Nova Patents
EP0807908A2

Digital signatures on a smartcard

Abstract

A digital signature scheme for a "smart" card utilizes a set of prestored signing elements and combines pairs of the elements to produce a new session pair. The combination of the elements is performed partly on the card and partly on the associated transaction device so that the exchange of information between card and device does not disclose the identity of the signing elements. The signing elements are selected in a deterministic but unpredictable manner so that each pair of elements is used once. Further signing pairs are generated by implementing the signing over an anomalous elliptic curve encryption scheme and applying a Frobenius Operator to the normal basis representation of one of the elements.

EP0807908A2, drawing sheet 1
Sheet 1 of 23

Term

Term ended

Projected expiry passed 15 April 2017, 9.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

27 claims: 5 independent, 22 dependent

  1. 1
    A method of generating a digital signature implemented over an elliptic curve public key encryption scheme utilizing information maintained secret in one computing device comprising the steps of (i) initiating the computation of a coordinate of a point on the elliptic curve from a pair of other points on said curve by performing on said one device (10) sufficient steps in the computation to inhibit recognition of information pertaining to the identity of said other points (steps I to III of Figure 5), (ii) transferring to another computing device (30) remote from the one device (10) the results of said steps (step IV), (iii) performing at least such additional steps in said computation at said other device to permit the completion of said computation at said one device (step V), and (iv) transferring the result of said additional steps to said one device (10) for incorporation in said signature(step VI).
  2. 10
    A method of deriving a coordinate of a point on an anomalous elliptic curve over the field GF2 m for utilization in a public key encryption scheme implemented on said curve, said method comprising the steps of (i) storing (20) a normal basis representation of each of a set of coordinates of points on said curve, (ii) retrieving said normal basis representation of a coordinate of one of said points (step I;figure 5);(iii) performing an i-fold cyclic shift on said retrieved normal basis representation of said one coordinate (step III), and (iv) utilizing the resultant representation as a coordinate of a further point on the curve resulting from an i-fold application of the Frobenius Operator to said one point (step III).
  3. 12
    A method of generating a session pair k,kP for use in a digital signature performed on an anomalous elliptic curve in the field GF2 m where kP is a point on said curve resulting from the k fold addition of a starting point P where k is an integer, said method comprising the steps of (i) storing (20) a set of initial values of k and kP, as a normal basis representation in the field GF2 m , (ii) selecting a coordinate of one of said points kP in said set of initial values (Figure 5, step I);(iii) performing an i-fold cyclic shift on said coordinate to obtain a normal basis representation of the coordinate after an i-fold application of a Frobenius Operator (step II);(iv) selecting the integer k associated with said one of said points;(v) computing an integer value λ i k where λ defines the relationship between the start point P and a point ØP and Ø indicates a Frobenius Operation (step VII);(vi) utilizing the resultant representation of the coordinate and the value λ i k as a session pair in a digital signature utilizing signature components r,s where r is derived from the representation of a coordinate of a point on the curve and s is derived from the integer value associated with such point, the message (m) to be signed ad r.
  4. 13
    A method of generating signature components for use in a digital signature scheme, said signature components including private information and a public key derived from said private information, said method comprising the steps of storing private information and related public key as an element in a set of such information (20), cycling in a deterministic but unpredictable fashion through said set to select at least one element of said set without repetition and utilizing said one element to derive a signature component in said digital signature scheme (Figure 6).
  5. 21
    A method of generating a digital signature implemented over an elliptic curve public key encryption scheme utilizing a session pair k, kP in which k is an integer maintained secret and kP represents a point on said curve resulting from a k-fold addition of starting point P, said method comprising the steps of storing a set of elements (52), each element having a normal basis representation of a value of k and a normal basis representation of a value of kP in the field GF2 m , identifying each element of said set for subsequent retrieval, selecting a pair of said elements in a deterministic and unpredictable manner (step I, Figure 6) and combining said elements (step IV) to provide a session pair for use in said digital signature.