pasta_curves-source/book/src/background/curves.md
Jack Grigg f8c5c2e28e book: Add background material
Co-authored-by: Sean Bowe <ewillbefull@gmail.com>
Co-authored-by: Daira Hopwood <daira@jacaranda.org>
Co-authored-by: ying tong <yingtong@z.cash>
2021-01-11 20:44:53 +00:00

11 KiB

Elliptic curves

Elliptic curves constructed over finite fields are another important cryptographic tool. There are several ways to define the curve equation, but for our purposes, let \mathbb{F}_p be a large (255-bit) field, and then let the set of solutions (x, y) to y^2 = x^3 + b for some constant b define the $\mathbb{F}_p$-rational points on an elliptic curve E(\mathbb{F}_p). These (x, y) coordinates are called "affine coordinates". Each of the $\mathbb{F}_p$-rational points, together with a "point at infinity" \mathcal{O} that serves as the group identity, can be interpreted as an element of a group. By convention, elliptic curve groups are written additively.

"Three points on a line sum to zero, which is the point at infinity."

The group addition law is simple: to add two points together, find the line that intersects both points and obtain the third point, and then negate its $y$-coordinate. The case that a point is being added to itself, called point doubling, requires special handling: we find the line tangent to the point, and then find the single other point that intersects this line and then negate. Otherwise, in the event that a point is being "added" to its negation, the result is the point at infinity.

The ability to add and double points naturally gives us a way to scale them by integers. The number of points on the curve is known as the "group order". If this number is prime q, we call the numbers that we scale curve points by "scalars" and consider that they are all elements of a scalar field \mathbb{F}_q.

Elliptic curves, when properly designed, have an important security property. Given two random elements G, H \in E(\mathbb{F}_p) finding a such that [a] G = H, otherwise known as the discrete log of H with respect to G, is considered computationally infeasible with classical computers. This is called the elliptic curve discrete log assumption.

Curve arithmetic

Point doubling

The simplest situation is doubling a point (x_0, y_0). Continuing with our example y^2 = x^3 + b, this is done first by computing the derivative \lambda = \frac{dy}{dx} = \frac{3x^2}{2y}.

To obtain expressions for (x_1, y_1) = (x_0, y_0) + (x_0, y_0), we consider

\begin{aligned} \frac{-y_1 - y_0}{x_1 - x_0} = \lambda &\implies -y_1 = \lambda(x_1 - x_0) + y_0 \ &\implies \boxed{y_1 = \lambda(x_0 - x_1) - y_0}. \end{aligned}

To get the expression for x_1, we substitute y = \lambda(x_0 - x) - y_0 into the elliptic curve equation:

\begin{aligned} y^2 = x^3 + b &\implies (\lambda(x_0 - x) - y_0)^2 = x^3 + b \ &\implies x^3 - \lambda^2 x^2 + \cdots = 0 \leftarrow\text{(rearranging terms)} \ &= (x - x_0)(x - x_0)(x - x_1) \leftarrow\text{(known roots x_0, x_0, x_1)} \ &= x^3 - (x_0 + x_0 + x_1)x^2 + \cdots. \end{aligned}

Comparing coefficients for the x^2 term gives us \lambda^2 = x_0 + x_0 + x_1 \implies \boxed{x_1 = \lambda^2 - 2x_0}.

Projective coordinates

This unfortunately requires an expensive inversion of 2y. We can avoid this by arranging our equations to "defer" the computation of the inverse, since we often do not need the actual affine (x', y') coordinate of the resulting point immediately after an individual curve operation. Let's introduce a third coordinate Z and scale our curve equation by Z^3 like so:

Z^3 y^2 = Z^3 x^3 + Z^3 b

Our original curve is just this curve at the restriction Z = 1. If we allow the affine point (x, y) to be represented by X = xZ, Y = yZ and Z \neq 0 then we have the homogenous projective curve

Y^2 Z = X^3 + Z^3 b.

Obtaining (x, y) from (X, Y, Z) is as simple as computing (X/Z, Y/Z) when Z \neq 0. (When Z = 0, we are dealing with the point at infinity O := (0:1:0).) In this form, we now have a convenient way to defer the inversion required by doubling a point. The general strategy is to express x', y' as rational functions using x = X/Z and y = Y/Z, rearrange to make their denominators the same, and then take the resulting point (X, Y, Z) to have Z be the shared denominator and X = x'Z, Y = y'Z.

Projective coordinates are often, but not always, more efficient than affine coordinates. There may be exceptions to this when either we have a different way to apply Montgomery's trick, or when we're in the circuit setting where multiplications and inversions are about equally as expensive (at least in terms of circuit size).

The following shows an example of doubling a point (X, Y, Z) = (xZ, yZ, Z) without an inversion. Substituting with X, Y, Z gives us \lambda = \frac{3x^2}{2y} = \frac{3(X/Z)^2}{2(Y/Z)} = \frac{3 X^2}{2YZ}

and gives us \begin{aligned} x' &= \lambda^2 - 2x \ &= \lambda^2 - \frac{2X}{Z} \ &= \frac{9 X^4}{4Y^2Z^2} - \frac{2X}{Z} \ &= \frac{9 X^4 - 8XY^2Z}{4Y^2Z^2} \ &= \frac{18 X^4 Y Z - 16XY^3Z^2}{8Y^3Z^3} \ \ y' &= \lambda (x - x') - y \ &= \lambda (\frac{X}{Z} - \frac{9 X^4 - 8XY^2Z}{4Y^2Z^2}) - \frac{Y}{Z} \ &= \frac{3 X^2}{2YZ} (\frac{X}{Z} - \frac{9 X^4 - 8XY^2Z}{4Y^2Z^2}) - \frac{Y}{Z} \ &= \frac{3 X^3}{2YZ^2} - \frac{27 X^6 - 24X^3Y^2Z}{8Y^3Z^3} - \frac{Y}{Z} \ &= \frac{12 X^3Y^2Z - 8Y^4Z^2 - 27 X^6 + 24X^3Y^2Z}{8Y^3Z^3} \end{aligned}

Notice how the denominators of x' and y' are the same. Thus, instead of computing (x', y') we can compute (X, Y, Z) with Z = 8Y^3Z^3 and X, Y set to the corresponding numerators such that X/Z = x' and Y/Z = y'. This completely avoids the need to perform an inversion when doubling, and something analogous to this can be done when adding two distinct points.

