IP Library Granted Patent US 8,806,197
Granted Patent B2
US 8,806,197 · App. 13/478,288 · Granted Aug 12, 2014

Accelerated verification of digital signatures and public keys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,806,197
App. No.
13/478,288
Granted
Aug 12, 2014
Kind
B2
Abstract

Accelerated computation of combinations of group operations in a finite field is provided by arranging for at least one of the operands to have a relatively small bit length. In a elliptic curve group, verification that a value representative of a point R corresponds the sum of two other points uG and vG is obtained by deriving integers w,z of reduced bit length and so that v=w/z. The verification equality R=uG+vQ may then be computed as −zR+(uz mod n) G+wQ=O with z and w of reduced bit length. This is beneficial in digital signature verification where increased verification can be attained.

Claims (37)

1. A method of generating a digital signature of a message, the method comprising:

by operation of a cryptographic module comprising one or more processors, generating a digital signature comprising a first signature component and a second signature component, said first signature component based on a first coordinate of an elliptic curve point representing an ephemeral public key; and

generating, for use with said digital signature, an indicator to identify which value of a plurality of values recoverable from said first signature component is said ephemeral public key.

2. The method according to claim 1 , wherein said indicator is a predetermined bit of a second coordinate of said elliptic curve point.

3. The method of claim 2 wherein said predetermined bit is generated by calculating y mod 2, and y is said second coordinate.

4. The method of claim 1 , wherein said indicator is based on a second coordinate of said elliptic curve point.

5. The method of claim 1 , wherein said indicator allows determination of said first coordinate of said elliptic curve point from said first signature component.

6. The method of claim 1 , wherein said indicator comprises said first coordinate of said elliptic curve point.

7. The method of claim 1 , wherein said indicator comprises said elliptic curve point.

8. The method of claim 1 , further comprising transmitting said second signature component and said indicator to a device configured to verify said digital signature.

9. The method of claim 8 , further comprising transmitting said first signature component to said device configured to verify said digital signature.

10. The method of claim 1 wherein said second signature component is derived from said first signature component, a private key associated with said cryptographic module, and an ephemeral private key associated with said cryptographic module, said ephemeral private key corresponding to said ephemeral public key.

11. The method of claim 10 wherein said second signature component is of the form s=k −1 (h(m)+dr) mod n, wherein n is an order of a generator point, h(m) is a hash of said message, d is said private key, k is said ephemeral private key, and r is said first signature component.

12. A cryptographic module operable to generate a digital signature of a message, the cryptographic module comprising one or more processors configured to:

generate a digital signature comprising a first signature component and a second signature component, said first signature component based on a first coordinate of an elliptic curve point representing an ephemeral public key; and

generate, for use with said digital signature, an indicator to identify which value of a plurality of values recoverable from said first signature component is said ephemeral public key.

13. The cryptographic module of claim 12 , wherein said indicator is based on a second coordinate of said elliptic curve point.

14. The cryptographic module of claim 13 , wherein said indicator is a predetermined bit of said second coordinate.

15. The cryptographic module of claim 12 , wherein said indicator allows determination of said first coordinate of said elliptic curve point from said first signature component.

16. The cryptographic module of claim 12 , wherein said indicator comprises said first coordinate of said elliptic curve point.

17. The cryptographic module of claim 12 , wherein said indicator comprises said elliptic curve point.

18. The cryptographic module of claim 12 , further comprising transmitting said second signature component and said indicator to a device configured to verify said digital signature.

19. The cryptographic module of claim 18 , further comprising transmitting said first signature component to said device configured to verify said digital signature.

20. The cryptographic module of claim 12 , wherein said second signature component is derived from said first signature component, a private key associated with said cryptographic module, and an ephemeral private key associated with said cryptographic module, said ephemeral private key corresponding to said ephemeral public key.

21. The cryptographic module of claim 20 , wherein said second signature component is of the form s=k −1 (h(m)+dr) mod n, wherein n is an order of a generator point, h(m) is a hash of said message, d is said private key, k is said ephemeral private key, and r is said first signature component.

22. A non-transitory computer readable medium storing instructions operable when executed by data processing apparatus to perform operations for generating a digital signature of a message, the operations comprising:

generating a digital signature comprising a first signature component and a second signature component, said first signature component based on a first coordinate of an elliptic curve point representing an ephemeral public key; and

generating, for use with said digital signature, an indicator to identify which value of a plurality of values recoverable from said first signature component is said ephemeral public key.

23. The computer-readable medium of claim 22 , wherein said indicator is based on a second coordinate of said elliptic curve point.

24. The computer-readable medium of claim 23 , wherein said indicator is a predetermined bit of said second coordinate.

25. The computer-readable medium of claim 22 , wherein said indicator allows determination of said first coordinate of said elliptic curve point from said first signature component.

26. The computer-readable medium of claim 22 , wherein said indicator comprises said first coordinate of said elliptic curve point.

27. The computer-readable medium of claim 22 , wherein said indicator comprises said elliptic curve point.

28. The computer-readable medium of claim 22 , further comprising transmitting said second signature component and said indicator to a device configured to verify said digital signature.

29. The computer-readable medium of claim 28 , further comprising transmitting said first signature component to said device configured to verify said digital signature.

30. The computer-readable medium of claim 22 , wherein said second signature component is derived from said first signature component, a private key associated with a cryptographic module, and an ephemeral private key associated with said cryptographic module, said ephemeral private key corresponding to said ephemeral public key.

31. The computer-readable medium of claim 30 , wherein said second signature component is of the form s=k −1 (h(m)+dr) mod n, wherein n is an order of a generator point, h(m) is a hash of said message, d is said private key, k is said ephemeral private key, and r is said first signature component.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2013
From: STRUIK, MARINUS; BROWN, DANIEL R.; VANSTONE, SCOTT A.; GALLANT, ROBERT P.; LAMBERT, ROBERT J.; ANTIPA, ADRIAN
To: CERTICOM CORP.
Reel/Frame 030632/0126 →