{"id":355,"date":"2018-04-18T17:05:45","date_gmt":"2018-04-18T08:05:45","guid":{"rendered":"http:\/\/tamatoyaku.com\/b\/?p=355"},"modified":"2018-04-18T17:05:45","modified_gmt":"2018-04-18T08:05:45","slug":"355","status":"publish","type":"post","link":"https:\/\/p-0.me\/b\/p\/355\/","title":{"rendered":"PARI GP\u306b\u3088\u308bECDSA\u306e\u5b9f\u88c5"},"content":{"rendered":"<p>[mathjax]\u4eca\u56de\u306fPARI GP\u3092\u7528\u3044\u3066ECDSA\u3092\u5b9f\u88c5\u3059\u308b\uff0e<br \/>\n<!--more--><br \/>\n\u6700\u521d\u306b\u74b0\u5883\u69cb\u7bc9\u3068\u3057\u3066\uff0c<a href=\"https:\/\/pari.math.u-bordeaux.fr\/\">\u516c\u5f0f\u30b5\u30a4\u30c8<\/a>\u304b\u3089zip\u3092\u843d\u3068\u3057\u3066\u5c55\u958b\u3059\u308b\uff0e\u306a\u304a\uff0c\u3053\u306e\u3068\u304d\u306bC\u30c9\u30e9\u30a4\u30d6\u76f4\u4e0b\u306a\u3069\u6a29\u9650\u304c\u5fc5\u8981\u306a\u5834\u6240\u3067\u306f\u3046\u307e\u304f\u3044\u304b\u306a\u3044\u3053\u3068\u304c\u3042\u308b\u305f\u3081\uff0c\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u306a\u3069\u306b\u5c55\u958b\u3059\u308b\uff0e\u5c55\u958b\u3059\u308b\u3068gp.exe\u304c\u3042\u308a\uff0c\u3053\u308c\u3092\u8d77\u52d5\u3059\u308b\u3068PARI GP\u7528\u306e\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u304c\u7acb\u3061\u4e0a\u304c\u308b\uff0e\u4eca\u56de\u306fgp.exe\u3068\u540c\u3058\u30d5\u30a9\u30eb\u30c0\u306becdsa.gp\u3068\u3057\u3066\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u3092\u66f8\u304d\uff0c\u5b9f\u884c\u3059\u308b\uff0e<br \/>\nGP\u30d5\u30a1\u30a4\u30eb\u306f{}\u3067\u56f2\u307e\u308c\u305f\u90e8\u5206\u3092\uff0cC\u8a00\u8a9e\u306b\u304a\u3051\u308bmain\u95a2\u6570\u306e\u3088\u3046\u306b\u5b9f\u884c\u3059\u308b\uff0e\u4eca\u56de\u306f\u95a2\u6570\u3092\u6a19\u6e96\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u3082\u306e\u3060\u3051\u3067\u5b9f\u88c5\u3059\u308b\u306e\u3067\uff0c\u95a2\u6570\u306e\u4f5c\u6210\u306f\u884c\u308f\u305a{}\u306e\u4e2d\u306b\u30b3\u30fc\u30c9\u3092\u8a18\u8ff0\u3057\u3066\u3044\u304f\uff0eECDSA\u306e\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u306b\u3064\u3044\u3066\u306f\uff0c<a href=\"https:\/\/researchmap.jp\/mulzrkzae-42427\/\">\u3053\u306e\u30da\u30fc\u30b8<\/a>\u306e<a href=\"https:\/\/researchmap.jp\/mulzrkzae-42427\/?action=multidatabase_action_main_filedownload&amp;download_flag=1&amp;upload_id=50351&amp;metadata_id=24198\">\u6955\u5186\u66f2\u7dda\u6697\u53f7\u5165\u9580<\/a>\u306ep.56\u306b\u8a18\u8f09\u3055\u308c\u3066\u3044\u308b\u3082\u306e\u3092\u53c2\u8003\u306b\u3059\u308b\uff0e\u306a\u304a\uff0c\u4eca\u56de\u4f8b\u3068\u3057\u3066\u4f7f\u7528\u3059\u308b\u30d1\u30e9\u30e1\u30fc\u30bf\u306f\\(a=84,b=12,p=251\\)\u3068\u3059\u308b\uff0e\u3064\u307e\u308a\\(F_{251}\\)\u4e0a\u3067\u306e\\(y^2=x^3+84x+12\\)\u3068\u306a\u308b\uff0e<br \/>\n\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3092\u6e96\u5099\u30fb\u9375\u751f\u6210\u30fb\u7f72\u540d\u751f\u6210\u30fb\u7f72\u540d\u691c\u8a3c\u30fb\u7d50\u679c\u8868\u793a\u306e5\u6bb5\u968e\u306b\u5206\u3051\u3066\uff11\u3064\u305a\u3064\u8a18\u8ff0\u3057\u3066\u3044\u304f\uff0e<br \/>\n&nbsp;<br \/>\n<strong>1.\u6e96\u5099<\/strong><br \/>\n\u6700\u521d\u306b\u6955\u5186\u66f2\u7dda\u3092\u751f\u6210\u3059\u308b\uff0ePARI GP\u3067\u306f\u6955\u5186\u66f2\u7dda\u3092ellinit\u95a2\u6570\u3092\u7528\u3044\u3066\u3064\u304f\u308b\uff0e\u306a\u304a\uff0cellinit\u306e\u4e2d\u306e\u884c\u5217\u306fWeierstrass\u6a19\u6e96\u5f62\u306e\\(a_1,a_2,a_3,a_4,a_6\\)\u306b\u5bfe\u5fdc\u3057\u3066\u304a\u308a\uff0c\u30b3\u30fc\u30c9\u4e2d\u306e\\(p\\)\u306f\u6709\u9650\u4f53\\(F_p\\)\u306e\\(p\\)\u3092\u8868\u3059\uff0e\u30d9\u30fc\u30b9\u30dd\u30a4\u30f3\u30c8\\(P\\)\u306b\u95a2\u3057\u3066\u306f\\((183, 12)\\)\u3068\u3059\u308b\uff0e\u307e\u305f\uff0c\u70b9\u4f4d\u6570\\(l\\)\u304c\u5fc5\u8981\u306a\u306e\u3067\u8a08\u7b97\u3057\u3066\u304a\u304f\uff0e\u70b9\u4f4d\u6570\\(l\\)\u306f\\(lP=O\\)\u3092\u6e80\u305f\u3059\u5de8\u5927\u306a\u7d20\u6570\u3067\u3042\u308b\uff0e<br \/>\n&nbsp;<\/p>\n<pre class=\"lang:default decode:true\">a=84;b=12;p=251;\ne=ellinit([0,0,0,a,b],p);\nP=[Mod(183, p), Mod(12, p)];\nl=ellorder(e,P);<\/pre>\n<p>&nbsp;<br \/>\n<strong>2.\u9375\u751f\u6210<\/strong><br \/>\n\u4e71\u6570\\(d_B\\)\u3092\u751f\u6210\u3057\uff0c\\(P_B=d_B\\times P\\)\u3092\u8a08\u7b97\u3059\u308b\uff0e\\(d_B\\)\u304c\u79d8\u5bc6\u9375\u3068\u306a\u308a\uff0c\\(P_B\\)\u304c\u516c\u958b\u9375\u3068\u306a\u308b\uff0e\u4e71\u6570\\(d_B\\)\u306b\u95a2\u3057\u3066\u306f\uff0c0\u30681\u304c\u90fd\u5408\u304c\u60aa\u3044\u305f\u3081\u9664\u5916\u3059\u308b\u3088\u3046\u306b\u3057\u3066\u3044\u308b\uff0e\u30b9\u30ab\u30e9\u30fc\u500d\u306fellmul\u95a2\u6570\u3092\u7528\u3044\u308b\uff0e<\/p>\n<pre class=\"lang:default decode:true\">d_B=random(l-2)+2;\nP_B=ellmul(e,P,d_B);\n<\/pre>\n<p>&nbsp;<br \/>\n<strong>3.