This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

@@ -6,15 +6,15 @@ $$
ax^2+by^2=r^2
$$
- There are an infinite amount of solutions to this equation
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
- There are an infinite number of solutions to this equation
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
- We define an elliptic curve over points in $\mathbb{Z}_p, \space p>3$
- Set of all pairs where:
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
- The neutral element is 0
- One requirement is:
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
@@ -23,8 +23,8 @@ This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
Notice the symmetry about the x axis, this is because we have a $y^2$ term meaning we have two solutions
- For a DLP problem, we need a cyclic group
- Elements within the group
- A group operation
- Elements within the group
- A group operation
- For ECs the elements are points on the curve
- The operation is point addition
@@ -47,23 +47,23 @@ In elliptic curves, to get $4P$, we can either do $P+3P$ or $2P+2P$
##### Group Properties
- Closed
- Any closed addition operation will end up somewhere on the curve
- Any closed addition operation will end up somewhere on the curve
- Associative
- The order of calculations doesn’t matter
- The order of calculations doesn’t matter
##### Point Addition Equations
- We can derive equations for this based on the equation for a line that intersects the curve in three places
- Given $y^3=x^3+ax+b$ and points:
- $P=(x_1,y_1)$
- $Q=(x_2, y_2)$
- line $y=s\cdot x + m$
- Given $y^3=x^3+ax+b$ and points:
- $P=(x_1,y_1)$
- $Q=(x_2, y_2)$
- line $y=s\cdot x + m$
- $(sx+m)^2 = x^3 + ax + b$
- $s^2x^2 + 2sxm + m^2 = x^3+ax+b$
- Plugging in $x_1, y_1, x_2, y_2$
- $P+Q=(x_3, y_3)$
- $x_3 = s^2 - x_1 - x_2$
- $y_3 = s(x_1 - x_3) - y_1$
- $P+Q=(x_3, y_3)$
- $x_3 = s^2 - x_1 - x_2$
- $y_3 = s(x_1 - x_3) - y_1$
$$
s = \cases{\frac{y_2-y_1}{x_2-x_1} \quad (mod\space p); P\neq Q\\{\frac{3x_1^2+a}{2y_1}}\quad (mod\space p); P=Q}
@@ -107,20 +107,20 @@ These are a pain as they don’t intersect the curve, we say they cross the curv
#### The Point $\mathcal O$ at Infinity
- The point at infinity is the neutral element on a elliptic curve
- $P+(-P)=\mathcal O$
- $P+\mathcal O=P$
- The point at infinity is the neutral element on an elliptic curve
- $P+(-P)=\mathcal O$
- $P+\mathcal O=P$
- In practice the point doesn’t have coordinates, and can’t be used within the normal formula
- $P=(x,y)$
- $-P=(x,-y)$
- $P=(x,y)$
- $-P=(x,-y)$
- When implementing, you have to detect when the x values are equal and y values are inverses $\mod p$
- e.g. $(7,6)+(7,11)$
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
- e.g. $(7,6)+(7,11)$
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
### Cyclic Groups
- The points on an elliptic curve including the neutral element $\mathcal O$ form a cyclic subgroup
- Under certain conditions all points for a cyclic group
- Under certain conditions all points form a cyclic group
![1647962887.png](img/1647962887.png)
@@ -136,48 +136,50 @@ $$
This is the graph modulus $p$
- Given a generator point, points on elliptic curves generate cyclic groups
- $y^2 \equiv x^3+2x+2 \mod 17$
- ![1648484059.png](img/1648484059.png)
- Here the next two points is the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
- $y^2 \equiv x^3+2x+2 \mod 17$
- ![1648484059.png](img/1648484059.png)
- Here the next two points are the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
- Each cyclic group includes the point at infinity
## Elliptic Curve Discrete Logarithm
- We can construct a DLP in a very similar way to the modular exponentiation equivalent
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
- Given points $P$ and $A$, find scalar value $a$
- Its important to remember the distinction between points on the curve, and integer values
- It's important to remember the distinction between points on the curve and integer values
- On elliptic curves, private keys such as $a$ are integers
