Finite-field Division Operator for Variable Key Length ECC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing elliptic curve cryptosystems face challenges in supporting variable key lengths, particularly with the transition from 256-bit to 384-bit keys, and are hindered by the time-consuming finite-field division operation, requiring hardware replacement when key lengths change.
Innovation Solution
A method and system for an elliptic curve cryptosystem that includes a finite-field division operator with hardware implementation, allowing for variable key lengths by using a key setting unit to generate setup information for both software-based operation devices and the finite-field division operator, which includes registers, adders/subtractors, multiplexers, shifters, and a controller to perform efficient division operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If hardware is used to perform finite-field division operations, then operation speed is improved, but device complexity increases
Solution Approach 1:
The finite-field division operator is divided into multiple functional modules including a dividend register, divisor register, quotient register, remainder register, comparison unit, subtraction unit, and shift unit. Each module performs a specific function in the division process, allowing the complex operation to be broken down into manageable components that can be implemented in hardware efficiently.
Solution Approach 2:
The patent introduces intermediate registers (dividend register, divisor register, quotient register, remainder register) that store values at different stages of the division process. These intermediate storage elements act as mediators between the various computational units, enabling the hardware to perform division operations systematically through a series of controlled steps including comparison, subtraction, and shifting.
2Reliability
If key length is increased from 256 bits to 384 bits, then security is improved, but hardware must be replaced
Solution Approach 1:
The patent implements a dynamic key length adaptation mechanism where the finite-field division operator can be reconfigured to support different key lengths (256 bits, 384 bits, and potentially other lengths). The hardware structure allows the register widths and operation parameters to be adjusted based on the required security level, enabling the same physical hardware to adapt to different cryptographic standards without replacement.
Solution Approach 2:
The finite-field division operator is designed with universal functionality to support multiple key lengths and elliptic curve parameters. The hardware structure incorporates configurable registers and control logic that can accommodate different field sizes, making the device capable of performing secure operations with 256-bit keys, 384-bit keys, or other lengths as required by different security standards and applications.
3Device complexity
If finite-field division is performed using software, then device complexity is reduced, but operation time increases
Solution Approach 1:
The patent replaces the software-based finite-field division implementation with a dedicated hardware circuit. The mechanical system (software execution involving interpretation, memory access, and sequential processing) is substituted with an electronic hardware system that performs division operations through parallel circuits, comparison units, and shift registers, dramatically reducing operation time while maintaining manageable complexity through modular design.
Data Source
AI summary
Disclosed herein are a finite-field division operator, an elliptic curve cryptosystem having the finite-field division operator, and a method for operating the elliptic curve cryptosystem. The method for operating an elliptic curve cryptosystem may include, setting, by a key setting unit, a length of a key of a cryptographic algorithm, generating, by the key setting unit, first setup information that indicates a number of words corresponding to the key length, and generating, by the key setting unit, second setup information that indicates a number of repetitions of an operation by a finite-field division operator corresponding to the key length.