\u7f72\u540d\u751f\u6210<\/strong><br \/>\n\u4e71\u6570r\u30921\u304b\u3089l\u307e\u3067\u306e\u7bc4\u56f2\u3067\u751f\u6210\u3057\uff0c\\(U=r\\times P\\)\u3092\u8a08\u7b97\u3057\u3066\u3044\u308b\uff0e\u307e\u305f\uff0c\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u30cf\u30c3\u30b7\u30e5\u5316\u3057\u3066\u56fa\u5b9a\u9577\u306b\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u304c\uff0c\u3053\u3053\u3067\u306f\u7c21\u7565\u5316\u306e\u305f\u3081\u4e71\u6570m\u3092\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u30cf\u30c3\u30b7\u30e5\u5316\u3057\u305f\u3082\u306e\u3068\u307f\u306a\u3059\uff0e\\(u\\)\u306b\u306f\u70b9\\(U\\)\u306e\\(x\\)\u5ea7\u6a19\u3092\\(mod\\ l\\)\u3057\u305f\u3082\u306e\u304c\u306f\u3044\u308b\uff0e\u70b9\u306f\\(x\\)\u5ea7\u6a19\u3068\\(y\\)\u5ea7\u6a19\u304c\u884c\u5217\u5f62\u5f0f\u3067\u683c\u7d0d\u3055\u308c\u3066\u3044\u308b\u305f\u3081\uff0c\u70b9\\(U\\)\u306e\u5834\u5408\\(U[1]\\)\u3067\\(x\\)\u5ea7\u6a19\uff0c\\(U[2]\\)\u3067\\(y\\)\u5ea7\u6a19\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\uff0elift\u95a2\u6570\u304c\u3064\u3044\u3066\u3044\u308b\u306e\u306f\uff0c\u70b9\\(U\\)\u304c\\(mod\\ p\\)\u3067\u8a08\u7b97\u3055\u308c\u3066\u3044\u308b\u305f\u3081Mod(xx,p)\u3068\u3044\u3046\u5f62\u5f0f\u306b\u306a\u3063\u3066\u304a\u308a\uff0cMod\u3092\u5916\u3059\u5fc5\u8981\u304c\u3042\u308b\u305f\u3081\uff0e<\/p>\n<pre class=\"lang:default decode:true \">r=random(l-1)+1;\nU=ellmul(e,P,r);\nm=random(p);\nu=lift(U[1])%l;v=((m+u*d_B)\/r)%l;\n<\/pre>\n<p>&nbsp;<br \/>\n<strong>4.\u7f72\u540d\u691c\u8a3c<\/strong><br \/>\n\\(d\\)\u3068\\(V\\)\u306b\u3064\u3044\u3066\u306f\uff0c\u5b9a\u7fa9\u3069\u304a\u308a\u30b3\u30fc\u30c9\u3092\u66f8\u304f\u3060\u3051\u3067\u826f\u3044\uff0e<\/p>\n<pre class=\"lang:default decode:true\">d=(1\/v)%l;\nV=elladd(e,ellmul(e,P,d*m),ellmul(e,P_B,d*u));<\/pre>\n<p>&nbsp;<br \/>\n<strong>5.\u7d50\u679c\u8868\u793a<\/strong><br \/>\n\u7d50\u679c\u304c\u6b63\u3057\u3044\u304b\u3069\u3046\u304b\u306f\\(u\\)\u3068\uff0c\u70b9\\(V\\)\u306e\\(x\\)\u5ea7\u6a19\u3092\\(mod\\ l\\)\u3057\u305f\u3082\u306e\u304c\u7b49\u3057\u3044\u304b\u3069\u3046\u304b\u3067\u5224\u65ad\u3059\u308b\uff0e\u7b49\u3057\u3044\u306a\u3089\u7f72\u540d\u306f\u6b63\u3057\u304f\uff0c\u7b49\u3057\u304f\u306a\u3044\u306a\u3089\u7f72\u540d\u306f\u6b63\u3057\u304f\u306a\u3044\u3053\u3068\u3092\u793a\u3059\uff0ePARI GP\u306e\u6761\u4ef6\u5206\u5c90\u306fif(\u6761\u4ef6\u5f0f\uff0c\u771f\uff0c\u507d)\u3067\u8a18\u8ff0\u3059\u308b\uff0e<\/p>\n<pre class=\"lang:default decode:true\">if(u==(lift(V[1])%l),\n\tprint(\"OK\");,\n\tprint(\"NG\");\n);<\/pre>\n<p>&nbsp;<br \/>\n&nbsp;<br \/>\n\u4ee5\u4e0b\u306b\u4e2d\u9593\u7d50\u679c\u306e\u8868\u793a\u3092\u8ffd\u52a0\u3057\u305f\u5168\u4f53\u306e\u30b3\u30fc\u30c9\u3068\u305d\u306e\u5b9f\u884c\u4f8b\u3092\u793a\u3059\uff0e\u306a\u304a\uff0c\u610f\u56f3\u7684\u306bNG\u3092\u51fa\u529b\u3057\u305f\u3044\u5834\u5408\u306f\u7f72\u540d\u691c\u8a3c\u306e\u6700\u521d\u3067\\(m\\)\u306e\u5024\u3092\u305a\u3089\u305b\u3070\u826f\u3044\uff0e<br \/>\n&nbsp;<br \/>\n&nbsp;<\/p>\n<pre class=\"lang:default decode:true \" title=\"ECDSA\">{\n\t\\\\\u6e96\u5099\n\ta=84;b=12;p=251;\n\te=ellinit([0,0,0,a,b],p);\n\tprint(\"y^2=x^3+\",a,\"x+\",b,\" on F_\",p);\n\tP=[Mod(183, p), Mod(12, p)];\n\tprint(\"base point P=\",P);\n\tl=ellorder(e,P);\n\tprint(\"order l=\",l);\n\t\\\\\u9375\u751f\u6210\n\td_B=random(l-2)+2;\n\tP_B=ellmul(e,P,d_B);\n\tprint(\"secret key d_B=\",d_B);\n\tprint(\"public key P_B=\",P_B);\n\t\\\\\u7f72\u540d\u751f\u6210\n\tr=random(l-1)+1;\n\tprint(\"random value r=\",r);\n\tU=ellmul(e,P,r);\n\tprint(\"U=\",U);\n\tm=random(p);\n\tprint(\"m=\",m);\n\tu=lift(U[1])%l;\n\tv=((m+u*d_B)\/r)%l;\n\tprint(\"signature (u,v)=(\",u,\",\",v,\")\");\n\t\\\\\u7f72\u540d\u691c\u8a3c\n\td=(1\/v)%l;\n\tprint(\"d=\",d);\n\tV=elladd(e,ellmul(e,P,d*m),ellmul(e,P_B,d*u));\n\tprint(\"V=\",V);\n\t\\\\\u7d50\u679c\u8868\u793a\n\tif(u==(lift(V[1])%l),\n\t\tprint(\"OK\");,\n\t\tprint(\"NG\");\n\t);\n}\n<\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"lang:default decode:true \">(16:33) gp &gt; \\r ecdsa.gp\ny^2=x^3+84x+12 on F_251\nbase point P=[Mod(183, 251), Mod(12, 251)]\norder l=241\nsecret key d_B=111\npublic key P_B=[Mod(237, 251), Mod(46, 251)]\nrandom value r=192\nU=[Mod(118, 251), Mod(240, 251)]\nm=93\nsignature (u,v)=(118,80)\nd=238\nV=[Mod(118, 251), Mod(240, 251)]\nOK<\/pre>\n<p>&nbsp;<br \/>\n&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[mathjax]\u4eca\u56de\u306fPARI GP\u3092\u7528\u3044\u3066ECDSA\u3092\u5b9f\u88c5\u3059\u308b\uff0e<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-355","post","type-post","status-publish","format-standard","hentry","category-4"],"_links":{"self":[{"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/posts\/355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/comments?post=355"}],"version-history":[{"count":0,"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/posts\/355\/revisions"}],"wp:attachment":[{"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/media?parent=355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/categories?post=355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/p-0.me\/b\/wp-json\/wp\/v2\/tags?post=355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}