2411077_en-US

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

2411077_en-US

2411077_en-US

ECDA signature verification with CASPER
Spoiler
 

Hello,
I managed to build mbedTLS on my own, in order to verify a signature with ECDSA (MBEDTLS_ECP_DP_SECP256R1).
With no alt implementation (all computation done by the CPU), the signature verification takes up to 4 seconds to compute on the LPC55S06.

I'm trying now to link mbedTLS ecdsa_verify() function with CASPER fsl driver. But it's not clear to me as the ECDSA verification doens't seem to be a single operation. 
How to link the basic primitive of CAPSER (SECP256R1_Mul & SECP256R1_MulAdd) with the mbedTLS function ECDSA_verify() ?

Thank you in advance for your replie.

LPC55xxRe: ECDA signature verification with CASPER

Hello peter89jean,

Thank you for your reply. The approach you mention is what I had in mind but there doesn't seem to be simple and straightforward SECP256R1_MULADD_ALT or SECP256R1_MUL_ALT defines in the mbedTLS config file. Maybe I should ask this question to a more mbdedTLS dedicated forum. 

Thanks again.

Regards.

Re: ECDA signature verification with CASPER

You generally don’t need to replace mbedtls_ecdsa_verify() itself; the CASPER acceleration should be integrated at the elliptic-curve/multiplication layer that mbedTLS uses internally. ECDSA verification requires computing scalar multiplications and their sum, so SECP256R1_Mul() can handle the individual scalar-point multiplication while SECP256R1_MulAdd() can accelerate the combined operation. The exact integration depends on your mbedTLS version and NXP CASPER driver API, but the usual approach is to provide an mbedTLS alternative/optimized implementation for the P-256 scalar-multiplication primitives rather than calling CASPER directly from ecdsa_verify().

回复: ECDA signature verification with CASPER

Hi @s_hdl 

ECDSA verification consists of several arithmetic and elliptic-curve operations, so it does not map to a single CASPER primitive.

In the MCUXpresso SDK, the integration is already implemented in the CASPER PSA Crypto port. The casper_mbedtls_ecdsa_verify() function performs the standard ECDSA verification flow, including the calculation of u1 and u2. It then calls:

casper_mbedtls_ecp_muladd(grp, &R, u1, &grp->G, u2, Q);
to calculate:
R = u1 × G + u2 × Q

The ECP adaptation layer converts the mbedTLS MPI values and elliptic-curve points into the format required by CASPER and maps this operation to CASPER_ECC_SECP256R1_MulAdd().

Similarly, casper_mbedtls_ecp_mul() maps a single scalar multiplication to CASPER_ECC_SECP256R1_Mul().

Therefore, rather than modifying mbedtls_ecdsa_verify() directly, we recommend reusing the complete CASPER integration provided by the SDK under:

component/psa_crypto_driver/casper_driver
In particular, please refer to:
mcux_psa_casper_ecdsa_port.c
mcux_psa_casper_ecp_port.c

Since you built mbedTLS separately, please also make sure that your mbedTLS version is compatible with the MCUXpresso SDK CASPER port.

You can refer to the lpcxpresso55s06_psa_crypto_examples.

Harry_Zhang_0-1788493275769.pngHarry_Zhang_0-1788493275769.pngHarry_Zhang_0-1788493275769.pngHarry_Zhang_0-1788493275769.png

BR

Harry

回复: ECDA signature verification with CASPER

Hello Harry,

Your answer helped me a lot, thank you. Everything works fine using the CASPER implementation now.


Regards.

タグ(1)
評価なし
バージョン履歴
最終更新日:
土曜日
更新者: