Two-party ECDSA with JavaCard-based smartcards
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14330%2F25%3A00140394" target="_blank" >RIV/00216224:14330/25:00140394 - isvavai.cz</a>
Výsledek na webu
<a href="http://dx.doi.org/10.1007/978-3-031-95764-2_7" target="_blank" >http://dx.doi.org/10.1007/978-3-031-95764-2_7</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1007/978-3-031-95764-2_7" target="_blank" >10.1007/978-3-031-95764-2_7</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Two-party ECDSA with JavaCard-based smartcards
Popis výsledku v původním jazyce
Threshold signatures are an effective method for enhancing the security of signing keys based on distributing their storage across multiple devices and enabling direct signing using the produced key shares without reconstructing the original keys. For instance, a private key can be split between a smartphone and a smartcard, with each device controlling a key share. To create a signature, a user simply taps the smartcard on the smartphone, executing the threshold signing protocol over the contactless interface, which results in the signature. However, computing threshold signatures on smartcards presents significant challenges due to their limited computational resources. This issue becomes even more pronounced with ECDSA signatures, the most widely used type of elliptic-curve-based signatures. Unlike other common EC-based signature schemes, threshold ECDSA is computationally intensive because it requires the multiplication of secretly shared values. To address this challenge, we surveyed protocols for computing threshold ECDSA signatures and proposed three approaches viable for computation on current smartcards with different trade-offs. The first approach is based on a two-party protocol by Lindell [22], which is computable on smartcards thanks to their modular exponentiation coprocessor but still relatively slow. The remaining two approaches utilize the preprocessing model with an optional trusted preprocessing party. We implemented all three approaches for the JavaCard platform while considering the hardware constraints and evaluated their performance on a physical smartcard to assess their practicality.
Název v anglickém jazyce
Two-party ECDSA with JavaCard-based smartcards
Popis výsledku anglicky
Threshold signatures are an effective method for enhancing the security of signing keys based on distributing their storage across multiple devices and enabling direct signing using the produced key shares without reconstructing the original keys. For instance, a private key can be split between a smartphone and a smartcard, with each device controlling a key share. To create a signature, a user simply taps the smartcard on the smartphone, executing the threshold signing protocol over the contactless interface, which results in the signature. However, computing threshold signatures on smartcards presents significant challenges due to their limited computational resources. This issue becomes even more pronounced with ECDSA signatures, the most widely used type of elliptic-curve-based signatures. Unlike other common EC-based signature schemes, threshold ECDSA is computationally intensive because it requires the multiplication of secretly shared values. To address this challenge, we surveyed protocols for computing threshold ECDSA signatures and proposed three approaches viable for computation on current smartcards with different trade-offs. The first approach is based on a two-party protocol by Lindell [22], which is computable on smartcards thanks to their modular exponentiation coprocessor but still relatively slow. The remaining two approaches utilize the preprocessing model with an optional trusted preprocessing party. We implemented all three approaches for the JavaCard platform while considering the hardware constraints and evaluated their performance on a physical smartcard to assess their practicality.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
<a href="/cs/project/VJ01010084" target="_blank" >VJ01010084: Elektronické důkazy v trestním řízení</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
Applied Cryptography and Network Security: 23rd International Conference on Applied Cryptography and Network Security
ISBN
9783031957635
ISSN
0302-9743
e-ISSN
—
Počet stran výsledku
18
Strana od-do
158-175
Název nakladatele
Lecture Notes in Computer Science
Místo vydání
Cham, Switzerland
Místo konání akce
Munich
Datum konání akce
1. 1. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
001549663000007