EP0940944B1

Elliptic curve transformation device, utilization device and utilization system

Abstract

This record has no abstract on file.

EP0940944B1, drawing sheet 1
Sheet 1 of 222

Term

Term ended

Expired 5 March 2019, 7.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

12 claims: 6 independent, 6 dependent

  1. 1
    An encryption/decryption apparatus utilising an elliptic curve E which is expressed as y ^2 = x ^3 + α × x + β    and defined over a finite field GF(p) , p being a prime number, α being a parameter of the elliptic curve E, and β being a parameter of the elliptic curve E ,     characterised in that the apparatus includes an elliptic curve transformation device for transforming the elliptic curve E into an elliptic curve Et, the device comprising:receiving means for receiving an element G as a base point, the prime number p , the parameter α, and the parameter β from an external device, the element G existing on the elliptic curve E and being expressed as G=(x0,y0) ;transformation coefficient acquiring means for acquiring a transformation coefficient t that is present on the finite field GF(p) , where t≠0 and a number of digits of t ^4 × α (mod p) is smaller than a number of digits of the prime number p ;elliptic curve calculating means for calculating a parameter α' and a parameter β' of the elliptic curve Et and an element Gt that is a new base point and is expressed as Gt=(xt0,yt0) , using the transformation coefficient t according to α' = α×t ^4 β' = β x t ^6 xt0 = t ^2×x0 yt0 = t ^3×y0    where the elliptic curve Et is expressed as y' ^2 = x' ^3 + α'×x' + β'    and defined over the finite field GF(p) ;and    outputting means for outputting the parameter α', the parameter β', and the element Gt to the external device.
  2. 5
    An encryption/decryption arrangement utilising an elliptic curve E which is expressed as y ^2 = x ^3 + α×x + β    and defined over a finite field GF(p) , p being a prime number, α being a parameter of the elliptic curve E, and β being a parameter of the elliptic curve E ,     characterised in that the arrangement includes an elliptic curve transformation device for transforming the elliptic curve E into an elliptic curve Et and a cryptographic device using the elliptic curve Et generated by the elliptic curve transformation device, the cryptographic device comprising first outputting means, first receiving means and utilizing means, while the elliptic curve transformation device includes second receiving means, transformation coefficient acquiring means, elliptic curve calculating means and second outputting means,    wherein the first outputting means outputs an element G as a base point, the prime number p, the parameter α, and the parameter β to the elliptic curve transformation device, the element G existing on the elliptic curve E and being expressed as G = (x0,y0)    wherein the second receiving means receives the prime number p, the parameter α, the parameter β and the element G from the cryptographic device,    wherein the transformation coefficient acquiring means acquires a transformation coefficient t that is present on the finite field GF(p) , where t≠0 and a number of digits of t^4 × α(mod p) is smaller than a number of digits of the prime number p ,    wherein the elliptic curve calculating means calculates a parameter α' and a parameter β' of the elliptic curve Et and an element Gt that is a new base point and is expressed as Gt=(xt0,yt0) , using the transformation coefficient t according to α'=α× t^4 β'=β× t^6 xt0 = t^2×x0 yt0 = t^3×y0    where the elliptic curve Et is expressed as y' ^2 = x' ^3 + α'×x' + β'    and defined over the finite field GF(p) ,    wherein the second outputting means outputs the parameter α', the parameter β' and the element Gt to the cryptographic device,    wherein the first receiving means receives the parameter α',    the parameter β', and the element Gt from the elliptic curve transformation device, and    wherein the utilizing means performs one of encryption, decryption, digital signature, digital signature verification, and key agreement using a discrete logarithm problem as a basis for security, by performing calculations on the elliptic curve Et using the prime number p, the elliptic curve Et defined by the parameter α', and the parameter β' over the finite field GF(p) , and the element Gt as the base point.
  3. 9
    A cryptographic device for receiving, from an elliptic curve transformation device that includes second receiving means, transformation coefficient acquiring means, elliptic curve calculating means and second outputting means and transforms an elliptic curve E into an elliptic curve Et, the elliptic curve Et and using the received elliptic curve Et,    the elliptic curve E being expressed as y ^2 = x ^3 + α×x + β    and defined over a finite field GF(p) , p being a prime number, α being a parameter of the elliptic curve E , and β being a parameter of the elliptic curve E , the cryptographic device comprising first outputting means, first receiving means, and utilizing means,    wherein the first outputting means outputs an element G as a base point, the prime number p , the parameter α and the parameter β to the elliptic curve transformation device, the element G existing on the elliptic curve E and being expressed as G=(x0,y0) ,    wherein the second receiving means receives the prime number p , the parameter α, the parameter β and the element G from the cryptographic device,    wherein the transformation coefficient acquiring means acquires a transformation coefficient t that is present on the finite field GF(p) , where t≠0 and a number of digits of t^4 × α(mod p) is smaller than a number of digits of the prime number p ,    wherein the elliptic curve calculating means calculates a parameter α' and a parameter