8.7 KiB
Elliptic Curves
- We’d like to find another type of group and operation in which the discrete logarithm problem is hard
ax^2+by^2=r^2
-
There are an infinite amount of solutions to this equation
- However if we restrict to only integers (
\mathbb{Z}) and use mod, we have a finite set
- However if we restrict to only integers (
-
We define an elliptic curve over points in
\mathbb{Z}_p, \space p>3 -
Set of all pairs where:
y^2 \equiv x^3 + ax + b \space (mod \space p)
-
The neutral element is 0
-
One requirement is:
4a^3 + 27b^2 \neq 0 \space (mod \space p)
This is y^2 \equiv x^3 -3x +3 over \mathbb{R}
Notice the symmetry about the x axis, this is because we have a y^2 term meaning we have two solutions
- For a DLP problem, we need a cyclic group
- Elements within the group
- A group operation
- For ECs the elements are points on the curve
- The operation is point addition
Point Addition
Point Doubling
P + P = 2P
- Here our line will be tangent to P
Group Laws
In elliptic curves, to get 4P, we can either do P+3P or 2P+2P
Group Properties
- Closed
- Any closed addition operation will end up somewhere on the curve
- Associative
- The order of calculations doesn’t matter
Point Addition Equations
- We can derive equations for this based on the equation for a line that intersects the curve in three places
- Given
y^3=x^3+ax+band points:P=(x_1,y_1)Q=(x_2, y_2)
- line
y=s\cdot x + m
- Given
(sx+m)^2 = x^3 + ax + bs^2x^2 + 2sxm + m^2 = x^3+ax+b- Plugging in
x_1, y_1, x_2, y_2P+Q=(x_3, y_3)x_3 = s^2 - x_1 - x_2y_3 = s(x_1 - x_3) - y_1
s = \cases{\frac{y_2-y_1}{x_2-x_1} \quad (mod\space p); P\neq Q\\{\frac{3x_1^2+a}{2y_1}}\quad (mod\space p); P=Q}
Example
y^2\equiv x^3+2x+2\space (mod \space 17)
(3,1)+(9,16)
s=\frac{16-1}{9-3}=\frac{15}{6}=15\cdot 6^{-1} \\
= 15\cdot 3 \mod{17} \\
= 11
x_3=11^2-3-9 \\
109 \space \mod{17} = 7 \\\\
y_3 = 11\cdot(3-7)-1=11\cdot 13 \mod{17} = 6 \\
Inverses
The point reflected in the x axis is the inverse
Neutral Element
P-P=?
P+?=P
These are a pain as they don’t intersect the curve, we say they cross the curve at \infty
The Point \mathcal O at Infinity
- The point at infinity is the neutral element on a elliptic curve
P+(-P)=\mathcal OP+\mathcal O=P
- In practice the point doesn’t have coordinates, and can’t be used within the normal formula
P=(x,y)-P=(x,-y)
- When implementing, you have to detect when the x values are equal and y values are inverses
\mod p- e.g.
(7,6)+(7,11) \frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O
- e.g.
