Access
Access
Implementation of Authenticated
Encryption Scheme using Elliptic Curve
Cryptography
P. L. SHARMA1 , SHALINI GUPTA2 , KRITIKA GUPTA3 , AND ARUN KUMAR SHARMA4
1
Department of Mathematics & Statistics, Himachal Pradesh University, Shimla 171005, India (e-mail: plsharma1964@[Link])
2
Department of Mathematics & Statistics, Himachal Pradesh University, Shimla 171005, India (e-mail: shalini.garga1970@[Link])
3
Department of Mathematics & Statistics, Himachal Pradesh University, Shimla 171005, India (e-mail: kritika993@[Link])
4
Department of Computer Science & Applications, Panjab University, Chandigarh, India (e-mail: arun_sharma@[Link])
Corresponding author: P. L. Sharma (plsharma1964@[Link]).
ABSTRACT Elliptic Curve Cryptography (ECC) is a powerful technique used to secure data communi-
cation and storage, which is based on the mathematics of elliptic curves. Confidentiality and authentication
are two important factors contributing to the security of information. There are several encryption schemes
which provide us confidentiality. In the present work, we propose a new encryption scheme which provides
us both confidentiality as well as authentication. Authentication mechanism ensures that the message comes
from a legitimate source. The scheme utilizes a public and private key pair generated from an elliptic
curve and combines symmetric and asymmetric encryption methods for secure data transmission. Here,
the technique used to map the characters of the message to point on an elliptic curve eliminates the need to
share a code table. The proposed mapping scheme is efficient, as it utilizes the mathematical properties of
elliptic curve to reduce the computation time. Further, we implement the proposed scheme using Python and
MATLAB and analyse its time efficiency and security. The performance analysis shows that the proposed
scheme provides better security and efficiency than the traditional encryption methods.
INDEX TERMS Authentication, elliptic curve cryptography, text encryption, decryption, public key,
private key.
1
mapping scheme. Several researchers have proposed various such that
mapping schemes. The first approach to map each character 4a3 + 27b2 ̸= 0.
of the message to a point on an elliptic curve is by multiplying
The condition 4a3 + 27b2 ̸= 0 implies that the elliptic curve
the generator point of the elliptic curve with the ASCII value
is smooth.
of each character of the message. This approach is one-one,
so is vulnerable to frequency analysis attack. A mapping
Some properties of the elliptic curve are given below:
scheme based on the permutation of message matrix is sug-
gested by Amounas and Kinani [16] preventing the frequency
A. GROUP LAW
analysis attack. Another approach to map the message to a
point on an elliptic curve is using quadratic residue, see [17]. Set of elliptic curve points together with the operation of
It is a probabilistic approach and is susceptible to collision addition forms an abelian group. To add two points on an
attack. Muthukuru and Sathyanarayana [18] proposed a new elliptic curve, we use chord and tangent rule.
mapping technique that uses XOR operation to map fixed
length block string to a point on an elliptic curve. But it B. GEOMETRY OF POINT ADDITION ON ELLIPTIC
is vulnerable to both man-in-the-middle attack and chosen CURVE
plaintext attack. Hisham et al. [19] presented a mapping Let E(Fp ) denotes the elliptic curve over finite field Fp .
scheme based on ECC which reduces the size of padding Suppose, A(u1 , v1 ) and B(u2 , v2 ) are two points on the
bits. Almajed and Almogren [20] proposed an authenticated elliptic curve E(Fp ). Then, to add A(u1 , v1 ) and B(u2 , v2 ),
encoding and mapping scheme using ECC. Genç and Afacan we draw a line through A and B and this line will further
[21] provided an encryption scheme using an elliptic curve intersect the curve at third point C(say). Now, taking the
over finite fields in which they encrypted using all the values reflection of this point C about x-axis will give us point D
in Unicode table. Singh and Singh [22] proposed a new on E, which is the sum of points A and B.
technique to map the characters of the message to affine
points on the elliptic curve by grouping the ASCII values and
then using Big Integer function to get the mapped point. This
scheme eliminated the need to share the code table required
for mapping.
In this paper, we propose a new mapping and encryption
scheme by introducing an additional parameter called spe-
cific private key which eliminates the need to share code
table, adds authentication and is more time efficient in terms
of encryption when compared with [22]. The proposed map-
ping scheme helps us in mapping more than one character of
the message simultaneously to a single point on the curve.
Further, we implement the proposed scheme using Python
and MATLAB and analyse its time efficiency and security.
This paper is organised in five sections. In Section 2,
we discuss some preliminaries which are necessary for the
understanding of the paper. In Section 3, we propose our
new authenticated encryption scheme. Section 4 gives the
illustration of the proposed encryption scheme. In Section 5,
we present the results obtained from the implemention of our
proposed scheme in Python and MATLAB. Section 6 deals
with the security analysis of the proposed scheme. Section 7 FIGURE 1. Point Addition
concludes the results.
y 2 = (x3 + ax + b) mod p
2
F. SCALAR POINT MULTIPLICATION
Operation of scalar multiplication over any point A of elliptic
curve is actually repeated addition, that is, kA = A+A+...k
times.
G. IDENTITY
Let A be any point of the elliptic curve, then A + O = O +
A = A for all A ∈ E(Fp ), where O is the point of infinity
and is known as the identity element of the group E(Fp ).
H. INVERSE
If A = (p, q) ∈ E(Fp ), then (p, q) + (p, −q) = O, where
(p, −q) is the inverse of A.
(n ∗ G) ∗ m = (m ∗ G) ∗ n.
FIGURE 2. Point Doubling
T1 = tG
and
T2 = M + tPB + As .
4
• By performing point addition operation between As and
L, obtains mapped point M = {39685671341888596238
43722237908158090746860617616532530491, 3518556
1019569579459636393134403233397779315575117544
99199}.
• Obtains Cipher Text by calculating T1 = tG =
{536974440367871056343245836125454417096609638
4586764429448, 54292343797890710397506549069152
54128254326554272718558123}
and T2 = M +tPB +As = {30337061357877585618499
IV. ILLUSTRATION
36745729377540034435268649892593917, 5705898295
Parameters of chosen elliptic curve of the form y 2 = (x3 + 9596225529324187099864025449379568449169304338
ax + b) mod p are given below: 84}.
• a = −3; • Sends (T1 , T2 ) this to Bob.
• b = 24551555460089438177402939151974517847691
Decryption Side
08058161191238065;
Bob
• p = 62771017353866807638357894232076664160839
• After getting {T1 , T2 }, obtains M by calculating T2 −
08700390324961279;
• nA = 4;
T1 nB −Bs = {396856713418885962384372223790815
• nB = 5;
8090746860617616532530491, 3518556101956957945
• G = {6020462823756886567582134805875261119166
963639313440323339777931557511754499199}.
• Performs point addition operation between Bs and M
98976636884684818, 174050332293622031404857552
280219410364023488927386650641}; and get the random point L = {28030007865416173313
• PA = {130599488043090399730594373869777940831
77384897435095499124748881890727495642, 426971
6929565234787837114, 3981863977451150342116987 802110594428720192929816825304095838300915746
835776121688410789618551673306674}; 3900739}.
• Replaces the last 64 bits of x-coordinate of random
• PB = {410283251116784874018993562136566870110
676706936762660240, 120665467489982524668820566 point L with the binary form of integer ‘b’ and get the
9651974202006189255452737318561}; resultant X = 11100100101000010110001100101011
• As = {4595861390586516053227332892407061980407
01010100100000010111010010100010011110101100
949769416178851175, 357731060455380874027104197 00110101010100100010100100011010101110011111
1695937863431408727974102387853}; 10001110011110111100011110011011111111101101
• Bs = {4595861390586516053227332892407061980407
000101100010110010110001101.
• Performs XOR operation between binary form of X and
949769416178851175, 357731060455380874027104197
1695937863431408727974102387853}; binary form of x-coordinate of random point L to get
• L = {28030007865416173313773848974350954991247
101100110011001001100101001101011101001101000
48881890727495642, 4269718021105944287201929298 1000011010000110001001010111 which corresponds
168253040958383009157463900739}. to ASCII values 66, 111, 97, 114, 100, 105, 110, 103
and text characters corresponding to ASCII values are
Encryption Side
‘boarding’.
• Suppose Alice wants to send a message ‘boarding’ to
Bob. V. PERFORMANCE ANALYSIS
• ASCII values corresponding to ‘boarding’ are 66, 111,
Proposed Scheme is implemented in Python for encryption
97, 114, 100, 105, 110, 103. and decryption. Performance comparison graph of reference
approach [22] and our proposed approach is plotted on MAT-
Alice LAB with string length 10 to 500 and time averaged over 100
• Performs XOR operation between binary form trials. Encryption and decryption time graphs obtained by the
of x-coordinate of random point L and binary implementation of proposed scheme and existing scheme are
form of ASCII value of first eight characters given below. Encryption time using our proposed scheme is
of the message and get the resultant X = much better than the existing approach, making our scheme
11100100101000010110001100101011010101001000 more efficient.
