Pairing Tutorial

Example: Implementing a pairing-based signature scheme

Cryptimeleon Math is a library supplying the mathematical basics for cryptography.

In this notebook, we’ll take a look at how to implement a pairing-based scheme.

The (multi-message) Pointcheval-Sanders signature scheme is a very useful digital signature scheme for advanced cryptographic constructions because of its elegant and simple algebraic structure. We’ll use it as an example for implementing a cryptographic scheme.

We’ll work alongside the scheme’s definition in the paper: image.png

… and show how to implement it.



Note: You can also check this page out in an interactive Jupyter notebook by clicking the badge below:

Binder


Setting up the bilinear group

image-2.png First, we need to set up the bilinear group setting required for the scheme. We need to know the type of pairing and the desired security parameter. In this case we want a type 3 pairing and 100 bit security.

%maven org.cryptimeleon:math:3.0.1
import org.cryptimeleon.math.structures.groups.elliptic.*;
import org.cryptimeleon.math.structures.groups.elliptic.type3.bn.BarretoNaehrigBilinearGroup;
import org.cryptimeleon.math.structures.groups.*;
import org.cryptimeleon.math.structures.groups.mappings.*;
import org.cryptimeleon.math.structures.rings.zn.*;

// Choose number of messages r
var r = 3;

// BN pairing is type 3 and we specify a 100 bit security parameter
BilinearGroup bilinearGroup = new BarretoNaehrigBilinearGroup(100);

// Let's collect the values for our pp
Group groupG1 = bilinearGroup.getG1();
Group groupG2 = bilinearGroup.getG2();
Group groupGT = bilinearGroup.getGT();
BilinearMap e = bilinearGroup.getBilinearMap();
BigInteger p = groupG1.size();
Zn zp = bilinearGroup.getZn();
System.out.println("Generated bilinear group of order " + p);
Generated bilinear group of order 66696243400694322499906033083377966773014133293855982130239936888504801018589797

Generating a key pair

image-2.png

For a key pair, we need to generate random exponents \(x\) and \(y_i\) as the secret key. Because it’s a group of order \(p\), we interpret the exponents as elements of \(\mathbb{Z}_p\).

// Generate secret key

var x = zp.getUniformlyRandomElement();
var y = zp.getUniformlyRandomElements(r); //computes a vector of r random numbers y_0, ..., y_(r-1)

System.out.println("x = " + x);
System.out.println("y = " + y);
x = 45896283663142216104362495977495081061350946911855985977320317196394162577842668
y = [49478563736238945082546531433013615588027372094598091605349074534734369843315494, 37045112144060471776592775498435376763144135288319977584834273839568977602967371, 2226548506858235244333716319839932877707715091686112891015789087861521371190460]

Then we can compute the corresponding public key easily and run precomputation on it to speed up later verifications:

// Generate public key

var tildeg = groupG2.getUniformlyRandomElement();
var tildeX = tildeg.pow(x).precomputePow(); // this computes X = tildeg^x as above and runs precomputations to speed up later pow() calls on tildeX
var tildeY = tildeg.pow(y).precomputePow(); // because y is a vector, this yields a vector of values tildeg.pow(y_0), tildeg.pow(y_1), ...
System.out.println("tildeg = " + tildeg);
System.out.println("tildeX = " + tildeX);
System.out.println("tildeY = " + tildeY);
tildeg = ([48564954436780276225129283888712875161956251454924267080521782266129471493846087, 13593196442609343951536265512361731641028377980024295467440642917272013971354139],[18686074728127273100460742312087430323759497426045052138364095971954286615055364, 45240668079139622699276330048963434819644225003999671864150887916207183485095344])
tildeX = ([57563123324327464176079609261658871699286259022003940327071834442004803033968984, 31137685492195396951109297221068659592586555815259419921593993146341188891637838],[28491346061572603752176955318351865478443654475506827314129229559788899033503143, 9138099414339924258159704610524765706594214108568814835913248745331811910320638])
tildeY = [([36287503656559771474284025253886396575531806228143092112504269174184197411002728, 15229919642588234170622767802457066896212470929426207445096393484878810723524718],[34576839464834281369786935795422402333294588818113392861012674965473706298678804, 27179668810405861869055735344930888100284893974115202905539324838102940716046808]), ([58859196773107645050282323966454502550577725355030774869156939688046567131587459, 56630850194254056680366519755298590987077466659279972459026045324201529899184483],[37572508345047012301872386907321943804034457419826219827887842232205749278336028, 39419388664418503344641198925345074766874457371063874100375134613450909933496177]), ([23723387085032437956392056466162029649573250565831532177741102746298065878342568, 36900538358093048436475569635785090859229703611763158619382463268724827801080607],[61642049410003042159817656751824645475056476008765334934561863200041083556574262, 34643497275535619465593678204672633643377643341818208187850201156948300963161168])]

Computing a signature

image.png

Computing a signature works as you’d expect now with what we’ve already seen. Messages for Pointcheval-Sanders lie in \(\mathbb{Z}_p\), but we can use a hash function \(\mathcal{H}:\{0,1\}\rightarrow \mathbb{Z}_p\) to sign arbitrary strings.

import org.cryptimeleon.math.structures.rings.cartesian.RingElementVector;

// Preparing messages ("Hello PS sigs", 42, 0, 0, ...)
var m = new RingElementVector(
    bilinearGroup.getHashIntoZGroupExponent().hash("Hello PS sigs"), 
    zp.valueOf(42)).pad(zp.getZeroElement(), r
);

// Computing signature
var sigma1 = groupG1.getUniformlyRandomNonNeutral().compute(); // h
var sigma2 = sigma1.pow(x.add(y.innerProduct(m))).compute(); // h^{x + sum(y_i*m_i)}
// The compute() call is optional but will cause sigma1 and sigma2 to be computed concurrently in the background.
System.out.println("sigma1 = " + sigma1);
System.out.println("sigma2 = " + sigma2);
sigma1 = (7881639518637039650791047105301300759166282868132131612822025387351629998025450,7600253022952598992338960339955656199253390260460539939888695959088997078594086)
sigma2 = (3765949726043157988393762436056219684134255253049660637015501037824100343641877,25453221067611326537796328047266178940618394483296936894413338481534808989792674)

Verifying a signature

image.png

For this verification, we need to emply the pairing e.

!sigma1.isNeutralElement() 
    && e.apply(sigma1, tildeX.op(tildeY.innerProduct(m))).equals(e.apply(sigma2, tildeg))
true

If this pairing computation seems slow, check out the mclwrap addon for a faster bilinear group.