than 1 respectively and performing an operation modulo the field order (p); When the adjustment scalar consists of the scalar(s), the value of the at least one adjustment integer is 1; and Convert the result point obtained by the scalar multiplication on the second elliptic curve to the scalar multiplication (s.G Ed ) on the first elliptic curve through at least one isogeny, where the degree of the at least one isogeny is respectively equal to the at least one adjustment integer, and map the second base point to at least one scalar multiplication (L·G Ed ) of the first base point according to the respective adjustment integers.
2. A device (2, 20; 3, 30) for generating a signature (R, S) associated with a message (msg) from a private key (Kpriv) in elliptic curve cryptography, the device comprising: - At least one input terminal (21, 201; 31, 301), configured to receive data (Kpriv, h, s, Prefix, r) representing the private key and the message, and at least one parameter (q, n, a, d, G Ed ), the at least one parameter defining a first elliptic curve (Ed25519) and a first base point (G Ed ) located on the first elliptic curve, the first elliptic curve being on a finite field having a field order (p), the first elliptic curve being of the twisted Edwards curve type; - At least one processor configured to calculate data representing the signature (r.G Ed , R, k, S) from data representing the private key and the message by performing scalar multiplication (r.G Ed ) of the first base point (G Ed ) on the first elliptic curve by a nonce value (r); - At least one output terminal (26, 206; 36, 306), configured to provide the data representing the signature for protecting digital communication; Characterized in that: - The at least one input is configured to receive at least one parameter (q, n, A, B, G M ), the at least one parameter defining a second elliptic curve (Curve25519) and a second base point (G M ) located on the second elliptic curve, the second elliptic curve being birationally equivalent to the first elliptic curve (Ed25519) by an isomorphism, the second base point corresponding to the first base point (G Ed ) with respect to the isomorphism, the second elliptic curve being of the Montgomery curve type; - The at least one processor is configured to: Perform scalar multiplication (r·G M ; r'·G M ) on the second base point (G M ) on the second elliptic curve with at least one adjusted nonce value (r; r'), where the at least one adjusted nonce value is selected from: the nonce value (r), and at least one quotient (r') obtained by dividing the nonce value (r) by at least one adjustment integer (L) greater than 1 and performing modulo operation on the field order (p); When the adjustment nonce value consists of the nonce value (r), the value of the adjustment integer is 1; And Convert the result point obtained by the scalar multiplication on the second elliptic curve to the scalar multiplication (r·G Ed ) on the first elliptic curve through at least one isogeny, where the degree of the at least one isogeny is respectively equal to the at least one adjustment integer, and map the second base point to at least one scalar multiplication (L·G Ed ) of the first base point according to the respective adjustment integers.
3. The apparatus (3, 30) for generating a signature (R, S) according to claim 2, characterized in that, The device for generating a signature includes the device for generating a public key according to claim 1.
4. The device (1, 10; 2, 20; 3, 30) according to any one of the preceding claims, characterized in that, The at least one processor is configured to perform the scalar multiplication (s.G M , r.G M ; s’.G M , r’.G M ) on the second elliptic curve (Curve25519) in an extended coordinate representation involving at least three coordinates (U:V:Z) rather than in an affine representation involving two coordinates (u, v), the extended coordinate representation being adapted to switch between the affine representation on the first elliptic curve and the extended coordinate representation on the second elliptic curve such that the scalar multiplication is performed without modular inversion in the extended coordinate representation; and is configured to convert the extended coordinate representation of the resulting point on the second elliptic curve to the affine representation of the scalar multiplication (s.G Ed , r.G Ed ) on the first elliptic curve (Ed25519).
5. The device (1, 10; 2, 20; 3, 30) for generating a signature (R, S) according to claim 4, characterized in that, The extended coordinate representation is a projective coordinate representation in which a point defined by the at least three coordinates remains unchanged by multiplying the at least three coordinates by the same coefficient, and the at least one processor is configured to convert the extended coordinate representation of the resulting point on the second elliptic curve (Curve25519) to the affine representation of the scalar multiplication (s.G Ed , r.G Ed ) on the first elliptic curve (Ed25519).