Cyclic Groups
- The points on an elliptic curve including the neutral element
\mathcal Oform a cyclic subgroup - Under certain conditions all points for a cyclic group
- Given a curve
E, a primitive rootP, and a pointaP, what isa? - This is the elliptic curve discrete logarithm problem
aP = \underbrace{P+P+...+P}_{a \space \mathrm {times}}
This is the graph modulus p
- Given a generator point, points on elliptic curves generate cyclic groups
- Each cyclic group includes the point at infinity
Elliptic Curve Discrete Logarithm
- We can construct a DLP in a very similar way to the modular exponentiation equivalent
aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A
- Given points
PandA, find scalar valuea - Its important to remember the distinction between points on the curve, and integer values
- On elliptic curves, private keys such as
aare integers - Generators and public keys are points
Group Cardinality
- The size of cyclic groups is very important to the security
- While easy to calculate for modular arithmetic, the number of points on a give elliptic curve is not so obvious
- You might imagine that a curve would have
2p+1points, in reality it is fewer than this- This is closer to
p
- This is closer to
- Hasse’s theorem states that for a curve
Eover a field\mathbb{Z}_p, the number of elements\#Eis bounded by:\#E=p+1+\epsilon- where
|\epsilon| \leq 2\sqrt{p}
#E
- A large #E is very important to prevent various attacks on ECDLP
- Calculating it exactly is hard, it can be done with Shoof’s algorithm
- Various properties of #E enable or restrict certain attacks
How Hard is ECDLP
- There are generic algorithms like Polig-Hellman that are applicable to any category of DLP
- Polig-Hellman requires
O(\sqrt{\#E})steps
- Polig-Hellman requires
- These are generic attacks mean curves and parameters should be chosen with care
- The most powerful attack on modular arithmetic based DLP is index calculus
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
Efficient Computation
- There is no nautral way of calculating
a\cdot P - Think back to binary exponentiation, square and multiply
->double and add
| Decimal | Binary |
|---|---|
26_{10}\cdot P |
11010_2\cdot P |
1P |
1 \cdot P |
2P=1P+1P |
10\cdot P |
3P=2P+1P |
11\cdot P |
6P=3P+3P |
110\cdot P |
12P=6P+6P |
1100\cdot P |
12P+1P = 13P |
1101\cdot P |
26P = 13P+13P |
11010\cdot P |
Elliptic Curve Diffie-Hellman (ECDH)
E, \#E, G \\
\mathrm{Alice}: a\in \{1,2,...,\#E-1\} \\
\mathrm{Bob}: a\in \{1,2,...,\#E-1\} \\
Alice takes point G on the curve and add it to a: A = a\cdot G
Bob does the same: B=b\cdot G
Alice takes bob’s public key k_{ab} = a\cdot B
Bob does the same: k_{ab}=b\cdot A
k_{ab} = a\cdot B = a \cdot (b \cdot G)=ab\cdot G
k_{ab} = b\cdot A = b \cdot (a \cdot G)=ab\cdot G
EC Structure
Where each layer builds on the one beneath
Implementation
Point Compression
- Since we know the formula for a given curve, we do not need to transport full
(x,y)coordinates - Each point contains a unique
x, and one or twoywherey=\sqrt{x^3 + 2x + 2}\mod p
- Most implementations will use the full
xvalue, and append a single bit representing a positive or negative y value
Projective Coordinates
- Some implementations adjust the formula for point addition to use projective coordinates
(x,y,z)rather than(x,y) - The curve sits on the plane
z=1 - Points at infinity
\mathcal O = (0,1,0)
Why?
- Point addition in this system does not require a multiplicative inverse
Standard Curves
- The choice of curve parameters influences both security and efficiency of crypto-systems based around ECs
- Never use a randomly generated curve!
- The chances are the number of points we generate will have a subgroup susecpible to Polig-Hellmen
- Standard curves exist in various forms
- Varied equations
- Different implementation methods
- Different choices of prime
P-256
- Weierstrass curve
y^2\equiv x^3+ax+b\mod p - Very widely used
- One of the few curves in
TLS1.3and NSA Suite B
his the cofactor, the size of the subgroup inG- Because its 1 it means all the points are being generated
- If it was 2, only half of the points are being generated
secp256k1
- Koblitz curve
y^2\equiv x^3+7\mod p - Underpins Bitcoin digital signatures
Curve25519
- Montgomery curve
y^2\equiv x^3 + 486662x^2+x\mod p - Primary alternative to
P-256 - In
TLS1.3and numerous other protocols - The nature of this curve allows efficient multiplication using a Montgomery ladder, using only
XandZ - This algorithm can compute numbers in constant time
Curve448-Goldilocks
- Untwisted Edwards Curve
y^2+x^2\equiv 1 - 39081x^2y^2\mod p - 448 bit curve
- Primarily used within digital signatures as part of
Ed448 - Edwards curve arithmetic mod this “goldilocks” prime is very efficient
Primary Applications
- Elliptic Curve Diffie Hellman
- DSA Signatures scheme, based on Elgamal signatures
- Similar schemes involving the alternative curves such as
Ed25519andEd448












