13 Solutions for Selected Exercises
259
p=113; a=0; b=7; G=[15,52]; n=19; % elliptic curve
P=[93,16];
% Alice’s public point
r=66; s=11;
% signature
m=’YES’;
% message
nm=double(m);
% numeric form
h=bitxor(nm(3),bitxor(nm(2),nm(1))); % hash
sinv=powermod(s,n-2,n);
% 1/s
hs=powermod(h*sinv,1,n);
% h/s
rs=powermod(r*sinv,1,n);
% r/s
Q1=G; for j=2:hs, Q1=ECadd_p(Q1,G,a,b,p); end % (h/s)*G
Q2=P; for j=2:rs, Q2=ECadd_p(Q2,P,a,b,p); end % (r/s)*P
Q=ECadd_p(Q1,Q2,a,b,p)
% (h/s)*G+(r/s)*P
Alice’s script ex12_8a.m to sign the message and Bob’s script ex12_8b.m to
validate it are available in the ESM.
Exercise 12.9
Just before (12.41) the operation of the operator U on the state |x
k
(mod N ) is defined
as U |x
k
(mod N ) = |x
k+1
(mod N ), such that we find
U |u s =
1
√
r
r −1
k=0
e
−2πiks/r
|x
k+1
(mod N )
= e
2πis/r 1
√
r
r −1
k=0
e
−2πi(k+1)s/r
|x
k+1
(mod N )
(13.79)
= e
2πis/r 1
√
r
r
k =1
e
−2πik
s/r
|x
k
(mod N )
= e
2πis/r
|u s .
In the last step we realize that the sum over k
still extends over all the r element of
the set that successive x
k cycle through. Only the starting point is a different element.
As a matter of fact, the element with k
= r is the same as that with k = 0. Therefore
the sum still describes |u s .
Précédent

- 266/292

Suivant