6. A device (4, 40; Ed ) for verifying a signature (R, S) associated with a message (msg) from a public key (Kpub 5, 50), the device comprising: - At least one input terminal (41, 401; 51, 501), configured to receive data (R, R’ Ed , S, Kpub Ed , Kpub’ Ed , k0) representing the signature, the public key, and the message, and at least one parameter (q, n, a, d, G Ed ) defining a first elliptic curve (Ed25519) and a first base point (G Ed ) located on the first elliptic curve, the first elliptic curve being of the twisted Edwards curve type; wherein: The signature (R, S) includes a scalar part associated with the check value (S) and a curve point part (R) representing the check curve point (R’ Ed ) of the first elliptic curve; and The public key (Kpub Ed ) represents the public key point (Kpub’ Ed ) of the first elliptic curve; - At least one processor, configured to verify the consistency between the signature and the message through an equation check corresponding to the first elliptic curve, the equation check involving terms respectively based on: The signature curve point part (R’ Ed ; R); For said first base point (G Ed ) by a base point multiplier (S; derived from at least said signature scalar part z·S -1 scalar multiplication (S.G Ed ) performed modulo n; and to the public key point (Kpub’ Ed ) by scalar multiplication (k0.Kpub’ - 1 mod n) with a public key multiplier (k0; R.S Ed ) derived from at least the signature curve point portion (R); wherein at least one of the base point multiplier and the public key multiplier (k0; z·S -1 mod n) is also derived from the message (msg); - At least one output terminal (46, 406; 56, 506), configured to provide the authentication result (Auth) of the equation check for protecting digital communication; Characterized in that: - The at least one input end is configured to receive at least one parameter (q, n, A, B, G M ), the at least one parameter defining a second elliptic curve (Curve25519) and a second base point (G M ) located on the second elliptic curve, the second elliptic curve being birationally equivalent to the first elliptic curve (Ed25519) by an isomorphism, the second base point corresponding to the first base point (G Ed ) with respect to the isomorphism, and the second elliptic curve being of the Montgomery curve type; - The at least one processor is configured to: Determine the conversion public key point (Kpub’) M of the second elliptic curve from the public key (Kpub Ed ), where the conversion public key point (Kpub’ M ) corresponds to the public key point (Kpub’ Ed ) of the first elliptic curve with respect to the isomorphism; Perform scalar multiplications on the second base point (G M ) according to the base point multiplier (S) and on the converted public key point (Kpub’ M ) according to the public key multiplier (k0) (S.G M , k0.Kpub’ M ); and On any one of the same curves among the first elliptic curve (Ed25519) and the second elliptic curve (Curve25519), perform the equality check based on the scalar multiplication and the verification curve point (R’ Ed ).
7. The device (4, 40) for verifying a signature (R, S) according to claim 6, characterized in that, The at least one processor is configured to determine the transformed public key point (Kpub’) M ) and the check curve point (R’) Ed ) corresponding to the first elliptic curve relative to the transformed check curve point (R’) M ) of the isomorphism in an extended coordinate representation of the second elliptic curve (Curve25519), the extended coordinate representation involving at least three coordinates (U:V:Z), the extended coordinate representation being adapted to switch between an affine representation involving two coordinates (x, y) on the first elliptic curve and the extended coordinate representation on the second elliptic curve; and is configured to perform the scalar multiplications (s.G M , k0.Kpub’ M ) and the equality check without modular inversion in the extended coordinate representation of the second elliptic curve.
8. The device (4, 40) for verifying a signature (R, S) according to claim 6 or 7, characterized in that, The at least one processor is configured to convert an affine representation involving two coordinates (x, y) of a public key point (Kpub’) in the first elliptic curve into a projective homogeneous coordinate representation (Kpub’) involving at least three coordinates (U:V:Z) in the second elliptic curve (Curve25519) without modular inverse operation. Ed ) such that the projective homogeneous coordinate representation makes the point defined by the at least three coordinates (U:V:Z) invariant by multiplying the at least three coordinates by the same coefficient. M 9. The apparatus (4, 40) for verifying a signature (R, S) according to claim 8, characterized in that, The at least one processor is configured to perform the scalar multiplication (S.G M , k0.Kpub’ M ) on the second elliptic curve (Curve25519) by an improved Montgomery ladder method that processes coordinates (U1, Z1, U2, Z2, U, V, Z) expressed entirely in projective homogeneous coordinates.
10. The device (4, 40; 5, 50) for verifying a signature (R, S) according to any one of claims 6 to 9, characterized in that, The at least one processor is configured to perform an EdDSA process on the first elliptic curve (Ed25519) via the second elliptic curve (Curve25519), wherein the base point multiplier corresponds to the check value (S), and the public key multiplier is derived from the curve point portion (R), the public key (Kpub Ed ), and the message (msg).
