Faster computation of the Tate pairing
The paper proposes some improvements in the computation of the Tate pairing on elliptic curves \(E\),\, both in Weierstrass form and in Edwards form, curves defined over a non-binary finite field \(F_q\)\, and with even embedding degree (for a prime \(n|\sharp(E)\)\, the embedding degree \(k\),\, with respect to \(n\),\, is the multiplicative degree of \(q\)\, modulo \(n\)). For \(E\)\, in Weierstrass form, Miller's algorithm computes efficiently the Tate pairing, using the chord-and-tangent method for the addition and doubling of points. Section 3 presents new formulas for the addition and doubling steps in Miller's algorithm. Those formulas use a representation of the points of \(E\)\, in Jacobian coordinates \((X:Y:Z:T)\), \(T^2=Z\), and the paper gives its cost in term of the costs \(m,s,M,S\) of multiplication and squaring in \(\mathbb F_q\) and \(\mathbb F_{q^k}\). A twisted Edwards curve, introduced by \textit{D. J. Bernstein} et al. [in: AFRICACRYPT 2008. Casablanca, Morocco, 2008. Lect. Notes Comput. Sci. 5023, 389--405 (2008; Zbl 1142.94332)], is a curve giving by an equation: \(E_{\text{ad}}: ax^2+y^2=1+dx^2y^2\), whose (affine) points have efficient addition formulas. Since the equation of \(E_{\text{ad}}\) has degree four the chord-and-tangent geometric interpretation of the addition is not more valid, but section 4 of the paper gives (theorem 2) a new geometric interpretation of the addition law for \(E_{\text{ad}}\), and with this tool section 5 shows how to compute Tate pairing on twisted Edwards curves. Section 6 gives the comparison of the proposed formulas with others in the literature, as the paper of \textit{S. Ionica} and \textit{A. Joux} [in: INDOCRYPT 2008. Kharagpur, India, 2008. Lect. Notes Comput. Sci. 5365, 400--413 (2008; Zbl 1203.94104)], concluding that `` ... our new formulas for Edwards curves solidly beat all previous formulas published for Tate computation on Edwards curves and `` Our new formulas for pairings on arbitrary Edwards curves are faster than all formulas previously known for Weierstrass curves except for the very special curves with \(a_4=0\).. Finally, sections 7 and 8 present construction and numerical examples (with embedding degree \(k=6,8,10,22\)) of pairing-friendly Edwards curves, examples covering the most common security levels.
- Fast Tate pairing computation on twisted Jacobi intersections curves
- Information Security and Privacy
- scientific article; zbMATH DE number 1950619
- Topics in Cryptology – CT-RSA 2005
- Efficient Tate pairing computation using double-base chains
- Efficient Computation of Tate Pairing in Projective Coordinate over General Characteristic Fields
- Efficient Algorithm for Tate Pairing of Composite Order
- Faster Ate pairing computation on Selmer's model of elliptic curves
- Faster pairing computation on genus 2 hyperelliptic curves
- A normal form for elliptic curves
- A taxonomy of pairing-friendly elliptic curves
- Advances in cryptology - CRYPTO 2002. 22nd annual international cryptology conference, Santa Barbara, CA, USA, August 18--22, 2002. Proceedings
- Advances in cryptology -- ASIACRYPT 2007. 13th international conference on the theory and application of cryptology and information security, Kuching, Malaysia, December 2-6, 2007. Proceedings
- Advances in cryptology -- ASIACRYPT 2008. 14th international conference on the theory and application of cryptology and information security, Melbourne, Australia, December 7--11, 2008. Proceedings
- Another Approach to Pairing Computation in Edwards Coordinates
- Efficient Computation of Tate Pairing in Projective Coordinate over General Characteristic Fields
- Efficient implementation of pairing-based cryptosystems
- Faster Addition and Doubling on Elliptic Curves
- Faster pairing computations on curves with high-degree twists
- Handbook of Elliptic and Hyperelliptic Curve Cryptography
- scientific article; zbMATH DE number 5532069 (Why is no real title available?)
- scientific article; zbMATH DE number 3937328 (Why is no real title available?)
- scientific article; zbMATH DE number 1942431 (Why is no real title available?)