TODO: Point addition

\begin{aligned} P + Q &= R\ (x_p, y_p) + (x_q, y_q) &= (x_r, y_r) \ \lambda &= \frac{y_q - y_p}{x_q - x_p} \ x_r &= \lambda^2 - x_p - x_q \ y_r &= \lambda(x_p - x_r) - y_p \end{aligned}


Important notes:

  • There exist efficient formulae1 for point addition that do not have edge cases (so-called "complete" formulae) and that unify the addition and doubling cases together. The result of adding a point to its negation using those formulae produces Z = 0, which represents the point at infinity.
  • In addition, there are other models like the Jacobian representation where (x, y) = (xZ^2, yZ^3, Z) where the curve is rescaled by Z^6 instead of Z^3, and this representation has even more efficient arithmetic but no unified/complete formulae.
  • We can easily compare two curve points (X_1, Y_1, Z_1) and (X_2, Y_2, Z_2) for equality in the homogenous projective coordinate space by "homogenizing" their Z-coordinates; the checks become X_1 Z_2 = X_2 Z_1 and Y_1 Z_2 = Y_2 Z_1.

Curve endomorphisms

Imagine that \mathbb{F}_p has a primitive cube root of unity, or in other words that 3 | p - 1 and so an element \zeta_p generates a $3$-order multiplicative subgroup. Notice that a point (x, y) on our example elliptic curve y^2 = x^3 + b has two cousin points: (\zeta_p x, \zeta_p^2 x), because the computation x^3 effectively kills the \zeta component of the $x$-coordinate. Applying the map (x, y) \mapsto (\zeta_p x, y) is an application of an endomorphism over the curve. The exact mechanics involved are complicated, but when the curve has a prime q number of points (and thus a prime "order") the effect of the endomorphism is to multiply the point by a scalar in \mathbb{F}_q which is also a primitive cube root \zeta_q in the scalar field.

Curve point compression

TODO

Cycles of curves

Let E_p be an elliptic curve over a finite field \mathbb{F}_p, where p is a prime. We denote this by E_p/\mathbb{F}_p. and we denote the group of points of E_p over \mathbb{F}_p, with order q = \#E(\mathbb{F}_p). For this curve, we call \mathbb{F}_p the "base field" and \mathbb{F}_q the "scalar field".

We instantiate our proof system over the elliptic curve E_p/\mathbb{F}_p. This allows us to prove statements about $\mathbb{F}_q$-arithmetic circuit satisfiability.

(aside) If our curve E_p is over \mathbb{F}_p, why is the arithmetic circuit instead in \mathbb{F}_q? The proof system is basically working on encodings of the scalars in the circuit (or more precisely, commitments to polynomials whose coefficients are scalars). The scalars are in \mathbb{F}_q when their encodings/commitments are elliptic curve points in E_p/\mathbb{F}_p.

However, most of the verifier's arithmetic computations are over the base field \mathbb{F}_p, and are thus efficiently expressed as an $\mathbb{F}_p$-arithmetic circuit.

(aside) Why are the verifier's computations (mainly) over \mathbb{F}_p? The Halo 2 verifier actually has to perform group operations using information output by the circuit. Group operations like point doubling and addition use arithmetic in \mathbb{F}_p, because the coordinates of points are in \mathbb{F}_p.

This motivates us to construct another curve with scalar field \mathbb{F}_p, which has an $\mathbb{F}_p$-arithmetic circuit that can efficiently verify proofs from the first curve. As a bonus, if this second curve had base field E_q/\mathbb{F}_q, it would generate proofs that could be efficiently verified in the first curve's $\mathbb{F}_q$-arithmetic circuit. In other words, we instantiate a second proof system over E_q/\mathbb{F}_q, forming a 2-cycle with the first:

TODO: Pallas-Vesta curves

Reference: https://github.com/zcash/pasta

Hashing to curves

Sometimes it is useful to be able to produce a random point on an elliptic curve E_p/\mathbb{F}_p corresponding to some input, in such a way that no-one will know its discrete logarithm (to any other base).

This is described in detail in the Internet draft on Hashing to Elliptic Curves. Several algorithms can be used depending on efficiency and security requirements. The framework used in the Internet Draft makes use of several functions:

  • hash_to_field: takes a byte sequence input and maps it to a element in the base field \mathbb{F}_p
  • map_to_curve: takes an \mathbb{F}_p element and maps it to E_p.

TODO: Simplified SWU

Reference: https://eprint.iacr.org/2019/403.pdf

References


  1. Renes, J., Costello, C., & Batina, L. (2016, May). "Complete addition formulas for prime order elliptic curves." In Annual International Conference on the Theory and Applications of Cryptographic Techniques (pp. 403-428). Springer, Berlin, Heidelberg. https://eprint.iacr.org/2015/1060.pdf ↩︎