Beruflich Dokumente
Kultur Dokumente
Y axis
X axis
2 2
• We know that 1 + 0 + x = 3/2 =>
x = ½ and y = ½
• Using symmetry of the curve we also have (1/2,-1/2)
as another solution
Diophantus’ Method
• Consider the line through (1/2,-1/2) and (1,1) =>
y=3x-2
• Intersecting with the curve we have:
51 2
x x ... 0
3
2
• Thus ½ + 1 + x = 51/2 or x = 24 and y=70
y x ax b
2 3
Examples
Weierstrass Equation
• A two variable equation F(x,y)=0, forms a curve
in the plane. We are seeking geometric
arithmetic methods to find solutions
a1 x a3 2 a12 2 a32
(y ) x (a2 ) x a4 x ( a6 )
3
2 2 4 4
y1 x3 a2' x 2 a4' x a6'
2
x1 x a2' / 3
y1 x1 Ax1 B
2 3
Points on the Elliptic Curve (EC)
• Elliptic Curve over field L
E ( L) {} {( x, y) L L | y ... x ...}
2 3
• P + Q = Q + P (commutativity)
• (P + Q) + R = P + (Q + R) (associativity)
y
• Consider elliptic curve
E: y2 = x3 - x + 1
P2 • If P1 and P2 are on E, we
P1
can define
x
P3 = P1 + P2
P3
as shown in picture
• Addition is all we need
Addition in Affine Co-ordinates
y=m(x-x1)+y1 P ( x1 , y1 ), Q ( x2 , y2 )
R ( P Q) ( x3 , y3 )
y
Let, P≠Q,
y2=x3+Ax+B
Doubling of a point
• Let, P=Q
dy
2y 3x 2 A
dx
dy 3x12 A
m
dx 2 y1
If , y1 0 (since then P1 +P2 =):
0 x3 m 2 x 2 ...
x3 m 2 2 x1 , y3 m( x1 x3 ) y1
y P2=O=∞
P1=P1+ O=P1
P1
Sum of two points
Define for two points P (x1,y1) and
Q (x2,y2) in the Elliptic curve
y2 y1
for _ x1 x2
x x
22 1
3 x1 a for _ x1 x2
2 y1
x3 x1 x2
y3 ( x3 x1 ) y1
Point at infinity O
P+P = 2P
a(x,y)
b(x,y)
Alice, A Bob, B
ECC Level 0
Point
multiplication: Level 1
kP
– End for
– Return Q
Example
• Compute 7P:
– 7=(111)2
– 7P=2(2(P)+P)+P=> 2 iterations are required
– Principle: First double and then add
(accumulate)
• Compute 6P:
– 6=(110)2
– 6P=2(2(P)+P)
Scalar Multiplication: LSB first
• Require k=(km-1,km-2,…,k0)2, km=1
• Compute Q=kP
– Q=0, R=P
– For i=0 to m-1 Can Parallelize…
x x a; P Q
• Let, R=P+Q=(x3,y3)
1 2 1 2
x x x x
1 2
1 2 1 2
x3 b
x12 2 ; P Q
x1
1. Point addition and doubling
each require 1 inversion
& 2 multiplications y1 y2
( x1 x3 ) x3 y1 ; P Q
2. We neglect the costs of
1 2
x x
squaring and addition y3 y1
3. Montgomery noticed that the x1
2
( x1 ) x3 x3 ; P Q
x1
x-coordinate of 2P does not
depend on the y-coordinate of
P
Montgomery’s method to perform scalar
multiplication
• Input: k>0, P
• Output: Q=kP
1. Set k<-(kl-1,…,k1,k0)2
2. Set P1=P, P2=2P
3. For i from l-2 to 0 Invariant Property:
If ki=1, P=P2-P1
Set P1=P1+P2, P2=2P2
else Question: How to implement the
Set P2=P2+P1, P1=2P1 Operation efficiently?
4. Return Q=P1
Example
Compute 7P Compute 6P
• 7=(111)2 • 7=(110)2
• Initialization: • Initialization:
P1=P; P2=2P P1=P; P2=2P
• Steps: • Steps:
– P1=3P, P2=4P – P1=3P, P2=4P
– P1=7P, P2=8P – P2=7P, P1=6P
Fast Multiplication on EC
without pre-computation
Result-1
• Let P1 = (x1,y1) and P2=(x2,y2) be elliptic points.
Then the x-coordinate of P1+P2, x3 can be
computed as:
x1 y2 x2 y1 x x x x 2 2
x3 1 2 2 1
( x1 x ) 2
2
• In Projective Coordinates:
• 0 inverses
P1 P2 , X 3 X b.Z
1
4
1
4
• 4 general field
Z 3 Z12 . X 12 multiplications
• 3 additions
P1 P2 , Z 3 ( X 1.Z 2 X 2 .Z1 ) 2
• 5 squarings
X 3 x.Z 3 ( X 1.Z 2 ).( X 2 .Z1 )
Montgomery Algorithm
• Input: k>0, P=(x,y)
• Output: Q=kP
• Set k<-(kl-1,…,k1,k0)2
• Set X1=x, Z1=1; X2=x4+b, Z2=x2
• For i from l-2 to 0
– If ki =1,
Madd(X1,Z1,X2,Z2), Mdouble(X2,Z2)
else
Madd(X2,Z2,X1,Z1), Mdouble(X1,Z1)
• Return Q=(Mxy(X1,Y1,X2,Y2))
Mxy: Projective to Affine
x3 X 1 / Z1
y3 ( x X 1 / Z1 )[( X 1 xZ1 )( X 2 xZ 2 ) ( x 2 y )( Z1Z 2 )]( xZ1Z 2 ) 1 y
Hence, final decision depends upon the I:M ratio of the finite field operators
Addition in Mixed Coordinates
• Theorem: Let P1=(X1/Z1,Y1/Z12) and
P2=(X2/Z2,Y2/Z22) be two points on the curve.
