Using Power Operation with Elliptic Curves

8 replies 233 views
omega_2013Senior Member
Posts: 3 · Reputation: 1043
#1Feb 28, 2020, 12:50 AM
hey, quick question, not sure if it's dumb I've got something like this in pure python: d = pow(g, f*(n-2), n) so, g is just an integer generator and I wanna know how to do this with elliptic curves where g is a point instead?
3 Reply Quote Share
stacksatsHero Member
Posts: 145 · Reputation: 2023
#2Feb 28, 2020, 03:12 AM
yeah that’s totally doable just gotta find the right resources on elliptic curve math
3 Reply Quote Share
Posts: 57 · Reputation: 90
#3Feb 28, 2020, 05:52 AM
you mean like this? check out the point multiplication on elliptic curves, it’s pretty straightforward if you look it up
3 Reply Quote Share
omega_2013Senior Member
Posts: 3 · Reputation: 1043
#4Mar 1, 2020, 04:57 PM
let me break it down: let n be the order of the secp256k1 group n = 0xfffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141 our generator G is: G.x = 55066263022277343669578718895168534326250603453777594175500187360389116729240 G.y = 32670510020758816978083085130507043184471273380659243275938904335757337482424 when I calculate: res = G * (n-2) I end up with -2*G but with negative y. And if I plug 2 as DLP: pow(2, n-2, n) gives me 57896044618658097711785492504343953926418782139537452191302581570759080747169
0 Reply Quote Share
Posts: 57 · Reputation: 90
#5Mar 1, 2020, 09:50 PM
the thing is, scalar multiplication on elliptic curves isn’t the same as exponentiation modulo n this is why your results differ.
2 Reply Quote Share
omega_2013Senior Member
Posts: 3 · Reputation: 1043
#6Mar 2, 2020, 08:16 AM
lol ChatGPT sure gets it wrong sometimes i’ve been through so many sources but all I see is exponential in ecdlp rewritten as multiplicative, no clue why.
3 Reply Quote Share
Posts: 57 · Reputation: 90
#7Mar 2, 2020, 01:14 PM
you sure about that? it’s meant to be additive, right? DLP is all about multiplication. thing is, notation can mess you up, trust me.
0 Reply Quote Share
mr_apeNewbie
Posts: 139 · Reputation: 35
#8Mar 2, 2020, 03:06 PM
wait, is "pow" for power? that’s modular exponentiation bigint libraries and ECC should have a ModPow() function, though I’m not sure the best algorithm for N-2.
2 Reply Quote Share
diamondhandsHero Member
Posts: 79 · Reputation: 2112
#9Mar 2, 2020, 09:10 PM
ECDSA and DSA ain’t the same. you got DSA and you wanna shift to ECDSA, but it’s tricky. DSA uses numbers, while ECDSA uses points. which means if you’re only on private keys, it can work out. but on public keys? you can’t just multiply them or raise a generator like that. it's not just repeated multiplication. check my old topic for more on this.
1 Reply Quote Share

Related topics