EP1590731A2

Modular exponentiation with randomized exponents

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 22 January 2024, 2.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

14 claims: 8 independent, 6 dependent

  1. 1
    Translation of claims of equivalent WO 2004070497 A2 Claims 1. " Device for determining a result of a modular exponentiation within a cryptosystem with a first key (e) and a second key (d), having the following features:means (12) for calculating a randomization auxiliary number based on a product of the first key (e) and the second key (d) less 1;means (14) for obtaining a random number and for combining a product of the random number and the randomization auxiliary number with the first or the second key to obtain a randomized exponent;and means (16) for calculating the result of the modular exponentiation using the randomized exponent.
  2. 3
    Third Apparatus according to either of claims 1 or 2, further comprising means (27, 28) for randomizing the module, the means for randomizing the module being operative to carry out the following equation:N '= N x R, where N' is the randomized modulus, where N is the modulus before randomization, and where R is the random number.
  3. 5
    5th Apparatus according to any one of the preceding claims, adapted to perform a digital signature (60), where m is a plaintext message to be signed, where d is a secret key, where e is a public key, and where N is the module ,
  4. 6
    6th Device for determining a result of a modular exponentiation within a cryptosystem with a first key (e) and an associated second key (d) using the Chinese remainder theorem, with the following features:means (102) for performing a first modular exponentiation using a first subkey derived from the second key (i p ) to obtain a first intermediate result (S p ), and for performing a second modular exponentiation using a second sub-key (dq) derived from the second key to obtain a second intermediate result (S q ) to obtain;and means (104) for combining the first and second intermediate results according to the Chinese remainder theorem to obtain the result of the modular exponentiation, the means (102) for performing comprising: means (110) for calculating a randomization auxiliary number based on a product of a partial key (i.e. p ;d q ) and the first key (s) less "1";means (112) for obtaining a random number and combining a product of the random number and the randomization auxiliary number with a subkey to obtain a randomized exponent, and wherein the means (102) is adapted to perform the randomized one Exponents for calculating the first or the second intermediate result to use.
  5. 10
    10th Apparatus according to any one of the preceding claims, wherein the means (14, 112) is adapted to obtain a random number whose length is between 8 and 128 bits.
  6. 11
    11th Apparatus according to any of claims 6 to 10, wherein the result of the modular exponentiation is a signature of a message, where m is the message before the signature, d is the secret key, e is the public key, and N is the module.
  7. 12
    12th A method of determining a result of a modular exponentiation within a cryptosystem having a first key (e) and a second key (d), comprising the steps of:calculating (12) a randomization helper number based on a product of the first key (e) and the second key (d) less 1;Obtaining (14) a random number and combining a product of the random number and the randomization auxiliary number with the first or second key to obtain a randomized exponent;and calculating (16) the result of the modular exponentiation using the randomized exponent.
  8. 13
    13th A method for determining a result of a modular exponentiation within a cryptosystem having a first key (e) and an associated second key (d) using the Chinese Remainder Theorem, comprising the steps of:Performing (102) a first modular exponentiation using a first subkey derived from the second key to obtain a first intermediate result S p and to perform a second modular exponentiation using a second subkey derived from the second key to obtain a second intermediate result S q to obtain;and combining (104) the first and second intermediate results according to the Chinese remainder theorem to obtain the result of the modular exponentiation, wherein the step of performing (102) comprises the substeps of: Calculating (110) a randomization auxiliary number based on a product of a partial key (i p ;d q and the first key (e) less "1";obtaining (112) a random number and combining a product of the random number and the randomization auxiliary number with a partial key to obtain a randomized exponent, and wherein the step of performing (102 ) is further adapted to use the randomized exponent for calculating the first or the second intermediate result.