IP Library Granted Patent US 8,331,557
Granted Patent B2
US 8,331,557 · App. 13/222,104 · Granted Dec 11, 2012

Power analysis attack countermeasure for the ECDSA

Assignee: Research In Motion Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,331,557
App. No.
13/222,104
Granted
Dec 11, 2012
Kind
B2
Abstract

Execution of the Elliptic Curve Digital Signature Algorithm (ECDSA) requires determination of a signature, which determination involves arithmetic operations. Some of the arithmetic operations employ a long term cryptographic key. It is the execution of these arithmetic operations that can make the execution of the ECDSA vulnerable to a power analysis attack. In particular, an attacker using a power analysis attack may determine the long term cryptographic key. By modifying the sequence of operations involved in the determination of the signature and the inputs to those operations, power analysis attacks may no longer be applied to determine the long term cryptographic key.

Claims (38)

1. A method of publishing a signature related to a message in a manner that counters power analysis attacks, wherein a private cryptographic key and a base point on a given elliptic curve have been selected, said base point having a prime order, said method comprising:

receiving, by a processing device, said message;

obtaining, by the processing device, a hash of said message;

selecting, by the processing device, a random integer;

obtaining, by the processing device, a non-zero first element of said signature based on said base point and said random integer;

obtaining, by the processing device, a non-zero second element of said signature based on said random integer, said hash, said first element, said private cryptographic key and a modular inverse of said random integer, wherein said obtaining said second element involves:

determining a first modular multiplication product of said private cryptographic key and said modular inverse of said random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular multiple of said first element; and

publishing, by the processing device, said first element of said signature and said second element of said signature.

2. The method of claim 1 , wherein said modular multiple of said first element is said first element.

3. The method of claim 2 wherein said obtaining said second element evaluating:

s =[k −1 m+(k −1 d A ) r]mod g

wherein

s is said second element;

k is said random integer;

m is said hash;

d A is said private cryptographic key;

r is said first element; and

g is said prime order of said base point.

4. A mobile communication device for publishing a signature related to a message in a manner that counters power analysis attacks, wherein a private cryptographic key and a base point on a given elliptic curve have been selected, said base point having a prime order, said apparatus comprising:

a processor configured to:

receive said message;

obtain a hash of said message;

select a random integer;

obtain a non-zero first element of said signature based on said base point and said random integer;

obtain a non-zero second element of said signature based on said random integer, said hash, said first element, said private cryptographic key and a modular inverse of said random integer, by:

determining a first modular multiplication product of said private cryptographic key and said modular inverse of said random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular multiple of said first element; and

publish said first element of said signature and said second element of said signature.

5. A non-transitory computer readable medium containing computer-executable instructions that, when executed on a processor given a private cryptographic key and a base point on a given elliptic curve, said base point having a prime order, cause said processor to:

receive a message;

obtain a hash of said message;

select a random integer;

obtain a non-zero first element of a signature based on said base point and said random integer;

obtain a non-zero second element of said signature based on said random integer, said hash, said first element, said private cryptographic key and a modular inverse of said random integer, by:

determining a first modular multiplication product of said private cryptographic key and said modular inverse of said random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular multiple of said first element; and

publish said first element of said signature and said second element of said signature.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Feb 23, 2016
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 037893/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2011
From: EBEID, NEVINE MAURICE NASSIF
To: RESEARCH IN MOTION LIMITED
Reel/Frame 026835/0004 →
Continuity (3)
Continuation 12040196 · Feb 29, 2008
Provisional Application 60893522 · Mar 7, 2007
Related Publication 20110314292A1 · Dec 22, 2011