β' of the elliptic curve Et and an element Gt that is a new base point and is expressed as Gt=(xt0,yt0), using the transformation coefficient t according to α'=α× t^4 β' = β×t^6 xt0 = t^2×x0 yt0 = t^3×y0    where the elliptic curve Et is expressed as y' ^2 = x' ^3 + α'×x' + β'    and defined over the finite field GF(p) ,    wherein the second outputting means outputs the parameter α', the parameter β', and the element Gt to the cryptographic device,    wherein the first receiving means receives the parameter α', the parameter β' and the element Gt from the elliptic curve transformation device, and    wherein the utilizing means performs one of encryption, decryption, digital signature, digital signature verification, and key agreement using a discrete logarithm problem as a basis for security, by performing calculations on the elliptic curve Et using the prime number p, the elliptic curve Et defined by the parameter α' and the parameter β' over the finite field GF(p) , and the element Gt as the base point.
  4. 10
    A cryptographic device for using an elliptic curve Et which is generated as a result of transformation of an elliptic curve E , wherein the elliptic curve E is expressed as y ^2 = x ^3 + α×x + β    and defined over the finite field GF(p) , while G as a base point is an element on the elliptic curve E and is expressed as G=(x0,y0) ,     characterised in that the device comprises:storing means for storing an element Gt as a base point, a parameter α' of the elliptic curve Et , and a parameter β' of the elliptic curve Et ;and utilizing means for performing one of encryption, decryption, digital signature, digital signature verification, and key agreement using a discrete logarithm problem as a basis for security, by performing calculations on the elliptic curve Et using a prime number p, the elliptic curve Et defined by the parameter α' and the parameter β' over a finite field GF(p) , and the element Gt as the base point,    wherein the parameter α', the parameter β' and the element Gt are generated by an elliptic curve transformation device that includes transformation coefficient acquiring means and elliptic curve calculating means,    wherein the transformation coefficient acquiring means acquires a transformation coefficient t that is present on the finite field GF(p) , where t≠0 and a number of digits of t^4 × α(mod p) is smaller than a number of digits of the prime number p , and    wherein the elliptic curve calculating means calculates the parameter α', the parameter β' and the element Gt which is present on the elliptic curve Et and is expressed. as Gt=(xt0,yt0) , using the transformation coefficient t according to α' = α×t^4 β' = β×t^6 xt0 = t^2×x0 yt0 = t^3×y0    where the elliptic curve Et is expressed as y' ^2 = x' ^3 + α'×x' + β'    and defined over the finite field GF(p) .
  5. 11
    A cryptographic method utilizing an elliptic curve E which is expressed as y ^2 = x ^3 + α×x + β    and defined over a finite field GF(p) , p being a prime number, α being a parameter of the elliptic curve E, and β being a parameter of the elliptic curve E,     characterised in that the method includes an elliptic curve transformation method for transforming the elliptic curve E into an elliptic curve Et comprising:a receiving step for receiving an element G as a base point, the prime number p, the parameter α, and the parameter β from an external device, the element G existing on the elliptic curve E and being expressed as G=(x0,y0) ;a transformation coefficient acquiring step for acquiring a transformation coefficient t that is present on the finite field GF(p) , where t≠0 and a number of digits of t^4 × α(mod p) is smaller than a number of digits of the prime number p ;an elliptic curve calculating step for calculating a parameter α' and a parameter β' of the elliptic curve Et and an element Gt that is a new base point and is expressed as Gt=(xt0,yt0) , using the transformation coefficient t according to α' = α×t^4 β' = β×t^6 xt0 = t^2×x0 yt0 = t^3 ×y0    where the elliptic curve Et is expressed as y' ^2 = x' ^3 + α'4×x' + β'    and defined over the finite field GF(p) ;and    an outputting step for outputting the parameter α', the parameter β' and the element Gt to the external device.
  6. 12
    A computer-readable storage medium storing a program for encrypting/decrypting information utilizing an elliptic curve E which is expressed as y ^2 = x ^3 + α×x + β    and defined over a finite field GF(p) , p being a prime number, α being a parameter of the elliptic curve E, and β being a parameter of the elliptic curve E,     characterised in that the program for encrypting/decrypting information utilizes an elliptic curve transformation program for transforming the elliptic curve E into an elliptic curve Et, the elliptic curve transformation program comprising:a receiving step for receiving an element G as a base point, the prime number p, the parameter α, and the parameter β from an external device, the element G existing on the elliptic curve E and being expressed as G=(x0,y0) ;a transformation coefficient acquiring step for acquiring a transformation coefficient t that is present on the finite field GF(p) , where t≠0 and a number of digits of t^4 × α(mod p) is smaller than a number of digits of the prime number p ;an elliptic curve calculating step for calculating a parameter α' and a parameter β' of the elliptic curve Et and an element Gt that is a new base point and is expressed as Gt=(xt0,yt0) , using the transformation coefficient t according to α' = α×t^4 β' = β×t^6 xt0 = t^2×x0 yt0 = t^3×y0    where the elliptic curve Et is expressed as y' ^2 = x'^3 + α'×x' + β'    and defined over the finite field GF(p) ;and    an outputting step for outputting the parameter α', the parameter β' and the element Gt to the external device.