Elliptic curve cryptography (Elliptic curve Cryptography, abbreviated as ECC) is a method of public key cryptography based on elliptic curve mathematics. The use of elliptic curves in cryptography was presented separately by Neal Koblitz and Victor Miller in 1985.
Elliptic Signature algorithm should be the first Microsoft used in software protection, our usual 25-bit serial number is based on the elliptic signature algorithm. In theory, the elliptic signature algorithm is difficult to crack because ... (omitted, interested can see "ECC Encryption Algorithm Introduction" this article). But because Microsoft is considering the length of the serial number, the length of the signature is only 62bit (how much, forget it), so the private key can be calculated violently. That's what we used for the number-counting device.
Defined:
Elliptic Curve ep= (p,a,b,g,n,h)
P, A, b are used to determine the curve, G is a base point, N is the order of point G, H is the integer portion of the number m and N of all points on the elliptic curve
Signing process
1, select an Elliptic Curve EP (A, B), and base point g
2, select the private key K (K<n,n is the order of G), using the base point G to calculate the public key k=kg
3, take a random integer R (r<n), calculate the point R=rg
4, calculates the feature information and the hash value of R, i.e. Hash=sha (data,x,y)
5, Calculate sig≡r-hash*k (mod n)
6. Generate serial numbers using sig and hash (e.g. using BASE24 encoding)
Validation process
1. Extract the sig and hash from the serial number
2, Calculate r≡sig*g+hash*k (mod p)
3, calculate the computed feature information and the hash value of R, i.e. H=sha (data,x,y)
4, compare H and Hash
In fact, the above process is elliptic Curve DSA (ECDSA).
Okay, so, how do we use the elliptic signature algorithm in C #?
In. Net3.5, Microsoft provides the Ecdsacng class, but the limitation is that it must be used on the Vista system, and the Microsoft implementation has previously determined the parameters of the elliptic curve (ecdsap256,ecdsap384,ecdsap521), We have no way of using our own parameters. The use of the Ecdsacng class has already been introduced, and is also described on MSDN. What I'm going to say here is how to use a third-party class library.
The third-party cryptographic class library introduced here is Bcccrypto (http://www.bouncycastle.org/csharp/), now the version is 1.4, tested more stable.
Signature
| 0102030405060708091011121314 |
// 生成R=r*G TBCryptoBigInteger r = null; Random random = new SecureRandom(); do // Generate r { r = new TBCryptoBigInteger(this.ecdomainpsCDKey.N.BitLength, random); } while (r.SignValue == 0); ECPoint R = this.ecdomainpsCDKey.G.Multiply(r);// Hash = SHA1(data,Rx,Ry)string hashStr = Sha1(31, rawKeyBytes, R.X.ToBigInteger().ToByteArray(), R.Y.ToBigInteger().ToByteArray());TBCryptoBigInteger hashInt = new TBCryptoBigInteger(hashStr, 2);// sig = r-Hash*D (mod n)TBCryptoBigInteger sig = r.Subtract(hashInt.Multiply(this.ecDCDKey)).Mod(this.ecdomainpsCDKey.N); |
Verify
| 01020304050607080910111213 |
// 验证签名 X9ECParameters ecps = X962NamedCurves.GetByOid(X9ObjectIdentifiers.Prime256v1); ECPublicKeyParameters pk = new ECPublicKeyParameters("ECDSA", ecps.Curve.DecodePoint(Hex.Decode(KeyAttribute.GetKey(type.Assembly))), new ECDomainParameters(ecps.Curve, ecps.G, ecps.N, ecps.H)); ISigner s = SignerUtilities.GetSigner("ECDSA"); s.Init(false, pk); s.BlockUpdate(bytes, 0, dataLen); if (s.VerifySignature(sig)){ this.data = new byte[dataLen]; Array.Copy(bytes, 0, this.data, 0, data.Length);} |
C # uses elliptic signature algorithm to make software serial number