Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -6,15 +6,15 @@ $$
|
||||
ax^2+by^2=r^2
|
||||
$$
|
||||
|
||||
- There are an infinite amount of solutions to this equation
|
||||
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
|
||||
- There are an infinite number of solutions to this equation
|
||||
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
|
||||
|
||||
- We define an elliptic curve over points in $\mathbb{Z}_p, \space p>3$
|
||||
- Set of all pairs where:
|
||||
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
|
||||
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
|
||||
- The neutral element is 0
|
||||
- One requirement is:
|
||||
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
|
||||
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
|
||||
|
||||
This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
|
||||
|
||||
@@ -23,8 +23,8 @@ This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
|
||||
Notice the symmetry about the x axis, this is because we have a $y^2$ term meaning we have two solutions
|
||||
|
||||
- For a DLP problem, we need a cyclic group
|
||||
- Elements within the group
|
||||
- A group operation
|
||||
- Elements within the group
|
||||
- A group operation
|
||||
- For ECs the elements are points on the curve
|
||||
- The operation is point addition
|
||||
|
||||
@@ -47,23 +47,23 @@ In elliptic curves, to get $4P$, we can either do $P+3P$ or $2P+2P$
|
||||
##### Group Properties
|
||||
|
||||
- Closed
|
||||
- Any closed addition operation will end up somewhere on the curve
|
||||
- Any closed addition operation will end up somewhere on the curve
|
||||
- Associative
|
||||
- The order of calculations doesn’t matter
|
||||
- The order of calculations doesn’t matter
|
||||
|
||||
##### Point Addition Equations
|
||||
|
||||
- We can derive equations for this based on the equation for a line that intersects the curve in three places
|
||||
- Given $y^3=x^3+ax+b$ and points:
|
||||
- $P=(x_1,y_1)$
|
||||
- $Q=(x_2, y_2)$
|
||||
- line $y=s\cdot x + m$
|
||||
- Given $y^3=x^3+ax+b$ and points:
|
||||
- $P=(x_1,y_1)$
|
||||
- $Q=(x_2, y_2)$
|
||||
- line $y=s\cdot x + m$
|
||||
- $(sx+m)^2 = x^3 + ax + b$
|
||||
- $s^2x^2 + 2sxm + m^2 = x^3+ax+b$
|
||||
- Plugging in $x_1, y_1, x_2, y_2$
|
||||
- $P+Q=(x_3, y_3)$
|
||||
- $x_3 = s^2 - x_1 - x_2$
|
||||
- $y_3 = s(x_1 - x_3) - y_1$
|
||||
- $P+Q=(x_3, y_3)$
|
||||
- $x_3 = s^2 - x_1 - x_2$
|
||||
- $y_3 = s(x_1 - x_3) - y_1$
|
||||
|
||||
$$
|
||||
s = \cases{\frac{y_2-y_1}{x_2-x_1} \quad (mod\space p); P\neq Q\\{\frac{3x_1^2+a}{2y_1}}\quad (mod\space p); P=Q}
|
||||
@@ -107,20 +107,20 @@ These are a pain as they don’t intersect the curve, we say they cross the curv
|
||||
|
||||
#### The Point $\mathcal O$ at Infinity
|
||||
|
||||
- The point at infinity is the neutral element on a elliptic curve
|
||||
- $P+(-P)=\mathcal O$
|
||||
- $P+\mathcal O=P$
|
||||
- The point at infinity is the neutral element on an elliptic curve
|
||||
- $P+(-P)=\mathcal O$
|
||||
- $P+\mathcal O=P$
|
||||
- In practice the point doesn’t have coordinates, and can’t be used within the normal formula
|
||||
- $P=(x,y)$
|
||||
- $-P=(x,-y)$
|
||||
- $P=(x,y)$
|
||||
- $-P=(x,-y)$
|
||||
- When implementing, you have to detect when the x values are equal and y values are inverses $\mod p$
|
||||
- e.g. $(7,6)+(7,11)$
|
||||
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
|
||||
- e.g. $(7,6)+(7,11)$
|
||||
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
|
||||
|
||||
### Cyclic Groups
|
||||
|
||||
- The points on an elliptic curve including the neutral element $\mathcal O$ form a cyclic subgroup
|
||||
- Under certain conditions all points for a cyclic group
|
||||
- Under certain conditions all points form a cyclic group
|
||||
|
||||

|
||||
|
||||
@@ -136,48 +136,50 @@ $$
|
||||
This is the graph modulus $p$
|
||||
|
||||
- Given a generator point, points on elliptic curves generate cyclic groups
|
||||
- $y^2 \equiv x^3+2x+2 \mod 17$
|
||||
- 
|
||||
- Here the next two points is the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
|
||||
- $y^2 \equiv x^3+2x+2 \mod 17$
|
||||
|
||||
- 
|
||||
|
||||
- Here the next two points are the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
|
||||
- Each cyclic group includes the point at infinity
|
||||
|
||||
## Elliptic Curve Discrete Logarithm
|
||||
|
||||
- We can construct a DLP in a very similar way to the modular exponentiation equivalent
|
||||
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
|
||||
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
|
||||
- Given points $P$ and $A$, find scalar value $a$
|
||||
- Its important to remember the distinction between points on the curve, and integer values
|
||||
- It's important to remember the distinction between points on the curve and integer values
|
||||
- On elliptic curves, private keys such as $a$ are integers