00010111010010100010011110101100001101010101
00100010100100011010101110011111100011100111
10111100011110011011111111101101000101100010
110010110001101.
• Get the integer ‘b′ = 4459634552883733901 on con-
verting the last 64 bits of resultant X to decimal value.
5
challenging problem that is provided by ECC which allows
the user to take smaller keys than previous cryptographic
methods, while maintaining the same security level. We used
a 192-bit key length in our implementation, which is quite
good to defend against simple attacks. We could lengthen the
keys for higher security.
D. TIME COMPLEXITY
Pollard’s Rho method and Pollard Lambda method are
the most well-known attacks on ECC. These are the
FIGURE 3. Encryption Time probabilistic methods√ that expects to find private key
in a maximum of N steps, where N is the cyclic
order of the Elliptic Curve. Here, we used N as
62771017353866807638357894231760590137671947731828 √
42284081. Therefore, key can be most probably found in N
steps = 7.92282 ∗ 102 8 steps. So, a large number of days will
be required to find the private key. By then, the value of the
message will be no more important.
VII. CONCLUSION
To provide confidentiality and authentication, this paper
presents an authenticated encryption scheme with the intro-
duction of additional parameter called specific private key.
FIGURE 4. Decryption Time Mapping of characters to a point on an elliptic curve is done
in such a way that it eliminates the need of sharing code
table and eight characters of the message can be mapped to
From the obtained graph, it is clear that encryption and a single point on the curve simultaneously. Security analysis
decryption can be performed very swiftly through our pro- shows that the scheme is secure against various attacks. The
posed approach and is more time efficient. proposed scheme is also faster in terms of encryption speed
when compared with the existing similar scheme. Further,
VI. SECURITY ANALYSIS sender can digitally sign the message along with encryption
A. CIPHERTEXT ONLY ATTACK and thus, modified authenticated encryption scheme provides
Suppose that the attacker is aware of the ciphertext and confidentiality, authentication and non-repudiation.
encryption scheme. The attacker cannot get the plaintext
until and unless the attacker does not have the receiver’s ACKNOWLEDGMENT
private and specific private key. When the key size is really Third author thankfully acknowledge the support of DST
huge, applying a Brute Force attack wouldn’t be particularly INSPIRE.
helpful because it will take a long time-in-years-to complete.
Therefore, even if the attacker is successful in decrypting it, REFERENCES
the information is no longer important. [1] N. Koblitz, “Elliptic curve cryptosystem,” Mathematics of Computation,
vol. 48, pp. 203-209, 1987.
[2] V. S. Miller, “Uses of elliptic curves in cryptography,” In Advances
B. KNOWN PLAINTEXT ATTACK
in Cryptology-CRYPTO’85 Proceedings, Crypto, vol. 218, pp. 417-426,
Suppose that the attacker is aware of the ciphertext, encryp- 1985.
tion scheme and one or more pair of plaintext-ciphertext. [3] M. Jaiswal and K. Lata, “Hardware implementation of text encryption
using elliptic curve cryptography over 192 bit prime field,” in Proc.
The scheme is safe from the known plaintext attack since International Conference on Advances in Computing, Communications
random point L and random integer t are used in the proposed and Informatics (ICACCI), Bangalore, India, 2018, pp. 343-349.
encryption scheme which generates different ciphertext for [4] B. V. Varun, A. M.V., A. C. Gangadhar, and P. U., “Implementation of
encryption and decryption algorithms for security of mobile devices,” in
the same message. Proc. IEEE 19th International Conference on Communication Technology
(ICCT), Xi’an, China, 2019, pp. 1391-1395.
C. KEY SPACE [5] S. M. C. Vigila and K. Muneeswaran, “Implementation of text based cryp-
tosystem using Elliptic Curve Cryptography,” in Proc. First International
The size of the key used has a significant impact on the Conference on Advanced Computing, Chennai, India, 2009, pp. 82-85.
security of cryptographic encryption scheme. Everyone will [6] A. M. Johnston and P. S. Gemmell, “Authenticated key exchange provably
be aware of the algorithm. A large key is always the wise secure against the Man-In-Middle attack,” Journal of Cryptology, vol. 2,
pp. 139-148, 2002.
decision, but when we raise the key size, we also need to con- [7] A. Joux, “A one round protocol for tripartite Diffie-Hellman,” Journal of
sider the computational burden. ECDLP is a computationally Cryptology, vol. 17, no. 4, pp. 263-276, 2004.
