Cryptology ePrint Archive: Report 2014/192
Two-sources Randomness Extractors for Elliptic Curves
Abdoul Aziz Ciss
Abstract: This paper studies the task of two-sources randomness extractors for elliptic curves defined over finite fields $K$, where $K$ can be a prime or a binary field. In fact, we introduce new constructions of functions over elliptic curves which take in input two random points from two differents subgroups. In other words, for a ginven elliptic curve $E$ defined over a finite field $\mathbb{F}_q$ and two random points $P \in \mathcal{P}$ and $Q\in \mathcal{Q}$, where $\mathcal{P}$ and $\mathcal{Q}$ are two subgroups of $E(\mathbb{F}_q)$, our function extracts the least significant bits of the abscissa of the point $P\oplus Q$ when $q$ is a large prime, and the $k$-first $\mathbb{F}_p$ coefficients of the asbcissa of the point $P\oplus Q$ when $q = p^n$, where $p$ is a prime greater than $5$. We show that the extracted bits are close to uniform.
Our construction extends some interesting randomness extractors for elliptic curves, namely those defined in \cite{op} and \cite{ciss1,ciss2}, when $\mathcal{P} = \mathcal{Q}$. The proposed constructions can be used in any cryptographic schemes which require extraction of random bits from two sources over elliptic curves, namely in key exchange protole, design of strong pseudo-random number generators, etc.
Category / Keywords: Elliptic curves, randomness extractor, key derivation, bilinear sums
Date: received 12 Mar 2014, last revised 12 Mar 2014
Contact author: aaciss at ept sn
Available format(s): PDF | BibTeX Citation
Version: 20140312:184042 (All versions of this report)
Short URL: ia.cr/2014/192
Discussion forum: Show discussion | Start new discussion
[ Cryptology ePrint archive ]