11. The device (1, 10; 2, 20; 3, 30; 4, 40; 5, 50) according to any one of the preceding claims, characterized in that, The first elliptic curve and the second elliptic curve are respectively birationally equivalent elliptic curves Ed25519 and Curve25519 defined over a prime field defined by the prime number 2 255 –19; the first elliptic curve Ed25519 is defined by the equation: -x 2 +y 2 = 1–(121665 / 121666)x 2 y 2 in affine coordinates x, y, and is associated with the first base point (G Ed ) whose ordinate y is equal to 4 / 5; and the second elliptic curve Curve25519 is defined by the equation: v 2 = u 3 + 486662u 2 + u in affine coordinates u, v, and is associated with the second base point (G M ) whose abscissa u is equal to 9.
12. A method (6) for generating a public key (Kpub) from a private key (Kpriv) in elliptic curve cryptography, the method comprising: Ed ) - Receive data (Kpriv, h, s) representing the private key, and at least one parameter (q, n, a, d, G Ed ), where the parameter defines a first elliptic curve (Ed25519) and a first base point (G Ed ) located on the first elliptic curve, the first elliptic curve is on a finite field with a field order (p), and the first elliptic curve is of the twisted Edwards curve type; - Using at least one processor, calculate (6, 60) data representing the public key (Kpub Ed ) from the data representing the private key by performing scalar multiplication (s.G Ed ) on the first base point (G Ed ) on the first elliptic curve with a scalar (s) derived from the private key, where the data representing the public key (s.G Ed , Kpub Ed ); - Provide the data representing the public key for protecting digital communication; Characterized in that the method further includes: - Receive at least one parameter (q, n, A, B, G M ), where the parameter defines a second elliptic curve (Curve25519) and a second base point (G M ) located on the second elliptic curve. The second elliptic curve is birationally equivalent to the first elliptic curve (Ed25519) through an isomorphism, and the second base point corresponds to the first base point (G Ed ) with respect to the isomorphism. The second elliptic curve is of the Montgomery curve type; - Using the at least one processor: On the second elliptic curve, the second base point (G M ) performs scalar multiplication (sG) by at least one adjustment scalar (s; s') M ;s'·G M )(603), wherein the at least one adjustment scalar is selected from: the scalar (s) derived from the private key, and at least one quotient (s') obtained by dividing the scalar (s) by at least one adjustment integer (L) respectively greater than 1 and performing a modulo operation on the field order (p); when the adjustment scalar consists of the scalar (s), the value of the at least one adjustment integer is 1; and Convert (604) the resulting point of the scalar multiplication on the second elliptic curve to the scalar multiplication (s·G Ed ) on the first elliptic curve through at least one isogeny, where the degrees of the at least one isogeny are respectively equal to the at least one adjustment integer, and map the second base point to at least one scalar multiplication (L·G Ed ) of the first base point by the respective adjustment integer; The method (6, 60) for generating a public key (Kpub Ed ) is advantageously by according to claim 1, The device (1, 10; 3, 30) according to any one of 4, 5, and 11 for generating a public key (Kpub Ed ) is executed.
