Sciweavers

PKC
2016
Springer

Degenerate Curve Attacks - Extending Invalid Curve Attacks to Edwards Curves and Other Models

8 years 8 months ago
Degenerate Curve Attacks - Extending Invalid Curve Attacks to Edwards Curves and Other Models
Abstract Invalid curve attacks are a well-known class of attacks against implementations of elliptic curve cryptosystems, in which an adversary tricks the cryptographic device into carrying out scalar multiplication not on the expected secure curve, but on some other, weaker elliptic curve of his choosing. In their original form, however, these attacks only affect elliptic curve implementations using addition and doubling formulas that are independent of at least one of the curve parameters. This property is typically satisfied for elliptic curves in Weierstrass form but not for newer models that have gained increasing popularity in recent years, like Edwards and twisted Edwards curves. It has therefore been suggested (e.g. in the original paper on invalid curve attacks) that such alternate models could protect against those attacks. In this paper, we dispel that belief and present the first attack of this nature against (twisted) Edwards curves, Jacobi quartics, Jacobi intersections...
Samuel Neves, Mehdi Tibouchi
Added 08 Apr 2016
Updated 08 Apr 2016
Type Journal
Year 2016
Where PKC
Authors Samuel Neves, Mehdi Tibouchi
Comments (0)