7 ms·
Elliptic Curve Cryptography: a gentle introduction
- valgaze 11y agoIf you want to experiment with the graph try adjusting the a/b parameters here: https://www.desmos.com/calculator/3ugvl6yz4i https://www.desmos.com/calculator/3ugvl6yz4i
- ufo 11y agoNeeds javascript to read... sigh.
- aw3c2 11y agoI was ready to say "well, the animations and formulas need it" but no, those are static images. Meh...
- PhantomGremlin 11y agoNo it doesn't. At least not with Firefox. Just use View --> Page Style --> No Style But as for the other complaint elsewhere in the comments, about light gray text, unfortunately Firefox can't help with that. Normally such misguided text is countered with Preferences --> Content --> Colors --> override ... but in this case the gray is unfortunately in images and not text. And it gets even worse for the light gray text. OS X Accessibility has a setting to "Enhance Contrast". But in this case the gray is closer to white than to black, so all that "enhancing" does is make the text even lighter! Sigh.
- Adlai 11y agoThe interactive tool[1] needs javascript. Don't try graphing secp256k1. [1] https://cdn.rawgit.com/andreacorbellini/ecc/0939921/interactive/modk-add.html https://cdn.rawgit.com/andreacorbellini/ecc/0939921/interact...
- jgrahamc 11y agoFor a slightly less mathematical introduction: https://blog.cloudflare.com/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography/ https://blog.cloudflare.com/a-relatively-easy-to-understand-...
- j2kun 11y agoBut the mathematical ones are the best ones :)
- YAYERKA 11y agoFor a slightly more mathematical introduction: https://www.youtube.com/watch?v=t3JzdKE-Fhs https://www.youtube.com/watch?v=t3JzdKE-Fhs along with accompanying slides http://crypto.biu.ac.il/sites/default/files/3rd_BIU_Winter_School/NigelSmart-BIU2013.pdf http://crypto.biu.ac.il/sites/default/files/3rd_BIU_Winter_S... both from ""3rd BIU Winter School on Cryptography: The basics of elliptic curves - Nigel Smart".
- j2kun 11y agoWhat I didn't say is that I wrote one :) So I don't think I need one.
- ColinWright 11y agoBy my understanding, there's an inaccuracy in that article. It describes a one-way function, but calls it a trapdoor function. I thought that a one-way function is only a trapdoor function if there exists the possibility of reversing it with an extra piece of information. The wikipedia link[0] given seems to confirm that understanding: A trapdoor function is a function that is easy to compute in one direction, yet difficult to compute in the opposite direction (finding its inverse) without special information, called the "trapdoor". I know the article is trying to be informal, but that seems a simple thing to get right, and quite important. If I'm wrong I'd welcome being corrected. [0] http://en.wikipedia.org/wiki/Trapdoor_function http://en.wikipedia.org/wiki/Trapdoor_function
- Retr0spectrum 11y agoWouldn't the "special information" be the private key in this case?
- 11y ago
- aw3c2 11y agoAlso check out https://events.ccc.de/congress/2014/Fahrplan/events/6369.html https://events.ccc.de/congress/2014/Fahrplan/events/6369.htm... Video of the talk: http://media.ccc.de/browse/congress/2014/31c3_-_6369_-_en_-_saal_1_-_201412272145_-_ecchacks_-_djb_-_tanja_lange.html#video http://media.ccc.de/browse/congress/2014/31c3_-_6369_-_en_-_...
- ufo 11y agoReally liked this version. All the time I was wondering when they would transition from the "toy" clock curve that is easy to understand to the complicated y^3 curves that are mentioned in the OP but it turns out that the easy to understand curve was just as good all along and much easier to implement correctly.
- willchang 11y agoThere is no design trend more inimical to the function of the web than gray on white text. If only it stopped at gray values of #444444, which is bad enough on old displays or in bright ambient light. The text on this site is #7f8d8c — more white than black — and the strokes on the letters in the equations are quite fine. Yes, it looks nice and clean to have so little black on the page, but the tradeoff is that I have to squint to read it.
- freework 11y agoI can't help but to point out the irony of a post complaining about grey text, being... in grey text (referring to the downvotes)
- ndesaulniers 11y ago> Those of you who know what public-key cryptography For those of you that don't, might I suggest my: https://nickdesaulniers.github.io/blog/2015/02/22/public-key-crypto-code-example/ https://nickdesaulniers.github.io/blog/2015/02/22/public-key...
- chris_wot 11y agoYou are awesome. Thank you!
- S4M 11y agoIt's not gonna be the most constructive comment, but I would like to thank the author for writing this article and the poster for submitting it. I worked a bit during my undergraduate studies on the Elliptic Curve method to factor products of large prime numbers, and found it interesting, and sometimes wish I could learn more about that.
- tagawa 11y agoFor those who prefer audio/video, this was also covered in Security Now episode 374: http://twit.tv/show/security-now/374 http://twit.tv/show/security-now/374
- tsmarsh 11y agoWhen I was in college there was a distinct worry about elliptic curves vs rsa. My professors were intuitively worried that discrete logs over elliptic curves may well have a simple solution, unlike factorization which has millenia of research proving that it is hard. They were worried enough that I just assumed that GCHQ had already cracked it. Is that still a worry?
- pbsd 11y agoSuch worries have mostly faded by now, though you will see some conservative people still preferring RSA. Keep in mind that the computational study of integer factorization only started seriously in the 70s with CFRAC, making the "milennia" argument somewhat moot. There is a fascinating article by (among others) Neal Koblitz, one of the inventors of elliptic curve cryptography, which describes the history and development of ECC through the 80s, 90s, and 00s, and some of the worries that developed: https://eprint.iacr.org/2008/390 https://eprint.iacr.org/2008/390.
- chris_wot 11y agoCan someone help me out here: I'm a bit rusty on my set builder notation... Is the following correct? The set of natural numbers isn't a group because a group is a set partially defined by { ∀a∃b | a + b = 0 } - or in other words for every element a in the group there exists an element b in the group such that a + b = 0; or to put it yet another way, every element a has an element b that is its arithmetic inverse. As the set of natural numbers are only positive, you can't satisfy this condition.
- haversoe 11y agoA group is a set equipped with a binary operator that obeys a few rules. One of the rules is the existence of inverses. If the operator is addition, then your description is correct. That is, every element x of the underlying set has an additive inverse x^-1 also in the set such that x + x^-1 = 0. Obviously, zero needs to be in the set as well and in some constructions of the natural numbers it is not.
- chris_wot 11y agoThank you!
- master-lincoln 11y agoI don't like how 0 is used as three different symbols in the beginning: the number, the point of infinity and the identity element. I know 0 is a common symbol for each of the three cases respectively but in the same context it feels rather confusing. Is that a common thing to do?
- geogriffin 11y agothe number zero is always defined as being an additive identity element, and in these groups 0 is the point at infinity.
- jordigh 11y agoYes, it's a very common thing to use the same symbol to mean different things in mathematics.