CA2306282C

Accelerated signature verification on an elliptic curve

Abstract

A public key encryption system exchanges information between a pair of correspondents. The recipient performs computations on the received data to recover the transmitted data or verify the identity of the sender. The data transferred includes supplementary information that relates to intermediate steps in the computations performed by the recipient.

CA2306282C, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Expired 16 October 2018, 7.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

71 claims: 9 independent, 62 dependent

  1. 1
    CA 02306282 2011-04-27 Claims:1. A method of transferring data over a communication channel between a pair of correspondents who perform public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said pair of correspondents, the complementary mathematical operations being performed upon information transferred between said pair of correspondents, said method comprising the steps of: a) assembling at one of said correspondents a data string including information to be transferred to the other of said correspondents;b) performing at said one of said correspondents one of said complementary mathematical operations upon at least a portion of said data string to provide a cryptographic component to said data string;c) incorporating in said data string additional information supplementary to that necessary for said other correspondent to perform the other of said complementary mathematical operations of said public key cryptographic operations, said additional information relating to the computation of intermediate steps involved in the performance of said other of said complementary mathematical operations;d) forwarding said data string over said communication channel to said other correspondent;and e) performing the other of said complementary mathematical operations of said public key cryptographic operations at said other correspondent with said additional information being available to facilitate the computation of said intermediate steps involved in said other of said complementary mathematical operations of said public key cryptographic operations. 22104208.1 CA 02306282 2011-04-27
  2. 6
    The method according to any one of claims 3 to 5 wherein said additional information includes an indication as to which of a pair of possible values resulting from said intermediate steps is an intended value.
  3. 15
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 1 to 14.
  4. 16
    A system for transferring data over a communication channel comprising a pair of correspondent devices who perform public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said pair of correspondent devices, the complementary mathematical operations being performed upon information transferred between said pair of correspondent 22104208.1 CA 02306282 2011-04-27 devices, said system being configured for having the correspondent devices perform the method according to any one of claims 1 to 14.
  5. 17
    A method of transferring data over a communication channel between a pair of correspondents who perform public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said pair of correspondents, the complementary mathematical operations being performed upon information transferred between said pair of correspondents, said method comprising the steps of:a) assembling at one of said correspondents a data string including information to be transferred to the other of said correspondents;b) performing at said one of said correspondents one of said complementary mathematical operations upon at least a portion of said data string to provide a cryptographic component to said data string;c) providing for said other correspondent, additional information supplementary to that necessary for said other correspondent to perform the other of said complementary mathematical operations of said public key cryptographic operations, said additional information relating to the computation of intermediate steps involved in the performance of said other of said complementary mathematical operations;d) forwarding said data string over said communication channel to said other correspondent;and e) performing the other of said complementary mathematical operations of said public key cryptographic operations at said other correspondent with said additional information being available to facilitate the computation of intermediate steps involved in said other of said complementary mathematical operations of said public key cryptographic operations. 22104208.1 CA 02306282 2011-04-27
  6. 19
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 17 to 18.
  7. 20
    A system for transferring data over a communication channel comprising a pair of correspondent devices who perform public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said correspondent devices, the complementary mathematical operations being performed upon information transferred between said pair of correspondent devices, said system being configured for having the correspondent devices perform the method according to any one of claims 17 to 18.
  8. 21
    A method of facilitating cryptographic signature verification between a first correspondent and a second correspondent connected by a communications channel, said method comprising steps of:a) assembling at said first correspondent a data string including information to be transferred to said second correspondent;b) providing for said second correspondent, a first set of information sufficient to permit a signature verification, and additional information supplementary to that of said first set of information, said additional information facilitating the computation of at least one intermediate step involved in the performance of said signature verification;c) signing at least a portion of said data string to produce a signature;and d) forwarding said signature over said communications channel to said second correspondent;whereby verification of said signature at said second correspondent can be facilitated by using said additional information in the computation of said at least one intermediate step during said signature verification.
  9. 27
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 21 to 26.
  10. 28
    A cryptographic unit comprising a processor configured for performing the method according to any one of claims 21 to 26.
  11. 29
    A method of verifying a cryptographic signature received from a first correspondent by a second correspondent over a communications channel, said method comprising the steps of:a) said second correspondent obtaining, a first set of information sufficient to permit said signature to be verified and additional information supplementary to that of said first set of information, said additional information facilitating the computation of at least one intermediate step involved in the performance of said signature verification;and b) verifying said signature at said second correspondent with said additional information being available to facilitate the computation of said at least one intermediate step during said signature verification. 22104208.1 CA 02306282 2011-04-27
