Understanding ECDSA Roots and Multiplications

6 replies 54 views
alex.byteLegendary
Posts: 78 · Reputation: 5910
#1Nov 5, 2023, 03:44 AM
What’s up with these clock-like values? Can we find more of them? Also, can we hit values like 2 or 3 in five or seven moves? I’m curious if we can apply this to that big number n=fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141 and get something from p=fffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2f.
6 Reply Quote Share
0xNodeMember
Posts: 307 · Reputation: 80
#2Nov 6, 2023, 04:54 AM
I think it’s because N squared equals 1. So, we can reach N in just 6 multiplications using this value E. Also, E to the power of 4 equals E squared minus 1. Not sure what to do with that, but E squared should be the square root of E squared minus 1. Anyone know how to find a square root in this group?
4 Reply Quote Share
diamondhandsHero Member
Posts: 98 · Reputation: 2112
#3Nov 6, 2023, 05:03 AM
Good point about divisibility. Since n-1=fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364140 is divisible by 12, it makes sense. If you can divide n-1 by a number and get zero, then it’s game on. But (n-1)%5 gives 1 and (n-1)%7 gives 2, so that doesn’t work. Yeah, you can do it, but not for 12. 14 seems better.
2 Reply Quote Share
Posts: 10 · Reputation: 185
#4Nov 6, 2023, 11:14 AM
There are tons of values like this. What you want is a primitive root modulo n. You can derive all roots of 1 from it. If you’re looking for a primitive root for prime p, you can use a simple algorithm. For instance, modulo p gives roots like 2, 3, 7, and so on. There are 31 possible roots when you consider multiples.
4 Reply Quote Share
Posts: 11 · Reputation: 209
#5Nov 8, 2023, 12:01 AM
I found something cool! When you double a point like this: Q = P * 2^155555555555555555555555555555553a393d1339460d5a4ffc328bbc04857, you still get the same Y value but a different X. Qx isn’t equal to Px. Just wanted to share, even though this thread is old.
1 Reply Quote Share
Posts: 11 · Reputation: 209
#6Nov 8, 2023, 01:29 AM
I used some code for this test. Started with 0x10 * G and after running it, I got 0xc9c52b33fa3cf1f5ad9e3fd77ed9ba573d36fec6139d59d88ec4cf8b2f09b056 * G. Not sure if it's right but I tried a lot of points.
3 Reply Quote Share
falcon2019Full Member
Posts: 50 · Reputation: 425
#7Nov 9, 2023, 06:59 AM
So, I checked pow(2, T, n) and got this result: 0xac9c52b33fa3cf1f5ad9e3fd77ed9ba4a880b9fc8ec739c2e0cfc810b51283ce. It’s one of the endomorphism constants for secp256k1's scalar domain. When you multiply any point by this value, Y stays the same in affine coords. How’d you get T though? Oh wait, I see it now. Still a bit surprising!
1 Reply Quote Share

Related topics