3 ms·
> ElGamal/DSA is fragile and difficult to implement securely in a way that doesn't reveal secret k. ECC (and somewhat particularly NIST curves[1]) is also very
by less_less 3y ago
> ElGamal/DSA is fragile and difficult to implement securely in a way that doesn't reveal secret k. ECC (and somewhat particularly NIST curves[1]) is also very difficult to implement securely from side channel attacks[2].
IMHO this isn't evidence of a backdoor. Side-channel protection is hard. RSA decryption and especially keygen are also tricky to implement in a side-channel-protected way, and a widespread timing attack on RSA decryption in many libraries was published earlier this year [3].
The NIST p-curves used the state-of-the-art elliptic curve shape for general operations when they were released: short Weierstrass curves over prime fields. Edwards curves are easier to defend against side channels and are overall a better choice (with their own rough edges, mostly involving the cofactor), but those were not known until 2007. Montgomery curves (similar rough edges to Edwards, plus the point at infinity) were known earlier and are nice for key exchange, but they are not as nice for signatures.
Overall I would not choose the NIST curves for a new design today, because Edwards/Montgomery curves are a better choice. But I think the evidence they were backdoored (mathematically or otherwise) is weak.
[3] https://people.redhat.com/~hkario/marvin https://people.redhat.com/~hkario/marvin
- Ar-Curunir 3y agoThere are now fairly efficient complete formulae for prime-order curves, so the case for the NIST curves is stronger.