Elliptic curve cryptography

Level AdvancedDifficulty ★★★★★Application⌖ Open in the map

What is it?

Public-key cryptography on the group of points of y2=x3+ax+by^2 = x^3 + ax + b over a finite field. The group law was derived geometrically over the reals (the tangent slope by implicit differentiation); security rests on the discrete logarithm problem, which has nothing to do with calculus.

Formulas

λ=3x12+a2y1,x3=λ2−2x1,y3=λ(x1−x3)−y1\lambda = \frac{3x_1^2 + a}{2y_1}, \quad x_3 = \lambda^2 - 2x_1, \quad y_3 = \lambda(x_1 - x_3) - y_1
point doubling P+PP + P (computed mod pp in practice)

The mathematics behind it

  • Polynomial functions★★★★★indirect

    The curve is the zero set of the polynomial y2−x3−ax−by^2 - x^3 - ax - b, but over a finite field, where calculus does not apply.

  • Implicit differentiation★★★★★historical

    The point-doubling formula uses the slope 3x2+a2y\frac{3x^2 + a}{2y}, derived over the reals and reused verbatim over finite fields.

This page has the essentials. A fuller treatment (intuition, formal definition, worked example) is on the way.

↑ ↓ to navigate · ↵ · Esc