6
[8] A. K. Lenstra and E. R. Verheul, “Selecting cryptographic key size,” SHALINI GUPTA received the M. Sc. degree
Journal of Cryptology, vol. 14, no. 4, pp. 255-293, 2001. in mathematics and M. Phil. Degree in computer
[9] J. H. Silverman, The Arithmetic of Elliptic Curves, Graduate Texts in applications from University of Roorkee, Roorkee
Mathematics, vol. 106, 2009. (Present IIT Roorkee) in the year 1991 and 1992
[10] N. Koblitz, A. J. Menezes, and S. Vanstone, “The State of Elliptic Curve respectively. She has completed her Ph. D. degree
Cryptography,” Design, Codes and Cryptography, vol. 19, pp. 173-193, in mathematics from Himachal Pradesh Univer-
2000. sity, Shimla (H. P.), India in 2018. Presently, she is
[11] D. C. Hankerson, A. J. Menezes, and S. Vanstone, Guide to Elliptic Curve
working as an Associate Professor of Mathemat-
Cryptography, Springer Professional Computing, 1st ed., 2004.
ics in Department of Mathematics and Statistics,
[12] L. C. Washington, Elliptic Curves Number Theory and Cryptography, 2nd
ed., Chapman and Hall/CRC, 2008. Himachal Pradesh University, Shimla, India. Her
[13] D. S. Kumar, CH. Suneetha, and A. Chandrasekhar, “Encryption of data research interest includes finite fields, cryptography, rhotrices and bent
using elliptic curve over finite fields,” International Journal of Distributed functions.
and Parallel Systems, vol. 3, no. 1, pp. 301-308, 2012.
[14] K. E. Abdullah and N. H. M. Ali, “Security improvement in elliptic curve
cryptography,” International Journal of Advanced Computer Science and KRITIKA GUPTA received the M. Sc. degree in
Applications, vol. 9, no. 5, pp. 122-131, 2018. mathematics from Central University of Himachal
[15] V. Srinadh, B. Maram, and T. Daniya, “Data security and recovery ap-
Pradesh, Dharamshala, India in 2018. She is cur-
proach using elliptic curve cryptography,” in Proc. IEEE International
rently pursuing the Ph.D. degree in mathematics at
Conference on Computation System and Information Technology for Sus-
tainable Solutions (CSITSS), 2021, pp. 1-6. Himachal Pradesh University, Shimla, India. Her
[16] F. Amounas and E. H. El Kinani, “Fast mapping method based on matrix research interest includes finite fields, cryptogra-
approach for elliptic curve cryptography,” International Journal of Infor- phy and image encryption.
mation & Network Security, vol. 1, no. 2, pp. 54-59, 2012.
[17] P. Bh, D. Chandravathi, and R. P. Prapoorna, “Encoding and decoding
of a message in the implementation of elliptic curve cryptography using
Koblitz’s method,” International Journal on Computer Science and Engi-
neering, vol. 2, no. 5, pp. 1904-1907, 2010.
[18] J. Muthukuru and B. Sathyanarayana, “Fixed and variable size text based ARUN KUMAR SHARMA received the M. Tech
message mapping techniques using ECC,” Global Journal of Computer degree from National Institute of Technology,
Science and Technology, vol. 12, no. 3, pp. 12-18, 2012. Hamirpur, India in the year 2019. He is currently
[19] A. Hisham, A. Ahmad, and A. Mohammed, “ iTrust—A trustworthy and pursuing the Ph. D. degree in computer science
efficient mapping scheme in elliptic curve cryptography,” Sensors, vol. 20, at Department of Computer Science & Applica-
pp. 1-20., 2020. tions, Panjab University, Chandigarh, India. His
[20] H. N. Almajed and A. S. Almogren, “SE-Enc: A secure and efficient research interest includes cryptography, wireless
encoding scheme using elliptic curve cryptography,” IEEE Access, vol. 7, sensor networks and machine learning.
pp. 175865-175878, 2019.
[21] Y. Genç and E. Afacan, “Implementation of new message encryption
using elliptic curve cryptography over finite fields,” in Proc. International
Congress of Advanced Technology and Engineering (ICOTEN), 2021, pp.
1-6.
[22] L. D. Singh and K. M. Singh, “Implementation of text encryption using
elliptic curve cryptography,” Procedia Computer Science, vol. 54, pp. 73-
82, 2015.