Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Curve448

From Wikipedia, the free encyclopedia
Elliptic curve used in Internet cryptography

Incryptography,Curve448 orCurve448-Goldilocks is anelliptic curve potentially offering 224 bits of security and designed for use with theelliptic-curve Diffie–Hellman (ECDH) key agreement scheme.

History

[edit]

Developed by Mike Hamburg ofRambus Cryptography Research, Curve448 allows fast performance compared with other proposed curves with comparable security.[1] Thereference implementation is available under anMIT license.[2] The curve was favored by theInternet Research Task Force Crypto Forum Research Group (IRTF CFRG) for inclusion inTransport Layer Security (TLS) standards along withCurve25519.

In 2017, NIST announced that Curve25519 and Curve448 would be added to "Special Publication 800-186", which specifies approvedelliptic curves for use by theUS Federal Government,[3] and in 2023 it was approved for use in FIPS 186-5.[4] Both are described inRFC 7748. The nameX448 is used for the DH function. X448 support was added toOpenSSL in version 1.1.1 (released on 11 September 2018).[5]

Mathematical properties

[edit]

Hamburg chose theSolinas trinomial prime basep = 2448 − 2224 − 1, calling it a "Goldilocks" prime "because its form defines the golden ratioφ ≡ 2224". The main advantage of agolden-ratio prime is fastKaratsuba multiplication.[6]

The curve Hamburg used is an untwistedEdwards curveEd:y2 +x2 = 1 − 39081x2y2. The constantd = −39081 was chosen as the smallest absolute value that had the required mathematical properties, thus anothing-up-my-sleeve number.

Curve448 is constructed such that it avoids many potentialimplementation pitfalls.[7]

See also

[edit]

References

[edit]
  1. ^Hamburg, Mike (2015)."Ed448-Goldilocks, a new elliptic curve".Cryptology ePrint Archive.
  2. ^"SourceForge.net: Ed448-Goldilocks".ed448goldilocks.sourceforge.net.
  3. ^"Transition Plans for Key Establishment Schemes". 31 October 2017. Archived fromthe original on 11 March 2018. Retrieved23 February 2018.
  4. ^Moody, Dustin (2023-02-03).FIPS 186-5: Digital Signature Standard (DSS) (Report).NIST.doi:10.6028/NIST.FIPS.186-5.S2CID 256480883. Retrieved2023-03-04.
  5. ^OpenSSL Foundation (2023-09-11)."/news/openssl-1.1.1-notes.html".openssl.org. Retrieved2024-01-11.
  6. ^Sasdrich, Pascal; Géneysu, Tim (2017).Cryptography for next generation TLS: Implementing the RFC 7748 elliptic Curve448 cryptosystem in hardware. 2017 54th ACM/EDAC/IEEE Design Automation Conference (DAC).doi:10.1145/3061639.3062222.
  7. ^"SafeCurves: Introduction".safecurves.cr.yp.to. Retrieved2018-02-23.
Algorithms
Integer factorization
Discrete logarithm
Lattice/SVP/CVP/LWE/SIS
Others
Theory
Standardization
Topics
Retrieved from "https://en.wikipedia.org/w/index.php?title=Curve448&oldid=1200445553"
Category:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp