Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

@@ -0,0 +1,293 @@
# Elliptic Curves
- We’d like to find another type of group and operation in which the discrete logarithm problem is hard
$$
ax^2+by^2=r^2
$$
- There are an infinite amount of solutions to this equation
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
- We define an elliptic curve over points in $\mathbb{Z}_p, \space p>3$
- Set of all pairs where:
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
- The neutral element is 0
- One requirement is:
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
![1647896060.png](img/1647896060.png)
Notice the symmetry about the x axis, this is because we have a $y^2$ term meaning we have two solutions
- For a DLP problem, we need a cyclic group
- Elements within the group
- A group operation
- For ECs the elements are points on the curve
- The operation is point addition
#### Point Addition
![1647896303.png](img/1647896303.png)
#### Point Doubling
$P + P = 2P$
- Here our line will be tangent to P
![1647896385.png](img/1647896385.png)
#### Group Laws
In elliptic curves, to get $4P$, we can either do $P+3P$ or $2P+2P$
##### Group Properties
- Closed
- Any closed addition operation will end up somewhere on the curve
- Associative
- The order of calculations doesn’t matter
##### Point Addition Equations
- We can derive equations for this based on the equation for a line that intersects the curve in three places
- Given $y^3=x^3+ax+b$ and points:
- $P=(x_1,y_1)$
- $Q=(x_2, y_2)$
- line $y=s\cdot x + m$
- $(sx+m)^2 = x^3 + ax + b$
- $s^2x^2 + 2sxm + m^2 = x^3+ax+b$
- Plugging in $x_1, y_1, x_2, y_2$
- $P+Q=(x_3, y_3)$
- $x_3 = s^2 - x_1 - x_2$
- $y_3 = s(x_1 - x_3) - y_1$
$$
s = \cases{\frac{y_2-y_1}{x_2-x_1} \quad (mod\space p); P\neq Q\\{\frac{3x_1^2+a}{2y_1}}\quad (mod\space p); P=Q}
$$
###### Example
$y^2\equiv x^3+2x+2\space (mod \space 17)$
$(3,1)+(9,16)$
$$
s=\frac{16-1}{9-3}=\frac{15}{6}=15\cdot 6^{-1} \\
= 15\cdot 3 \mod{17} \\
= 11
$$
$$
x_3=11^2-3-9 \\
109 \space \mod{17} = 7 \\\\
y_3 = 11\cdot(3-7)-1=11\cdot 13 \mod{17} = 6 \\
$$
#### Inverses
The point reflected in the x axis is the inverse
![1647897774.png](img/1647897774.png)
#### Neutral Element
$P-P=?$
$P+?=P$
![1647897899.png](img/1647897899.png)
These are a pain as they don’t intersect the curve, we say they cross the curve at $\infty$
![1647897899.png](img/1647897899.png)
#### The Point $\mathcal O$ at Infinity
- The point at infinity is the neutral element on a elliptic curve
- $P+(-P)=\mathcal O$
- $P+\mathcal O=P$
- In practice the point doesn’t have coordinates, and can’t be used within the normal formula
- $P=(x,y)$
- $-P=(x,-y)$
- When implementing, you have to detect when the x values are equal and y values are inverses $\mod p$
- e.g. $(7,6)+(7,11)$
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
### Cyclic Groups
- The points on an elliptic curve including the neutral element $\mathcal O$ form a cyclic subgroup
- Under certain conditions all points for a cyclic group
![1647962887.png](img/1647962887.png)
- Given a curve $E$, a primitive root $P$, and a point $aP$, what is $a$?
- This is the elliptic curve discrete logarithm problem
$$
aP = \underbrace{P+P+...+P}_{a \space \mathrm {times}}
$$
![1647963097.png](img/1647963097.png)
This is the graph modulus $p$
- Given a generator point, points on elliptic curves generate cyclic groups
- $y^2 \equiv x^3+2x+2 \mod 17$
- ![1648484059.png](img/1648484059.png)
- Here the next two points is the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
- Each cyclic group includes the point at infinity
## Elliptic Curve Discrete Logarithm
- We can construct a DLP in a very similar way to the modular exponentiation equivalent
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
- Given points $P$ and $A$, find scalar value $a$
- Its important to remember the distinction between points on the curve, and integer values
- On elliptic curves, private keys such as $a$ are integers
- Generators and public keys are points
#### Group Cardinality
- The size of cyclic groups is very important to the security
- While easy to calculate for modular arithmetic, the number of points on a give elliptic curve is not so obvious
- You might imagine that a curve would have $2p+1$ points, in reality it is fewer than this
- This is closer to $p$
- Hasse’s theorem states that for a curve $E$ over a field $\mathbb{Z}_p$, the number of elements $\#E$ is bounded by:
- $\#E=p+1+\epsilon$
- where $|\epsilon| \leq 2\sqrt{p}$
##### #E
- A large #E is very important to prevent various attacks on ECDLP
- Calculating it exactly is hard, it can be done with Shoof’s algorithm
- Various properties of #E enable or restrict certain attacks
##### How Hard is ECDLP
- There are generic algorithms like **Polig-Hellman** that are applicable to any category of DLP
- Polig-Hellman requires $O(\sqrt{\#E})$ steps
- These are generic attacks mean curves and parameters should be chosen with care
- The most powerful attack on modular arithmetic based DLP is **index calculus**
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
#### Efficient Computation
- There is no nautral way of calculating $a\cdot P$
- Think back to binary exponentiation, square and multiply `->` double and add
| Decimal | Binary |
| ---------------- | ---------------- |
| $26_{10}\cdot P$ | $11010_2\cdot P$ |
| $1P$ | $1 \cdot P$ |
| $2P=1P+1P$ | $10\cdot P$ |
| $3P=2P+1P$ | $11\cdot P$ |
| $6P=3P+3P$ | $110\cdot P$ |
| $12P=6P+6P$ | $1100\cdot P$ |
| $12P+1P = 13P$ | $1101\cdot P$ |
| $26P = 13P+13P$ | $11010\cdot P$ |
### Elliptic Curve Diffie-Hellman (ECDH)
$$
E, \#E, G \\
\mathrm{Alice}: a\in \{1,2,...,\#E-1\} \\
\mathrm{Bob}: a\in \{1,2,...,\#E-1\} \\
$$
Alice takes point $G$ on the curve and add it to $a$: $A = a\cdot G$
Bob does the same: $B=b\cdot G$
Alice takes bob’s public key $k_{ab} = a\cdot B$
Bob does the same: $k_{ab}=b\cdot A$
$k_{ab} = a\cdot B = a \cdot (b \cdot G)=ab\cdot G$
$k_{ab} = b\cdot A = b \cdot (a \cdot G)=ab\cdot G$
![1648486510.png](img/1648486510.png)
#### EC Structure
![1648486533.png](img/1648486533.png)
Where each layer builds on the one beneath
## Implementation
#### Point Compression
- Since we know the formula for a given curve, we do not need to transport full $(x,y)$ coordinates
- Each point contains a unique $x$, and one or two $y$ where
- $y=\sqrt{x^3 + 2x + 2}\mod p$
- Most implementations will use the full $x$ value, and append a single bit representing a positive or negative y value
#### Projective Coordinates
- Some implementations adjust the formula for point addition to use projective coordinates $(x,y,z)$ rather than $(x,y)$
- The curve sits on the plane $z=1$
- Points at infinity $\mathcal O = (0,1,0)$
**Why?**
- Point addition in this system does not require a multiplicative inverse
#### Standard Curves
- The choice of curve parameters influences both security and efficiency of crypto-systems based around ECs
- Never use a randomly generated curve!
- The chances are the number of points we generate will have a subgroup susecpible to Polig-Hellmen
- Standard curves exist in various forms
- Varied equations
- Different implementation methods
- Different choices of prime
##### P-256
- Weierstrass curve $y^2\equiv x^3+ax+b\mod p$
- Very widely used
- One of the few curves in `TLS1.3` and NSA Suite B
![1648487070.png](img/1648487070.png)
- $h$ is the cofactor, the size of the subgroup in $G$
- Because its 1 it means all the points are being generated
- If it was 2, only half of the points are being generated
##### secp256k1
- Koblitz curve $y^2\equiv x^3+7\mod p$
- Underpins Bitcoin digital signatures
![1648487312.png](img/1648487312.png)
##### Curve25519
- Montgomery curve $y^2\equiv x^3 + 486662x^2+x\mod p$
- Primary alternative to `P-256`
- In `TLS1.3` and numerous other protocols
- The nature of this curve allows efficient multiplication using a Montgomery ladder, using only $X$ and $Z$
- This algorithm can compute numbers in constant time
![1648487421.png](img/1648487421.png)
##### Curve448-Goldilocks
- Untwisted Edwards Curve $y^2+x^2\equiv 1 - 39081x^2y^2\mod p$
- 448 bit curve
- Primarily used within digital signatures as part of `Ed448`
- Edwards curve arithmetic mod this “goldilocks” prime is very efficient
#### Primary Applications
- Elliptic Curve Diffie Hellman
- DSA Signatures scheme, based on Elgamal signatures
- Similar schemes involving the alternative curves such as `Ed25519` and `Ed448`