IP Library Granted Patent US 11,128,434
Granted Patent B2
US 11,128,434 · App. 16/539,643 · Granted Sep 21, 2021

Elliptic curve cryptography scheme with simple side-channel attack countermeasure

Inventors: Vladimir Soukharev (Toronto, CA); Basil Hess (Zurich, CH)
Assignee: INFOSEC GLOBAL INC.
H04L9/003H04L9/00H04L9/30H04L9/3066H04L63/00H04L63/0442H04L63/06G06F2211/008H04L2209/08H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,128,434
App. No.
16/539,643
Granted
Sep 21, 2021
Kind
B2
Abstract

There is provided an elliptic curve cryptographic scheme for permitting secure communications between two or more cryptographic correspondent devices, with a simple side-channel attack countermeasure. The cryptographic scheme includes: transforming a point to Jacobian projective coordinates; constant-time scalar multiplication of the point by a parameter; and transforming the resultant of the scalar multiplication to affine coordinates. The scalar multiplication including: performing iteratively to the value of the parameter either one of: doubling of the point and multiplying any two random field elements; or mixed addition of the point.

Claims (28)

1. A method for a simple side-channel attack countermeasure for scalar multiplication of a point by a parameter in an elliptic curve cryptographic scheme, the elliptic curve cryptographic scheme permitting secure communications between two or more cryptographic correspondent devices, each of the cryptographic correspondent devices comprising a processor and a memory, the memory configured to store a plurality of instructions which when executed by the processor cause the processor to implement the cryptographic scheme, the method comprising:

generating a Jacobian projective coordinate representation of the point;

performing iteratively in relation to the value of the parameter, for each iteration, either one of:

if doubling of the point is viable:

doubling of the point to produce a new value for the point; and

performing a dummy operation; or

otherwise, performing mixed addition on the point to produce a new value for the point; and

transforming the point to affine coordinates,

wherein mixed addition on the point comprises performing addition on the value of the point at a particular iteration, in Jacobian projective coordinates, with an original value of the point, in affine coordinates, to produce the new value of the point in Jacobian projective coordinates.

2. The method of claim 1 , wherein the dummy operation has a computational cost of one operation.

3. The method of claim 2 , wherein the dummy operation comprises multiplying two field elements of the elliptic curve.

4. The method of claim 3 , wherein the field elements are any two random field elements.

5. The method of claim 1 , wherein the point is a generator point of the elliptic curve.

6. The method of claim 1 , wherein doubling the point is viable if the value of a corresponding bit of a scalar is zero.

7. A system for implementing an elliptic curve cryptographic scheme on a correspondent device, the elliptic curve cryptographic scheme comprising a countermeasure resistant to a simple side-channel attack, the elliptic curve cryptographic scheme permitting secure communications between two or more cryptographic correspondent devices, each of the cryptographic correspondent devices comprising a processor and a memory, the memory configured to store a plurality of instructions which when executed by the processor cause the processor to implement the cryptographic scheme, the elliptic curve cryptographic scheme comprising scalar multiplication of a point by a parameter, the system comprising:

a representation generation module for generating a Jacobian projective coordinate representation of the point;

a determination module for performing iteratively in relation to the value of the parameter, for each iteration, either one of:

if doubling of the point is viable:

doubling of the point to produce a new value for the point; and

performing a dummy operation; or

otherwise, performing mixed addition on the point to produce a new value for the point; and

a transformation module for transforming the point to affine coordinates,

wherein mixed addition on the point comprises the determination module performing addition on the value of the point at a particular iteration, in Jacobian projective coordinates, with an original value of the point, in affine coordinates, to produce the new value of the point in Jacobian projective coordinates.

8. The system of claim 7 , wherein the dummy operation has a computational cost of one operation.

9. The system of claim 8 , wherein the dummy operation comprises the determination module multiplying two field elements of the elliptic curve.

10. The system of claim 9 , wherein the field elements are any two random field elements.

11. The system of claim 7 , wherein the point is a generator point of the elliptic curve.

12. The system of claim 7 , wherein the determination module determines if doubling the point is viable by determining if the value of a corresponding bit of a scalar is zero.

Assignments (2)
SECURITY INTEREST Recorded Jul 28, 2025
From: INFOSEC GLOBAL INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 071847/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2021
From: SOUKHAREV, VLADIMIR; HESS, BASIL
To: INFOSEC GLOBAL INC.
Reel/Frame 056386/0611 →
Continuity (2)
Continuation PCTCA2017050173 · Feb 13, 2017
Related Publication 20200044817A1 · Feb 6, 2020