  12. 35
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 29 to 34.
  13. 36
    A cryptographic unit comprising a processor configured for performing the method according to any one of claims 29 to 34.
  14. 37
    A correspondent device having a processor for verifying a signature received from another correspondent over a communications channel, said processor configured to perform computer executable instructions for:a) obtaining a first set of information sufficient to permit said signature to be verified and additional information supplementary to that of said first set of information, said additional information facilitating the computation of at least one intermediate step involved in the performance of said signature verification;and 22104208.1 CA 02306282 2011-04-27 b) verifying said signature with said additional information being available to facilitate the computation of said at least one intermediate step during said signature verification.
  15. 38
    A method of generating a certificate in a cryptographic data communication system, said method comprising:- determining, for a first set of information sufficient to permit verification of a signature, additional information supplementary to that of said first set of information, said additional information facilitating the computation of at least one intermediate step involved in the performance of said verification;- incorporating said additional information in a certificate associated with said signature to be verified by a recipient;and - making said certificate available to said recipient to thereby provide said additional information to facilitate verification of said signature, wherein said additional information is to be used in at least one intermediate step involved in the performance of said verification.
  16. 42
    The method according to any one of claims 38 to 41 wherein said additional information includes data pertaining to coordinates of points on an elliptic curve used in said verification. 22104208.1 CA 02306282 2011-04-27
  17. 46
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 38 to 45.
  18. 48
    A method of transferring data over a communication channel between a pair of correspondents in a data communication system and facilitating a computation performed by one of said correspondents, the correspondents performing public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said correspondents, the complementary mathematical operations being performed upon information transferred between said correspondents, said method comprising the steps of:a) assembling at a first of said correspondents a data string including information to be transferred to a second of said correspondents;b) performing at said first of said correspondents one of said complementary mathematical operations upon at least a portion of said data string to provide a cryptographic component to said data string;22104208.1 CA 02306282 2011-04-27 c) incorporating in said data string additional information supplementary to that necessary for said second of said correspondents to perform the other of said complementary mathematical operations of said public key cryptographic operations, said additional information being usable by said second correspondent to facilitate the computation of intermediate steps of the other of said complementary mathematical operations;and d) forwarding said data string over said communication channel to said second correspondent.
  19. 54
    A method of transferring data over a communication channel between a pair of correspondents in a data communication system and facilitating a computation performed by one 22104208.1 CA 02306282 2011-04-27 of said correspondents, the correspondents performing public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said correspondents, the complementary mathematical operations being performed upon information transferred between said correspondents, said method comprising the steps of:a) receiving at a second correspondent a data string having a cryptographic component provided by a first correspondent by said first correspondent performing one of said complementary mathematical operations upon at least a portion of said data string;b) said second correspondent performing the other of said complementary mathematical operations on said cryptographic component of said data string, wherein computation of intermediate steps of the other of said complimentary mathematical operations is facilitated by additional information made available to said second correspondent, the additional information being supplementary to that necessary for said second correspondent to perform the other of said complementary mathematical operations.
  20. 57
    The method according to any one of claims 54 to 56 wherein said complementary mathematical operations include operations involving an underlying elliptic curve group.
  21. 68
    A method of transferring data over a communication channel between a pair of correspondents in a data communication system and facilitating a computation performed by one of said correspondents, the correspondents performing public key cryptographic operations by implementing respective ones of a pair of complementary mathematical operations utilizing a public key and a private key of one of said correspondents, the complementary mathematical operations being performed upon information transferred between said correspondents, said method comprising the steps of:a) assembling at a first of said correspondents a data string including information to be transferred to a second of said correspondents;b) performing at said first of said correspondent one of said complementary mathematical operations upon at least a portion of said data string to provide a cryptographic component to said data string;c) providing for said second of said correspondents additional information supplementary to that necessary for said second of said correspondents to perform the other of said complementary mathematical operations of said public key cryptographic operations, said additional information being usable by said second of said correspondents to facilitate the computation of intermediate steps of the other of said complementary mathematical operations;and d) forwarding said data string over said communication channel to said second of said correspondents. 22104208.1 CA 02306282 2011-04-27
  22. 70
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 48 to 69.
Independent claims22