Download the PHP package famoser/elliptic without Composer
On this page you can find all versions of the php package famoser/elliptic. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download famoser/elliptic
More information about famoser/elliptic
Files in famoser/elliptic
Package elliptic
Short Description PHP Elliptic Curve Cryptography library
License MIT
Homepage https://github.com/famoser/elliptic
Informations about the package elliptic
Elliptic: Low-level Elliptic Curve Library
This library provides low-level access to elliptic curve group computations. Extensively tested (100% branch coverage, 9k third-party integration tests) and hardened against side-channels.
Functionality overview:
- Curves: Use
SEC2,brainpooland the bernstein curves (curve25519andcurve448). - Math: Operate on the curves using
add,doubleandmul. - Decoders: Decode according to SEC or bernstein. Recover points given only an x or y coordinate.
Compared to the popular paragonie/phpecc, this library focuses on the math on the elliptic curves directly, and does not implement any cryptographic primitives.
For this task, this library is around 100x [sic!] faster, while not performing significantly worse in terms of side-channels.
Math overview
There are two types of math:
- Unsafe implementations (
$repository->createUnsafeMath($curve)): Simply implement the addition and double formulas for the given curve type ($repository->createUnsafeMath($curve)). - Hardened implementations (
$repository->createHardenedMath($curve)): Follow specifications and RFCs that notably aim to reduce the effectiveness of side-channels (side-channels may allow an adversary to recover the input to the algorithms, e.g. private key material, by observing the environment, e.g. time and power usage of the CPU).
All curves, except the secp*k1 and the brainpool*r1 variants, have hardened implementations available. Unless you have a good reason, you should use these hardened implementations.
| Hardened Math | Supported Curves | Correctness | Hardened | Runtime |
|---|---|---|---|---|
SW_ANeg3_Math |
secp*r1, brainpool*t1 |
:white_check_mark: | :warning::warning: | 4 |
SW_QT_ANeg3_Math |
brainpool*r1 |
:white_check_mark: | :warning::warning: | 4 |
MGXCalculator (mul only) |
curve25519, curve448 |
:white_check_mark: | :warning::warning::warning: | 1 |
MG_TwED_ANeg1_Math |
curve25519 |
:white_check_mark: | :warning: | 2.5 |
TwED_ANeg1_Math |
edwards25519 |
:white_check_mark: | :grey_question: | 2.5 |
EDMath |
edwards448, curve448Edwards |
:white_check_mark: | :grey_question: | 2 |
MG_ED_Math |
curve448 |
:x: | :grey_question: | 2 |
Correctness:
MG_ED_Mathperforms incorrectly in relation to baselines (e.g., third party testcases). It should not be used.
Hardened:
- No implementation can be shown constant-time, and other side-channels are not quantitively assessed.
- Implementations finish faster with adversarial input (points and factors close to 0) vs random input. This is due to GMP, the underlying library used for large number math, and cannot be fixed.
- Unsafe maths show 50% variance in execution time, hardened math between 3% (
MG_TwED_ANeg1_Math) and 15% (MGXCalculator)
Runtime:
- Denoted is execution time of mul in some unit; hence lower is better.
MGXCalculatorperforms best, but is no full math implementation (nodouble, noadd).- The unsafe variants of SW are 2x faster, the unsafe variant of MG is 1.5x faster.
Project context
This library is part of a larger effort:
- Provide low-level library that executes math on elliptic curves (this project)
- Provide elliptic-crypto library which exposes general cryptographic primitives (signatures, encryptions and zero-knowledge proofs) (in development here)
- Provide more specialized libraries for more exotic cryptographic primitives (verifiable shuffle) (in development here)
All versions of elliptic with dependencies
ext-gmp Version *