Skipping p-values in secp160k1 what's up with that?

5 replies 345 views
alex.byteLegendary
Posts: 78 · Reputation: 5910
#1Apr 30, 2023, 02:38 PM
So I was digging into how we generate curves like secp160k1, secp192k1, secp224k1, and secp256k1. We start with "2^n-2^32" and then go down the p-value list until we find a prime. For secp192k1, secp224k1, and secp256k1, we grab the first match. But with secp160k1, the p-value we used is actually the fifth one down. Why did we skip the first four? They all had some matching b-value with a prime n.
3 Reply Quote Share
Posts: 48 · Reputation: 19
#2Apr 30, 2023, 04:12 PM
Yeah, I noticed that too. For secp192k1, secp224k1, and secp256k1, we pick the first valid p-value, so it's weird to see secp160k1 doing something different. It raises questions about the selection process. Also, why b=5 for secp224k1? Wouldn’t b=2 also work?
4 Reply Quote Share
stacksatsHero Member
Posts: 168 · Reputation: 2023
#3Apr 30, 2023, 07:42 PM
Good point about the primitive root of unity. It’s essential for making endomorphisms efficient. So that has to be factored into how we choose the p-values for these curves.
4 Reply Quote Share
Posts: 48 · Reputation: 19
#4May 1, 2023, 01:30 AM
What’s a primitive root, though? I’m kinda lost on that part.
0 Reply Quote Share
alex.byteLegendary
Posts: 78 · Reputation: 5910
#5May 1, 2023, 06:39 AM
Primitive roots can generate vulnerable subgroups, which is a big deal. They can potentially break a 256-bit key super fast. There's more info on GitHub about this, but I’d take it with a grain of salt since some of it looks sketchy.
3 Reply Quote Share
eric_gasFull Member
Posts: 2 · Reputation: 774
#6May 1, 2023, 10:07 AM
That’s just misinformation. Secp256k1 is prime ordered, meaning no subgroups exist. All keys are equivalent, so it's not as vulnerable as you think.
1 Reply Quote Share

Related topics