3 ms·
There is, but it's not a special operation: it's called scalar multiplication and it's just a lot of grouped additions. If you want 13P you do 2P = P + P 4P
by FiloSottile 6y ago
There is, but it's not a special operation: it's called scalar multiplication and it's just a lot of grouped additions.
If you want 13P you do
2P = P + P
4P = 2P + 2P
8P = 4P + 4P
12P = 8P + 4P
13P = 12P + P
To use this for encryption you do a Diffie-Hellman operation, where A and B pick secrets a and b, send each other a x G and b x G, and compute the shared secret a x b x G = b x a x G. (Where G is a standard point.)
You can call "b x G" the public key and do ephemeral-static DH if you are not doing a key exchange between two online peers.
- alecbenzer 6y agoAh ok, so the dot operation is associative I guess? --- I mean, once you have the keys, how do you actually use them to transform data?
- john_alan 6y agoWith elliptic curve crypto you don’t encrypt directly with the private key (just a number) or the public key (just an x,y point). Instead we usually multiply our private key by someone else’s public key to get a point. We take that points x value, hash it and use the output as a symmetric key. The other person can take our public key and multiply it by their private key to get the same point. We end up with something like this: OurPrivate * TheirPub == secret point. (TheirPub is actually equal to TheirPrivateG, thus the secret point is really OurPrivateTheirPrivate*G)
- alecbenzer 6y agoOh, I see, we're just doing Diffie-Hellman but with elliptic curves? Ok, that makes much more sense... it was confusing for the article to compare it with RSA instead of vanilla Diffie-Hellman.
- john_alan 6y agoYup exactly that! “Encryption” with elliptic curves is just ECDH and then using a symmetric cipher like AES. Signature is a little more complicated. It’s not just “encrypting a hash”