CA2792267C

Verifying implicit certificates and digital signatures

Abstract

Methods, systems, and computer programs for verifying a digital signature are disclosed. The verifier accesses an implicit certificate and a digital signature provided by the signer. The implicit certificate includes a first elliptic curve point representing a public key reconstruction value of the signer. The verifier accesses a second elliptic curve point representing a pre-computed multiple of the certificate authority's public key. The verifier uses the first elliptic curve point and the second elliptic curve point to verify the digital signature. The verifier may also use a third elliptic curve point representing a pre-computed multiple of a generator point. Verifying the digital signature may provide verification that the implicit certificate is valid.

CA2792267C, drawing sheet 1
Sheet 1 of 7

Term

6.1 yearsleft in the term

Expires 12 October 2032.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

17 claims: 3 independent, 14 dependent

  1. 1
    CA 02792267 2014-10-09 CLAIMS What is claimed is:1. A computer implemented method for verifying a digital signature, the method comprising: accessing a digital signature associated with an entity, wherein the digital signature includes a first signature element r and a second signature element s;accessing a message m associated with the digital signature (r, s);accessing an implicit certificate issued by a certificate authority and associated 5 with the entity, the implicit certificate including a first elliptic curve point P representing a public key reconstruction value of the entity;accessing a second elliptic curve point representing a pre-computed multiple of a public key C of the certificate authority;accessing a third elliptic curve point Gy representing a pre-computed multiple 10 of a generator point G, the generator point G representing a generator of an elliptic curve group of order n;obtaining a fourth elliptic curve point R based on the first signature element r;computing a first integer u and a second integer v based on the digital signature, wherein the first integer u and the second integer v are each less than Vn;15 computing a hash h of the message m;computing a third integer 2 0 and a fourth integer Ay such that A = A o + Λ 1 2^/ 2 ζ where t = [log 2 (n + 1)1, A = kv/s·, computing a fifth integer y 0 and a sixth integer γ ± such that γ = y 0 + γ 1 2^ 2 1, where γ = vr/s;20 verifying that A Q G -(- A 0 Gy + y 0 C + YyCy + uP — vR = 0 to verify the digital signature by data processing apparatus, where O represents an identity element of the elliptic curve group. CA 02792267 2014-10-09
  2. 6
    A computing device comprising:20 one or more hardware processors configured to: access a digital signature associated with an entity, wherein the digital signature includes a first signature element r and a second signature element s;access a message τη associated with the digital signature (r, s);access an implicit certificate issued by a certificate authority and 25 associated with the entity, the implicit certificate including a first elliptic curve point P representing a public key reconstruction value of the entity;access a second elliptic curve point Q representing a pre-computed multiple of a public key C of the certificate authority;CA 02792267 2014-10-09 access a third elliptic curve point G r representing a pre-computed multiple of a generator point G, the generator point G representing a generator of an elliptic curve group of order n;obtain a fourth elliptic curve point R based on the first signature 5 element r;compute a first integer u and a second integer v based on the digital signature, wherein the first integer u and the second integer v are each less than Vn;compute a hash h of the message m;compute a third integer A o and a fourth integer such that λ = A o ΙΙΟ A 1 2^ z \ where t = [log 2 (n + 1)1, A = hv/s;compute a fifth integer y 0 and a sixth integer y-L such that y = y 0 + y t 2^ 2 \ where y = vr/s;verify that A 0 G + X 0 G 1 + y 0 C + y^ + uP - vR = 0 to verify the digital signature by data processing apparatus, where 0 represents an identity element 15 of the elliptic curve group.
  3. 12
    A non-transitory computer-readable medium storing instructions that are 15 operable when executed by data processing apparatus to perform operations for verifying a digital signature, the operations comprising:accessing a digital signature associated with an entity, wherein the digital signature includes a first signature element r and a second signature element s;accessing a message m associated with the digital signature (r, s);20 accessing an implicit certificate issued by a certificate authority and associated with the entity, the implicit certificate including a first elliptic curve point P representing a public key reconstruction value of the entity;accessing a second elliptic curve point C ± representing a pre-computed multiple of a public key of the certificate authority;25 accessing a third elliptic curve point 6/ representing a pre-computed multiple of a generator point G, the generator point G representing a generator of an elliptic curve group of order n;obtaining a fourth elliptic curve point R based on the first signature element r;CA 02792267 2014-10-09 computing a first integer u and a second integer v based on the digital signature, wherein the first integer u and the second integer v are each less than Vn;computing a hash h of the message m;computing a third integer A o and a fourth integer A ± such that A = A o + 5 A 1 2^ t C\ where t = [log 2 (n + 1)], A = hv/s;computing a fifth integer y 0 and a sixth integer γ 1 such that y = y 0 + Yι2^ 2 ζ where y = vr/s', verifying that A 0 G + A 0 G 1 + y 0 C + y 1 C 1 + uP — vR = 0 to verify the digital signature, where 0 represents an identity element of the elliptic curve group. 10