- Generators and public keys are points
#### Group Cardinality
- The size of cyclic groups is very important to the security
- While easy to calculate for modular arithmetic, the number of points on a give elliptic curve is not so obvious
- While easy to calculate for modular arithmetic, the number of points on a given elliptic curve is not so obvious
- You might imagine that a curve would have $2p+1$ points, in reality it is fewer than this
- This is closer to $p$
- This is closer to $p$
- Hasse’s theorem states that for a curve $E$ over a field $\mathbb{Z}_p$, the number of elements $\#E$ is bounded by:
- $\#E=p+1+\epsilon$
- where $|\epsilon| \leq 2\sqrt{p}$
- $\#E=p+1+\epsilon$
- where $|\epsilon| \leq 2\sqrt{p}$
##### #E
- A large #E is very important to prevent various attacks on ECDLP
- Calculating it exactly is hard, it can be done with Shoof’s algorithm
- Calculating it exactly is hard; it can be done with Schoof’s algorithm
- Various properties of #E enable or restrict certain attacks
##### How Hard is ECDLP
- There are generic algorithms like **Polig-Hellman** that are applicable to any category of DLP
- Polig-Hellman requires $O(\sqrt{\#E})$ steps
- These are generic attacks mean curves and parameters should be chosen with care
- There are generic algorithms like **Pohlig-Hellman** that are applicable to any category of DLP
- Pohlig-Hellman requires $O(\sqrt{\#E})$ steps
- These generic attacks mean curves and parameters should be chosen with care
- The most powerful attack on modular arithmetic based DLP is **index calculus**
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
#### Efficient Computation
- There is no nautral way of calculating $a\cdot P$
- There is no natural way of calculating $a\cdot P$
- Think back to binary exponentiation, square and multiply `->` double and add
| Decimal | Binary |
@@ -199,13 +201,11 @@ E, \#E, G \\
\mathrm{Bob}: a\in \{1,2,...,\#E-1\} \\
$$
Alice takes point $G$ on the curve and add it to $a$: $A = a\cdot G$
Alice takes point $G$ on the curve and adds it to $a$: $A = a\cdot G$
Bob does the same: $B=b\cdot G$
Alice takes bob’s public key $k_{ab} = a\cdot B$
Alice takes Bob’s public key $k_{ab} = a\cdot B$
Bob does the same: $k_{ab}=b\cdot A$
@@ -227,7 +227,7 @@ Where each layer builds on the one beneath
- Since we know the formula for a given curve, we do not need to transport full $(x,y)$ coordinates
- Each point contains a unique $x$, and one or two $y$ where
- $y=\sqrt{x^3 + 2x + 2}\mod p$
- $y=\sqrt{x^3 + 2x + 2}\mod p$
- Most implementations will use the full $x$ value, and append a single bit representing a positive or negative y value
#### Projective Coordinates
@@ -244,11 +244,11 @@ Where each layer builds on the one beneath
- The choice of curve parameters influences both security and efficiency of crypto-systems based around ECs
- Never use a randomly generated curve!
- The chances are the number of points we generate will have a subgroup susecpible to Polig-Hellmen
- The chances are the number of points we generate will have a subgroup susceptible to Pohlig-Hellman
- Standard curves exist in various forms
- Varied equations
- Different implementation methods
- Different choices of prime
- Varied equations
- Different implementation methods
- Different choices of prime
##### P-256
@@ -259,8 +259,8 @@ Where each layer builds on the one beneath
![1648487070.png](img/1648487070.png)
- $h$ is the cofactor, the size of the subgroup in $G$
- Because its 1 it means all the points are being generated
- If it was 2, only half of the points are being generated
- Because it's 1 it means all the points are being generated
- If it was 2, only half of the points are being generated
##### secp256k1
@@ -289,5 +289,5 @@ Where each layer builds on the one beneath
#### Primary Applications
- Elliptic Curve Diffie Hellman
- DSA Signatures scheme, based on Elgamal signatures
- DSA signature scheme, based on Elgamal signatures
- Similar schemes involving the alternative curves such as `Ed25519` and `Ed448`