Fault attacks on hyperelliptic curve discrete logarithm problem over binary field
In this paper, we present invalid-curve attacks that apply to the hyperelliptic curve scalar multi- plication (HECSM) algorithm proposed by Avanzi et al. on the genus 2 hyperelliptic curve over binary field. We observe some new properties of the HECSM. Our attacks are based on these new properties a...
Gespeichert in:
Veröffentlicht in: | Science China. Information sciences 2014-02, Vol.57 (3), p.182-198 |
---|---|
Hauptverfasser: | , , |
Format: | Artikel |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | In this paper, we present invalid-curve attacks that apply to the hyperelliptic curve scalar multi- plication (HECSM) algorithm proposed by Avanzi et al. on the genus 2 hyperelliptic curve over binary field. We observe some new properties of the HECSM. Our attacks are based on these new properties and the obser- vation that the parameters f0 and fl of the hyperelliptic curve equation are not utilized for the HECSM. We show that with different "values" for curve parameters f0, fl, there exsit cryptographically weak groups in the Koblitz hyperelliptic curve. Also, we compute the theoretical probability of getting a weak Jacobian group of hyperelliptic curve whose cardinality is an smooth integer. |
---|---|
ISSN: | 1674-733X 1869-1919 |
DOI: | 10.1007/s11432-013-5048-6 |