Elliptic Curve Cryptography: a gentle introduction
andrea.corbellini.name
andrea.corbellini.name
A trapdoor function is a function that is easy
to compute in one direction, yet difficult to
compute in the opposite direction (finding its
inverse) without special information, called the
"trapdoor".
I know the article is trying to be informal, but that seems a simple thing to get right, and quite important. If I'm wrong I'd welcome being corrected. Choose p, q, and let n=pq
Note: phi(n) = (p-1)(q-1)
Choose e
Compute d such that de = 1 (mod phi(n))
The number d is your private key.
Given a message M, E(M) = M^e (mod n)
Given an encrypted message E, D = E^d (mod n).
Magically, D=M.
Now multiplying the numbers p and q is a one-way function, because there is no effective way to factor n (if p and q are chosen suitably.) The exponentiation M^e is a trap-door function because normally you can't undo it, but with any of the extra knowledge p, q, or d, then you can undo it.There are nuances, and time and time again I meet people who think lots of things are the same when in fact they are different, and the differences matter.
A one-way function is not necessarily a trap-door function.
In this case many things are equivalent in the sense that one can easily be computed given another, but the details actually matter.
The point, though, is that there are on-way functions that do not have trap-doors and hence are not trap-door functions. The definition as given in the blog post seems to conflate the two, when in fact the difference is important. PKCs are often made by starting with a provably one-way function and trying to find a way of inserting a trap-door without weakening it.
(Sorry if this is a little incoherent, it's late here, and I need to do some stuff before going to bed, and I have an early start tomorrow.)
- The first 128 bits of SHA2(n). It should be computationally infeasible to find n from the output.
- AES128(n, k). It should be computationally infeasible to find n from the output, unless you know k.
Discrete log: for f(x) = y
- Easy: given f and x find y.
- Hard: given f and y find x.
Trapdoor: for f(x) = y
- Easy: given f and y find x, given a secret, e.g. (p-1)(q-1) in RSA.
- Hard: given f and y find x, without possesion of the secret.
Is that accurate, or have I misstated the essential difference somehow?I'm sure you knew this already, but for completeness, another property of the trapdoor function is:
- Easy: given f and x find y. Easy: given int n, point P -> compute Q = nP
Hard: given points P, Q (known to be nP for some n) -> compute n
This said, similarly as RSA vs factorization, DHP vs DLP (and other problems) are only assumed to be equivalent, meaning that one could find an easy way to break DH without computing the DLP.Furthermore, for most groups the DHP is polynomially equivalent to the DLP. The requirement for this to be true is that there exists an elliptic curve with smooth order modulo the Diffie-Hellman group's order. Such smooth-order curves are hard to actually find for large groups, exponentially so (this is a fine example of the chasm between uniform and nonuniform reductions); but for elliptic curves groups used in practice, it is possible to find them. In other words, an easy way to break the DHP in smallish elliptic curve groups would lead to ECDLP solving with only polynomial overhead.
>1.12 Definition
>A function f from a set X to a set Y is called a one-way function if f(x) is “easy” to compute for all x \in X but for “essentially all” elements y \in Im(f) it is “computationally infeasible” to find any x \in X such that f(x) = y. [0]
>1.16 Definition
>A trapdoor one-way function is a one-way function f : X -> Y with the additional property that given some extra information (called the trapdoor information) it becomes feasible to find for any given y \in Im(f), an x \in X such that f(x) = y. [0]
[0]; Menezes, A.; Oorschot, P. van; Vanstone, S. (2001). Handbook of Applied Cryptography (5th ed.). CRC Press.
James D'Angelo has some good videos that go into some of the detail too
In the billards example it's stated that for a given player starting at point A:
"It is easy for him to hit the ball over and over following the rules described above."
arriving at some point B after some number of hits N. However, regarding some other player who knows point A and B
"they cannot determine the number of times the ball was struck to get there without running through the whole game again"
The question of course, is "Why not? Why can't the second player just start at point A and keep hitting the ball until it gets to point B, and count the hits?
The answer is that the first player does not run through the the sequence one hit at a time! Knowing N, you can take a mathematical shortcut from A to B. The simplest of these is known as "double and add" for elliptic curves. This is similar to the "square and multiply" method for fast exponentiation. The shortcut is the critical advantage, because it's the enormous computational complexity of running through the entire game without the shortcut that is the basis of ECC's security.
Video of the talk: http://media.ccc.de/browse/congress/2014/31c3_-_6369_-_en_-_...
For those of you that don't, might I suggest my: https://nickdesaulniers.github.io/blog/2015/02/22/public-key...
The set of natural numbers isn't a group because a group is a set partially defined by { ∀a∃b | a + b = 0 } - or in other words for every element a in the group there exists an element b in the group such that a + b = 0; or to put it yet another way, every element a has an element b that is its arithmetic inverse. As the set of natural numbers are only positive, you can't satisfy this condition.
View --> Page Style --> No Style
But as for the other complaint elsewhere in the comments, about light gray text, unfortunately Firefox can't help with that. Normally such misguided text is countered with Preferences --> Content --> Colors --> override ...
but in this case the gray is unfortunately in images and not text.And it gets even worse for the light gray text. OS X Accessibility has a setting to "Enhance Contrast". But in this case the gray is closer to white than to black, so all that "enhancing" does is make the text even lighter!
Sigh.
[1] https://cdn.rawgit.com/andreacorbellini/ecc/0939921/interact...
There is a fascinating article by (among others) Neal Koblitz, one of the inventors of elliptic curve cryptography, which describes the history and development of ECC through the 80s, 90s, and 00s, and some of the worries that developed: https://eprint.iacr.org/2008/390.