13. A method (7) for generating a signature (R, S) associated with a message (msg) from a private key (Kpriv) in elliptic curve cryptography, the method comprising: - Receive data (Kpriv, h, s, Prefix, r) representing the private key and the message, and at least one parameter (q, n, a, d, G Ed ), where the parameter defines a first elliptic curve (Ed25519) and a first base point (G Ed ) located on the first elliptic curve, the first elliptic curve being on a finite field having a field order (p), the first elliptic curve being of the twisted Edwards curve type; - Using at least one processor, by performing scalar multiplication (r.G Ed ) on the first base point (G Ed ) according to the nonce value (r) on the first elliptic curve, to calculate (7, 70) the data representing the signature (r.G Ed , R, k0, S) from the data representing the private key and the message; - Provide the data representing the signature for protecting digital communication; Characterized in that the method further includes: - Receive at least one parameter (q, n, A, B, G M ), where the parameter defines a second elliptic curve (Curve25519) and a second base point (G M ) located on the second elliptic curve, the second elliptic curve is birationally equivalent to the first elliptic curve (Ed25519) by an isomorphism, and the second base point corresponds to the first base point (G Ed ) with respect to the isomorphism, and the second elliptic curve is of the Montgomery curve type; - Using the at least one processor: On the second elliptic curve, the second base point (G M ) performs a scalar multiplication (sG) by at least one adjusted nonce value (r; r') M ;s'·G M )(703), wherein the at least one adjusted nonce value is selected from: the nonce value (r), and at least one quotient (r') obtained by dividing the nonce value (r) by at least one adjustment integer (L) respectively greater than 1 and performing a modulo operation on the field order (p); when the adjusted nonce value is composed of the nonce value (r), the value of the adjustment integer is 1; and Convert (704) the resulting point of the scalar multiplication on the second elliptic curve to the scalar multiplication (r.G Ed ) on the first elliptic curve through at least one isogeny, where the degrees of the at least one isogeny are respectively equal to the at least one adjustment integer, and map the second base point to at least one scalar multiplication (L·G Ed ) of the first base point according to the respective adjustment integers; The method (7, 70) for generating a signature (R, S) is advantageously executed by a device (2, 20; 3, 30) for generating a signature (R, S) according to any one of claims 2 to 5 and 11.
14. A method (8, 80, 85) for verifying a signature (R, S) associated with a message (msg) from a public key (Kpub Ed ) in elliptic curve cryptography, the method comprising: - Receive data representing the signature, the public key, and the message (R, R’ Ed , S, Kpub Ed , Kpub’ Ed , k0), and at least one parameter (q, n, a, d, G Ed ) defining a first elliptic curve (Ed25519) and a first base point (G Ed ) located on the first elliptic curve, the first elliptic curve being of the twisted Edwards curve type, the signature (R, S) including a scalar part associated with a check value (S) and a curve point part (R Ed ) representing a check curve point (R’ Ed ) of the first elliptic curve, and the public key (Kpub Ed ) representing a public key point (Kpub’ ) of the first elliptic curve; - Use at least one processor to verify (85) the consistency between the signature and the message through an equation check corresponding to the first elliptic curve, the equation check involving terms respectively based on the following: the signature curve point part (R’ Ed ; R); scalar multiplication (S.G Ed ) of the first base point (G - 1 mod n) by a base point multiplier (S; z·S Ed ) derived from at least the signature scalar part; and scalar multiplication (k0.Kpub’ Ed ) of the public key point (Kpub’ -1 ) by a public key multiplier (k0; R.S Ed mod n) derived from at least the signature curve point part (R); wherein at least one of the base point multiplier and the public key multiplier (k0; z·S -1 mod n) is also derived from the message (msg); - Provide the authentication result (Auth) of the equation check for protecting digital communication; Characterized in that the method further includes: - Receive at least one parameter (q, n, A, B, G M ), where the parameter defines a second elliptic curve (Curve25519) and a second base point (G M ) located on the second elliptic curve. The second elliptic curve is birationally equivalent to the first elliptic curve (Ed25519) by an isomorphism, and the second base point corresponds to the first base point (G Ed ) with respect to the isomorphism. The second elliptic curve is of the Montgomery curve type; - Using the at least one processor: Determine (82, 802) the converted public key point (Kpub') of the second elliptic curve from the public key (Kpub Ed ), the converted public key point (Kpub' M ) corresponding to the public key point (Kpub' M ) of the first elliptic curve with respect to the isomorphism Ed ); Perform (803) on the second elliptic curve scalar multiplications of the second base point (G M ) by the base point multiplier (S) and of the converted public key point (Kpub’ M ) by the public key multiplier (k0) (S.G M , k0.Kpub’ M ); and On any of the same curves among the first elliptic curve (Ed25519) and the second elliptic curve (Curve25519), perform the equality check based on the scalar multiplication and the verification curve point (R’ Ed ); The method (8, 80, 85) for verifying a signature (R, S) is advantageously executed by a device (4, 40; 5, 50) for verifying a signature (R, S) according to any one of claims 6 to 11.
15. A computer program comprising software code which, when executed by a processor, is configured to execute at least one of the methods for generating a public key (A) according to claim 12, the method for generating a signature (R, S) according to claim 13, and / or the method for verifying a signature (R, S) according to claim 14.
Citation Information
Cited By
Data encryption method and device, data decryption method and device, storage medium and program product
CN120602242A
Data encryption and decryption methods, devices, storage media, and software products
CN120602242B