IP Library Granted Patent US 8,660,263
Granted Patent B2
US 8,660,263 · App. 13/615,854 · Granted Feb 25, 2014

Power analysis attack countermeasure for the ECDSA

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,660,263
App. No.
13/615,854
Granted
Feb 25, 2014
Kind
B2
Abstract

Execution of the Elliptic Curve Digital Signature Algorithm (ECDSA) requires determination of a signature, which determination involves arithmetic operations. Some of the arithmetic operations employ a long term cryptographic key. It is the execution of these arithmetic operations that can make the execution of the ECDSA vulnerable to a power analysis attack. In particular, an attacker using a power analysis attack may determine the long term cryptographic key. By modifying the sequence of operations involved in the determination of the signature and the inputs to those operations, power analysis attacks may no longer be applied to determine the long term cryptographic key.

Claims (59)

1. A method of publishing a signature related to a message in a manner that counters power analysis attacks, the method based on a private cryptographic key and a base point on a given elliptic curve, said base point having a prime order, said method comprising:

receiving, by a processing device, said message;

obtaining, by the processing device, a hash of said message;

selecting, by the processing device, a first random integer;

obtaining, by the processing device, a non-zero first element of said signature based on said base point and said first random integer;

selecting, by the processing device, a second random integer;

obtaining, by the processing device, a non-zero second element of said signature based on said first random integer, said hash, said first element, said private cryptographic key and said second random integer, wherein said obtaining said second element involves:

determining a first modular multiplication product of said private cryptographic key and said second random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular product of:

said first element; and

a modular inverse of said second random integer; and

publishing, by the processing device, said first element of said signature and said second element of said signature.

2. The method of claim 1 wherein said obtaining said second element comprises evaluating:

s=k −1 [m+ ( d A ω)(ω −1 r )] mod g

wherein

s is said second element;

k is said first random integer;

m is said hash;

d A is said private cryptographic key;

ω is said second random integer;

r is said first element; and

g is said prime order of said base point.

3. The method of claim 1 wherein said obtaining said hash comprises employing a Secure Hash Algorithm referred to as SHA-1.

4. A mobile communication device for publishing a signature related to a message in a manner that counters power analysis attacks, the method based on a private cryptographic key and a base point on a given elliptic curve, said base point having a prime order, said apparatus comprising:

a processor configured to:

receive said message;

obtain a hash of said message;

select a first random integer;

obtain a non-zero first element of said signature based on said base point and said first random integer;

select a second random integer;

obtain a non-zero second element of said signature based on said first random integer, said hash, said first element, said private cryptographic key and said second random integer, by:

determining a first modular multiplication product of said private cryptographic key and said second random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular product of:

said first element; and

a modular inverse of said second random integer; and

publish said first element of said signature and said second element of said signature.

5. A non-transitory computer readable medium containing computer-executable instructions that, when executed on a processor given a private cryptographic key and a base point on a given elliptic curve, said base point having a prime order, cause said processor to:

receive a message;

obtain a hash of said message;

select a first random integer;

obtain a non-zero first element of a signature based on said base point and said first random integer;

select a second random integer;

obtain a non-zero second element of said signature based on said first random integer, said hash, said first element, said private cryptographic key and said second random integer, by:

determining a first modular multiplication product of said private cryptographic key and said second random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular product of:

said first element; and

a modular inverse of said second random integer; and

publish said first element of said signature and said second element of said signature.

6. A method of countering power analysis attacks on an operation to determine a signature related to a message, wherein a private cryptographic key and a base point on a given elliptic curve have been selected, said base point having a prime order, said method comprising:

receiving, by a processing device, said message;

obtaining, by the processing device, a hash of said message;

selecting, by the processing device, a first random integer;

obtaining, by the processing device, a non-zero first element of said signature based on said base point and said first random integer;

selecting, by the processing device, a second random integer; and

obtaining, by the processing device, a non-zero second element of said signature based on said first random integer, said hash, said first element, said private cryptographic key and said second random integer, wherein said obtaining said second element involves:

determining a first modular multiplication product of said private cryptographic key and said second random integer; and

determining a second modular multiplication product of said first modular multiplication product and a modular product of:

said first element; and

a modular inverse of said second random integer.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Jan 1, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 031896/0305 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2012
From: EBEID, NEVINE MAURICE NASSIF
To: RESEARCH IN MOTION LIMITED
Reel/Frame 028961/0686 →