- scientific article; zbMATH DE number 5493294 (Why is no real title available?)
- scientific article; zbMATH DE number 3288410 (Why is no real title available?)
- scientific article; zbMATH DE number 2231488 (Why is no real title available?)
- Information security and cryptology -- ICISC 2004. 7th international conference, Seoul, Korea, December 2--3, 2004. Revised Selected Papers
- Ordinary Abelian varieties having small embedding degree
- Pairing Computation on Twisted Edwards Form Elliptic Curves
- Pairing-based cryptography -- Pairing 2008. Second international conference, Egham, UK, September 1--3, 2008. Proceedings
- Pairing-based cryptography -- Pairing 2009. Third international conference Palo Alto, CA, USA, August 12--14, 2009. Proceedings
- Pairing-Friendly Elliptic Curves of Prime Order
- Progress in cryptology -- AFRICACRYPT 2008. First international conference on cryptology in Africa, Casablanca, Morocco, June 11--14, 2008. Proceedings
- Progress in cryptology -- INDOCRYPT 2008. 9th international conference on cryptology in India, Kharagpur, India, December 14--17, 2008. Proceedings
- Public key cryptography -- PKC 2010. 13th international conference on practice and theory in public key cryptography, Paris, France, May 26--28, 2010. Proceedings
- Selected areas in cryptography. 12th international workshop, SAC 2005, Kingston, ON, Canada, August 11--12, 2005. Revised selected papers.
- The Weil pairing, and its efficient calculation
- Twisted Edwards Curves
- Identity-based undetachable digital signature for mobile agents in electronic commerce
- Parallelizing pairings on Hessian elliptic curves
- Pairing-friendly twisted Hessian curves
- An optimal Tate pairing computation using Jacobi quartic elliptic curves
- A short-list of pairing-friendly curves resistant to special TNFS at the 128-bit security level
- A complete set of addition laws for incomplete Edwards curves
- On the near prime-order MNT curves
- Compression for trace zero points on twisted Edwards curves
- Deterministic encoding into twisted Edwards curves
- Faster Ate pairing computation on Selmer's model of elliptic curves
- Fast simplifications for Tarski formulas
- Twisted Hessian curves
- Improved sieving on algebraic curves
- On near prime-order elliptic curves with small embedding degrees
- Another elliptic curve model for faster pairing computation
- Further refinements of Miller's algorithm on Edwards curves
- An analysis of affine coordinates for pairing computation
- Efficient pairing computation on elliptic curves in Hessian form
- Efficient Pairing Computation on Ordinary Elliptic Curves of Embedding Degree 1 and 2
- The pairing computation on binary Edwards curves
- Efficient Algorithm for Tate Pairing of Composite Order
- Faster Pairings on Special Weierstrass Curves
- Pairing computation on Edwards curves with high-degree twists
- Faster pairing computations on curves with high-degree twists
- Pairing Computation on Twisted Edwards Form Elliptic Curves
- The pairing computation on Edwards curves
- Mean value formulas for twisted Edwards curves
- Fast Tate pairing computation on twisted Jacobi intersections curves
- Tate pairing computation on Jacobi's elliptic curves
- Efficient self-pairing on ordinary elliptic curves
- Speeding up Ate pairing computation in affine coordinates
- Elliptic curves in Huff’s model
- Huff's model for elliptic curves
- Efficient pairing computation with theta functions
- Formal Proof of the Group Law for Edwards Elliptic Curves
- Refinement of Miller's algorithm over Edwards curves
- Tate pairing computation on generalized Hessian curves
- Encapsulated Scalar Multiplications and Line Functions in the Computation of Tate Pairing
- Another Approach to Pairing Computation in Edwards Coordinates
- scientific article; zbMATH DE number 962546 (Why is no real title available?)
- scientific article; zbMATH DE number 7746256 (Why is no real title available?)
- Optimized and Secure Pairing-Friendly Elliptic Curves Suitable for One Layer Proof Composition
- Fuzzy perspective of online games by using cryptography and cooperative game theory
- Exp function for Edwards curves over local fields
- A generalisation of Miller's algorithm and applications to pairing computations on abelian varieties
This page was built for publication: Faster computation of the Tate pairing
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q2430985)