If Z1=1, then P1+P2=(X3/Z3,Y3/Z32) st.
U Z 22Y1 Y2 , S Z 2 X 1 X 2 , T Z 2 S , Z 3 T 2 ,
V Z 3 X 1 , X 3 U 2 T (U S 2 Ta ),
Y3 (V X 3 )(TU Z 3 ) Z 32C
ECC Level 0
Point
multiplication: Level 1
kP
• Let Q=(u,v)=2P
• Compute P=(x,y)
• Remember : b
ux 2
x2
y
v x ( x )u u
2
x
Halving (contd.)
y
Let , x
x
Square
v x 2 ( 1)u x v ( 1)u Root
Note : 2 u a Solving
Quadratics
• Properties of Trace:
– Tr(c)=Tr(c2)=Tr(c)2, Tr(c) can be 0 or 1
– Tr(c+d)=Tr(c)+Tr(d)
– NIST Curves : Tr(a)=1
– If x,y belongs to the Elliptic Curve, Tr(x)=Tr(a)
Computing λ
• The roots of 2 u a are λ1= λ or λ+1
• Theorem:
Let, P ( x, y ), Q (u, v) G, st. Q 2 P
and denote x y / x. Let ˆ be a solution
to 2 u a and t v uˆ. Suppose that
Tr (a) 1. Then ˆ if and only if Tr (t ) 0.
Halving Algorithm
• Input: (u,v) , Output: (x,y)
1. Solve u a for λ. Let the root be ̂
2
2. Compute t v uˆ
3. If Tr(t)=0, then λP= ̂ , x=(t+u)1/2
else λP= ̂ +1,x=(t)1/2
4. Return (x,λP)
Implementation of Trace
m 1 m 1
• Trace : Tr (C ) Tr ( ci x ) ciTr ( xi )
i
i 0 i 0
1. H (C D) H (C ) H ( D)
2. H (C ) is a root for x 2 x C Tr (C ), as
H (C ) H (C 2 ) C Tr (C )
H(C) gives a root for the quadratic equation. A simple method to find
H(C) requires storage for m elements and m/2 field additions on an average
Obtaining Square Root
• Field squaring in binary field is linear
• Hence squaring can be rephrased as:
– C=MA=A2
• We require to compute D st. D2=A
• Let, D=M-1A=> A=MD
• D2=MD (as M is the squaring matrix)
=M(M-1A)=A
• Hence, D=(A)1/2
An Example
Compute: 763R 7 , where order of R 7 1013
m 10
2101 (763) 651(mod 1013) (1010001011)2
1 1 1 1
763 ( 9 8 6 2 1) mod(1013)
2 2 2 2
763R7 may be computed using the following steps:
1
Step 1: R7 R7
2
1 1
Step 2: ( R7 R7 ) R7
2 2
Step 3: Similarly continue...
Half and Add Algorithm
1. Input: 0<k<n, P=(x,y)
2. Output: Q=kP
3. Compute: t= log n 1 , k1=(2t-1k)mod n
2
4. Q=O
5. for i=0 to m-1 do
1. Q=[1/2]Q
2. If, k1i=1, then Q=Q+P
6. return Q
No method is currently known to perform point halving in projective
Coordinates. Keep Q in affine coordinates and P in Projective
Coordinates. Then step 5.2 is a mixed operation, giving further
efficiency.
Key References
• Papers:
– J. Lopez and R. Dahab, “Fast Multiplication on Elliptic Curves
over GF(2m) without pre-computation”, CHES 1999
– K. Fong etal, “Field Inversion and Point Halving Revisited”, IEEE
Trans on Comp, 2004
– G. Orlando and C. Paar, “A High Performance Reconfigurable
Elliptic Curve Processor for GF(2m)”, CHES 2000
– N. A. Saqib etal, “A Parallel Architecture for Fast Computation of
Elliptic Curve Scalar Multiplication over GF(2m)”, Elsevier Journal
of Microprocessors and Microsystems, 2004
– Sabiel Mercurio etal, “ An FPGA Arithmetic Logic Unit for
Computing Scalar Multiplication using the Half-and-Add Method”,
IEEE ReConfig 2005
Key References
• Books:
– Elliptic Curves: Number Theory and
Cryptography, by Lawrence C. Washington
– Guide to Elliptic Curve Cryptography, Alfred J.
Menezes
– Guide to Elliptic Curve Cryptography, Darrel
R. Hankerson, A. Menezes and A. Vanstone
– http://cr.yp.to/ecdh.html ( Daniel Bernstein)
Thank You