ECMQV Key Agreement Power Analysis Countermeasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Elliptic Curve Menezes-Qu-Vanstone (ECMQV) Key Agreement Algorithm is vulnerable to power analysis attacks, particularly Differential Power Analysis (DPA), which can reveal the long-term private key by monitoring power consumption during scalar multiplication operations.
Innovation Solution
Modifying the arithmetic operations involved in determining the implicit signature by using modular inverses and random numbers to mask the long-term private key, such as through equations like SA=(kAdA−1+ RA)dA mod u or SA=[kA+(RAω)(ω−1dA)] mod u, which introduces additional modular operations to prevent attackers from deducing the private key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the ECMQV key agreement algorithm is implemented using standard scalar multiplication operations, then the key agreement process is efficient and straightforward, but the implementation becomes vulnerable to power analysis attacks that can reveal the long-term private key
Solution Approach 1:
The patent applies preliminary action by pre-computing the modular inverse of the long-term private key (dA^-1 mod u) and storing it before the key agreement operation. This pre-computed value is then used in the modified implicit signature calculation SA = (kA*dA^-1 + RA)*dA mod u, which masks the private key during power-consuming operations, thereby preventing power analysis attacks while maintaining operational efficiency
Solution Approach 2:
The patent changes the parameter representation by transforming the standard implicit signature calculation into a modified form that incorporates the modular inverse. The equation SA = (kA*dA^-1 + RA)*dA mod u replaces the traditional approach, changing how the private key is utilized during the computation to mask its value during power analysis vulnerable operations
Data Source
AI summary
Execution of the ECMQV key agreement algorithm requires determination of an implicit signature, which determination involves arithmetic operations. Some of the arithmetic operations employ a long-term cryptographic key. It is the execution of these arithmetic operations that can make the execution of the ECMQV key agreement algorithm vulnerable to a power analysis attack. In particular, an attacker using a power analysis attack may determine the long-term cryptographic key. By modifying the sequence of operations involved in the determination of the implicit signature and the inputs to those operations, power analysis attacks may no longer be applied to determine the long-term cryptographic key.


