WO2006076800A1

Accelerated verification of digital signatures and public keys

Abstract

Accelerated computation of combinations of group operations in a finite field is provided by arranging for at least one of the operands to have a relatively small bit length. In a elliptic curve group, verification that a value representative of a point R corresponds the sum of two other points uG and vG is obtained by deriving integers w, z of reduced bit length and so that v = w/z. The verification equality R = uG + vQ may then be computed as -zR +(uz mod n) G + wQ = O with z and w of reduced bit length. This is beneficial in digital signature verification where increased verification can be attained.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

38 claims: 5 independent, 33 dependent

  1. 1
    What we claim is 1. A method of verifying the equality of a relationship between the sum of scalar multiples of a pair of points on an elliptic curve and a third point on said curve comprising the steps of i) obtaining a pair of integers of bit length less than one of said scalars and whose ratio corresponds to said scalar, ii) substituting said integers for said scalars in said relationship to obtain an equivalent relationship in which at least one of said terms is a scalar multiple of one of said points with reduced bit length, and iii) computing said equivalent relationship to verify said equality.
  2. 16
    A method of verifying a digital signature of a message performed by a cryptographic operation in a group of a finite field having elements represented by bit strings of defined maximum bit length, said signature comprising a pair of components, one of which is derived from an ephemeral public key of a signer and the other of which combines said message, said first component and said ephemeral public key and a long term public key of said signer, said method comprising the steps of recovering said ephemeral public key from said first component, establishing a verification equality as a combination of group operations on said ephemeral public key, said long term public key and a generator of said group with at least one of said group operations involving an operand represented by bit strings having a reduced bit length less than said defined maximum bit length, computing said combination and accepting said signature if said equality holds and rejecting said signature if said equality fails.
  3. 31
    A method of generating a signature of a message by a cryptographic operation in an elliptic curve group of finite field comprising the steps of generating a pair of signature components with one of said components derived from a point representing an ephemeral public key and including in said signature an indicator to identify one of a plurality of possible values of said public key that may be recovered from said one component.
  4. 33
    A digital signature of a message obtained using cryptographic operations in an elliptic curve cryptosystem, said signature including a first component derived from a point representative of an ephemeral public key of the signer and an indicator to identify are of a plurality of values of said public key recoverable from said first component.
  5. 35
    A method of generating a digital signature of a message obtained using cryptographic operations in an elliptic curve cryptosystem comprising the steps of generating a point representative of an ephemeral public key, determining if coordinates of said point meet prearranged criteria and inhibiting use or said point if said criteria are not met.