|
||||
- Generators and public keys are points
|
||||
|
||||
#### Group Cardinality
|
||||
|
||||
- The size of cyclic groups is very important to the security
|
||||
- While easy to calculate for modular arithmetic, the number of points on a give elliptic curve is not so obvious
|
||||
- While easy to calculate for modular arithmetic, the number of points on a given elliptic curve is not so obvious
|
||||
- You might imagine that a curve would have $2p+1$ points, in reality it is fewer than this
|
||||
- This is closer to $p$
|
||||
- This is closer to $p$
|
||||
- Hasse’s theorem states that for a curve $E$ over a field $\mathbb{Z}_p$, the number of elements $\#E$ is bounded by:
|
||||
- $\#E=p+1+\epsilon$
|
||||
- where $|\epsilon| \leq 2\sqrt{p}$
|
||||
- $\#E=p+1+\epsilon$
|
||||
- where $|\epsilon| \leq 2\sqrt{p}$
|
||||
|
||||
##### #E
|
||||
|
||||
- A large #E is very important to prevent various attacks on ECDLP
|
||||
- Calculating it exactly is hard, it can be done with Shoof’s algorithm
|
||||
- Calculating it exactly is hard; it can be done with Schoof’s algorithm
|
||||
- Various properties of #E enable or restrict certain attacks
|
||||
|
||||
##### How Hard is ECDLP
|
||||
|
||||
- There are generic algorithms like **Polig-Hellman** that are applicable to any category of DLP
|
||||
- Polig-Hellman requires $O(\sqrt{\#E})$ steps
|
||||
- These are generic attacks mean curves and parameters should be chosen with care
|
||||
- There are generic algorithms like **Pohlig-Hellman** that are applicable to any category of DLP
|
||||
- Pohlig-Hellman requires $O(\sqrt{\#E})$ steps
|
||||
- These generic attacks mean curves and parameters should be chosen with care
|
||||
- The most powerful attack on modular arithmetic based DLP is **index calculus**
|
||||
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
|
||||
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
|
||||
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
|
||||
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
|
||||
|
||||
#### Efficient Computation
|
||||
|
||||
- There is no nautral way of calculating $a\cdot P$
|
||||
- There is no natural way of calculating $a\cdot P$
|
||||
- Think back to binary exponentiation, square and multiply `->` double and add
|
||||
|
||||
| Decimal | Binary |
|
||||
@@ -199,13 +201,11 @@ E, \#E, G \\
|
||||
\mathrm{Bob}: a\in \{1,2,...,\#E-1\} \\
|
||||
$$
|
||||
|
||||
|
||||
|
||||
Alice takes point $G$ on the curve and add it to $a$: $A = a\cdot G$
|
||||
Alice takes point $G$ on the curve and adds it to $a$: $A = a\cdot G$
|
||||
|
||||
Bob does the same: $B=b\cdot G$
|
||||
|
||||
Alice takes bob’s public key $k_{ab} = a\cdot B$
|
||||
Alice takes Bob’s public key $k_{ab} = a\cdot B$
|
||||
|
||||
Bob does the same: $k_{ab}=b\cdot A$
|
||||
|
||||
@@ -227,7 +227,7 @@ Where each layer builds on the one beneath
|
||||
|
||||
- Since we know the formula for a given curve, we do not need to transport full $(x,y)$ coordinates
|
||||
- Each point contains a unique $x$, and one or two $y$ where
|
||||
- $y=\sqrt{x^3 + 2x + 2}\mod p$
|
||||
- $y=\sqrt{x^3 + 2x + 2}\mod p$
|
||||
- Most implementations will use the full $x$ value, and append a single bit representing a positive or negative y value
|
||||
|
||||
#### Projective Coordinates
|
||||
@@ -244,11 +244,11 @@ Where each layer builds on the one beneath
|
||||
|
||||
- The choice of curve parameters influences both security and efficiency of crypto-systems based around ECs
|
||||
- Never use a randomly generated curve!
|
||||
- The chances are the number of points we generate will have a subgroup susecpible to Polig-Hellmen
|
||||
- The chances are the number of points we generate will have a subgroup susceptible to Pohlig-Hellman
|
||||
- Standard curves exist in various forms
|
||||
- Varied equations
|
||||
- Different implementation methods
|
||||
- Different choices of prime
|
||||
- Varied equations
|
||||
- Different implementation methods
|
||||
- Different choices of prime
|
||||
|
||||
##### P-256
|
||||
|
||||
@@ -259,8 +259,8 @@ Where each layer builds on the one beneath
|
||||

|
||||
|
||||
- $h$ is the cofactor, the size of the subgroup in $G$
|
||||
- Because its 1 it means all the points are being generated
|
||||
- If it was 2, only half of the points are being generated
|
||||
- Because it's 1 it means all the points are being generated
|
||||
- If it was 2, only half of the points are being generated
|
||||
|
||||
##### secp256k1
|
||||
|
||||
@@ -289,5 +289,5 @@ Where each layer builds on the one beneath
|
||||
#### Primary Applications
|
||||
|
||||
- Elliptic Curve Diffie Hellman
|
||||
- DSA Signatures scheme, based on Elgamal signatures
|
||||
- DSA signature scheme, based on Elgamal signatures
|
||||
- Similar schemes involving the alternative curves such as `Ed25519` and `Ed448`
|
||||
Reference in new issue
Block a user