Nova Patents
CA2308170C

Masked digital signatures

Abstract

The present invention relates to digital signature operations using public key schemes in a secure communications system and in particular for use with processors having limited computing power such as "smart cards". This invention describes a method for creating and authenticating a digital signature comprising the steps of selecting a first session parameter k and generating a first short term public key derived from the session parameter k, computing a first signature component r derived from a first mathematical function using the short term public key, selecting a second session parameter t and computing a second signature component s derived from a second mathematical function using the second session parameter t and without using an inverse operation, computing a third signature component using the first and second session parameters and sending the signature components (r, s, c) as a masked digital signature to a receiver computer system. In the receiver computer system computing a recovered second signature component s' by combining a third signature component with the second signature component to derive signature components ( ~, r) as an unmasked digital signature. Verifying these signature components as in a usual ElGamal or ECDSA type signature verification.

CA2308170C, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 10 November 2018, 7.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

27 claims: 4 independent, 23 dependent

  1. 1
    CA 02308170 2008-11-06 Claims:1. A method of signing and authenticating a message m in a public key data communication system, by a correspondent having a long term private key d, and a corresponding long term public key derived from said long term private key d, comprising the steps of: in a secure computer system: (a) generating a first short term private key k, (b) computing a first short term public key derived from said first short term private key k, (c) computing a first signature component r by using said first short term public key;(d) generating a second short term private key /;(e) computing a second signature component s by using said second short term private key t on said message m, said long term private key d, and said first signature component r;(f) computing a third signature component c using said first and second short term private keys k and t respectively and providing said signature components (r, s, c) as a masked digital signature of said message τη to a receiver computer system associated with said secure computer system;and (g) using said second and third signature components (5, c) to compute a regular signature component s and providing said signature components (s , r) as a regular digital signature to a receiver verifier computer system to enable said verifier system to verify said regular signature (s ,r).
  2. 7
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 1 to 6.
  3. 8
    A cryptographic processor at a sender in a data communication system having access to a long term private key d, and a corresponding long term public key derived from said long term private key d, said processor being configured for performing the method according to any one of claims 1 to 6.
  4. 9
    A method of generating a digital signature S of a message in a data communication system, wherein a signor of the message has a long term private key d and a long term public key y derived from a generator g and said long term private key d, said method comprising the steps of:(a) generating a short term private key k;(b) computing a first short term public key derived from said short term private key k;(c) computing a first signature component r by using said first short term public key k;(d) generating a second short term private key t;(e) computing a second signature component s by using said second short term private key t on said message m, said long term private key d and first signature component r;(f) computing a third signature component c using said first and second short term private keys k and t respectively;and (g) sending said signature components (r, s, c) as a masked digital signature of said message m to a receiver computer system.
  5. 12
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 9 to 11.
  6. 13
    A cryptographic processor at a sender in a data communication system having access to a long term private key d and a long term public key y derived from a generator g and said long term private key d, said processor being configured for performing the method according to any one of claims 9 to 11.
  7. 14
    A processing means for signing a message m without performing inversion operations and including a long term private key contained within a secure boundary and a long term public key derived from said private key and a generator of predetermined order in a field, said processing means comprising:a generator for generating a first short term private key;a generator for generating a second short term private key;a generator for generating a first signature component using at least said second short term private key;said processor operating to generate a masked signature component using said first and second short term private keys to produce masked signature components of said message m.
  8. 16
    A method for verifying a signature for a message m in a data communication system established between a sender and a verifier, said sender having generated in a secure computer 21824077.1 1 1 CA 02308170 2008-11-06 system a masked signature hairing a first signature component r computed using a first short term public key derived from a first short term private key; a second signature component s computed using a second short term private key on said message m, a long term private key, and said first signature component r; and a third signature component c computed using said first and second short term private keys, said method for verifying comprising said verifier:a) obtaining a regular signature derived from said masked signature (r, s, c), said regular signature having said first signature component r, and another signature component s computed using said second signature component s and said third signature component c;b) recovering a point on an elliptic curve defined over a finite field using said message m and said another signature component s;c) converting an element of said point to an integer;d) calculating a value r' using said integer;and e) verifying said regular signature (x , r) if said value r' is equal to said first signature component r.
  9. 26
    A computer readable medium comprising computer executable instructions for performing the method according to any one of claims 16 to 25.
  10. 27
    A cryptographic processor at a verifier in a data communication system, said processor being configured to perform the method according to any one of claims 16 to 25. 21824077.1