IP Library Granted Patent US 10,284,370
Granted Patent B2
US 10,284,370 · App. 14/318,313 · Granted May 7, 2019

Accelerated verification of digital signatures and public keys

Inventors: Marinus Struik (Toronto, CA); Daniel Richard L. Brown (Mississauga, CA); Scott Alexander Vanstone (Campbellville, CA); Robert Philip Gallant (Corner Brook, CA); Adrian Antipa (Brampton, CA); Robert John Lambert (Cambridge, CA)
Assignee: Certicom Corp.
H04L9/3066G06F7/725H04L9/30H04L9/3252
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,370
App. No.
14/318,313
Granted
May 7, 2019
Kind
B2
Abstract

Accelerated computation of combinations of group operations in a finite field is provided by arranging for at least one of the operands to have a relatively small bit length. In a elliptic curve group, verification that a value representative of a point R corresponds the sum of two other points uG and vG is obtained by deriving integers w,z of reduced bit length and that v=w/z. The verification equality R=uG+vQ may then be computed as −zR+(uz mod n)G+wQ=O with z and w of reduced bit length. This is beneficial in digital signature verification where increased verification can be attained.

Claims (25)

1. A method performed by a hardware processor of a computing device, comprising:

receiving, by a receiver of the computing device and through a network, an electronic message including a signature, wherein the electronic message omits a public key of a signer, and the signature comprises a signature on the electronic message M;

receiving, by the receiver of the computing device and through the network, a first elliptic curve point associated with a signature component from the signer, wherein the signature component comprises a first signature component r, the signature includes the first signature component r and a second signature component s, and the first elliptic curve point comprises an elliptic curve point R;

recovering, by the hardware processor of the computing device, the omitted public key of the signer based on the received first elliptic curve point and the received signature, wherein the public key comprises a second elliptic curve point in an elliptic curve group different from the first elliptic curve point, wherein the elliptic curve group includes the first and second elliptic curve points, wherein the second elliptic curve point comprises an elliptic curve point Q, wherein recovering the omitted public key of the signer comprises computing Q=r −1 (sR−eG), wherein G comprises a generator of an elliptic curve group that includes the elliptic curve point R and the elliptic curve point Q, and wherein e is a hash value computed from the electronic message M; and

verifying, by the hardware processor of the computing device, the received signature using the recovered public key which provides an accelerated verification of the received signature.

2. The method of claim 1 , further comprising verifying that the elliptic curve point Q represents the public key of the signer.

3. The method of claim 1 , wherein the elliptic curve point R is generated based on the first signature component r and a cofactor h for an elliptic curve that includes the elliptic curve point R and the elliptic curve point Q.

4. The method of claim 1 , wherein the public key of the signer can be used to verify the signature.

5. The method of claim 4 , wherein verifying the signature comprises verifying the signature according to an Elliptic Curve Digital Signature Algorithm (ECDSA).

6. A non-transitory computer-readable medium storing instructions that, when executed by one or more hardware processors of a computing device, cause the computing device to perform operations comprising:

receiving, by a receiver of the computing device and through a network, an electronic message including a signature, wherein the electronic message omits a public key of a signer, and the signature comprises a signature on the electronic message M;

receiving, by the receiver of the computing device and through the network, a first elliptic curve point associated with a signature component from the signer, wherein the signature component comprises a first signature component r, the signature includes the first signature component r and a second signature component s, and the first elliptic curve point comprises an elliptic curve point R;

recovering, by the one or more hardware processors of the computing device, the omitted public key of the signer based on the received first elliptic curve point and the received signature, wherein the public key comprises a second elliptic curve point in an elliptic curve group different from the first elliptic curve point, wherein the elliptic curve group includes the first and second elliptic curve points, wherein the second elliptic curve point comprises an elliptic curve point Q, wherein recovering the omitted public key of the signer comprises computing Q=r −1 (sR−eG), wherein G comprises a generator of an elliptic curve group that includes the elliptic curve point R and the elliptic curve point Q, and wherein e is a hash value computed from the electronic message M; and

verifying, by the one or more hardware processors of the computing device, the received signature using the recovered public key which provides an accelerated verification of the received signature.

7. The computer-readable medium of claim 6 , the operations further comprising verifying that the elliptic curve point Q represents the public key of the signer.

8. The computer-readable medium of claim 6 , wherein the elliptic curve point R is generated based on the first signature component r and a cofactor h for an elliptic curve that includes the elliptic curve point R and the elliptic curve point Q.

9. The computer-readable medium of claim 6 , wherein the public key of the signer can be used to verify the signature.

10. A computing device comprising:

a receiver configured to receive an electronic message including a signature, wherein the electronic message omits a public key of a signer, and the signature comprises a signature on the electronic message M;

a memory; and

a hardware processor communicatively coupled with the memory and configured to:

receive, from the receiver, a first elliptic curve point associated with a signature component from the signer, wherein the signature component comprises a first signature component r, the signature includes the first signature component r and a second signature component s, and the first elliptic curve point comprises an elliptic curve point R;

recover, by the hardware processor of the computing device, the omitted public key of the signer based on the received first elliptic curve point and the received signature, wherein the public key comprises a second elliptic curve point in an elliptic curve group different from the first elliptic curve point, wherein the elliptic curve group includes the first and second elliptic curve points, wherein the second elliptic curve point comprises an elliptic curve point Q, wherein recovering the omitted public key of the signer comprises computing Q=r −1 (sR−eG), wherein G comprises a generator of an elliptic curve group that includes the elliptic curve point R and the elliptic curve point Q, and wherein e is a hash value computed from the electronic message M; and

verify, by the hardware processor of the computing device, the received signature using the recovered public key which provides an accelerated verification of the received signature.

11. The computing device of claim 10 , wherein the hardware processor is further configured to verify that the elliptic curve point Q represents the public key of the signer.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2014
From: STRUIK, MARINUS; BROWN, DANIEL R.; VANSTONE, SCOTT A.; GALLANT, ROBERT P.; LAMBERT, ROBERT J.; ANTIPA, ADRIAN
To: CERTICOM CORP.
Reel/Frame 033602/0816 →
Continuity (5)
Continuation 13620206 · Sep 14, 2012
Continuation 13478288 · May 23, 2012
Continuation 11333296 · Jan 18, 2006
Provisional Application 60644034 · Jan 18, 2005
Related Publication 20140344579A1 · Nov 20, 2014