Binary Edwards Curve Cryptography for 32/64-bit Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current binary Edwards curves used in cryptography do not achieve the recommended 128-bit security level and are not optimized for speed of execution, making them vulnerable to attacks and inefficient on 32-bit or 64-bit hardware architectures.

Innovation Solution

A cryptographic method is developed for a binary Edwards curve by selecting parameters that enhance security, ease of implementation, and calculation speed, including choosing binary extension fields and irreducible polynomials suitable for 32 or 64-bit hardware, and optimizing the curve parameters to meet specific security criteria and arithmetic efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current binary Edwards curves are used for cryptography, then implementation is simple, but security level is insufficient (below 128-bit)

Engineering Contradiction:
Improvesecurity levelVSAvoidcurve parameter complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of the binary Edwards curve by selecting specific values for d1 and d2 from the binary extension field F2^m, where m is a prime number. This parameter optimization ensures that the curve achieves at least 128-bit security level while maintaining implementation simplicity. The specific parameter selection resolves the contradiction by finding the right balance between security requirements and computational feasibility.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If current binary Edwards curves are used, then computational operations are straightforward, but execution speed is not optimized

Engineering Contradiction:
Improvecalculation speedVSAvoidarithmetic operation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent optimizes specific aspects of the arithmetic operations on the binary Edwards curve by selecting particular curve parameters. This local optimization of the curve structure improves calculation speed for cryptographic operations while keeping the overall system architecture and implementation approach relatively simple, thus resolving the contradiction between execution speed and operational complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If standard binary Edwards curves are used, then implementation is easier, but vulnerability to attacks increases

Engineering Contradiction:
Improveresistance to attacksVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent enhances resistance to cryptographic attacks by carefully selecting the parameters d1 and d2 of the binary Edwards curve. These parameter changes strengthen the curve's security properties without fundamentally altering the implementation approach, thus maintaining relative ease of implementation while significantly improving attack resistance.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If curves over Fp are used, then security can be achieved, but calculations are complex and vulnerable to side-channel attacks

Engineering Contradiction:
Improvesecurity levelVSAvoidcalculation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a binary Edwards curve defined over F2^m as an alternative to curves over Fp, effectively copying the cryptographic functionality while changing the underlying field. This approach maintains security levels while simplifying calculations and reducing vulnerability to side-channel attacks, as binary field operations are inherently more efficient and less prone to timing variations.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3457626B1Cryptographic method on binary edwards elliptic curves
Publication Date: 2023.05.24 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • EP3457626B1 patent drawing
  • EP3457626B1 patent drawing
  • EP3457626B1 patent drawing

AI summary

The present invention relates to a cryptographic method on a binary Edwards curve (BEC) defined on a binary extension field F2m, whose domain parameters are selected to allow implementation suitable for a 32-bit or 64-bit hardware architecture, to reduce the number of computations, and to ensure a high level of security against potential attacks. A list of binary extension fields with associated primitive polynomials is provided. For each of these binary extension fields, at least one optimal parameter of the BEC and an optimal generator point are proposed.