Self-pairings on supersingular elliptic curves with embedding degree \textit{three}
The present paper provides (Theorem 1) a simple and efficient formula to compute self-pairing (i.e. computing \(e(P,P)\),\, \(e\)\, a given pairing) on supersingular elliptic curves with embedding degree \(k=3\).NEWLINENEWLINESection 2 remembers the basic concepts on pairings and supersingular elliptic curves with embedding degree three. These curves are defined over a finite field \(\mathbb{F}_{p^2}\)\, (or more generally \(\mathbb{F}_{p^{2m}}\)), for \(p\)\, a prime, \(p\equiv 2 \bmod 3\), see [\textit{E. R. Verheul}, Lect. Notes Comput. Sci. 2045, 195--210 (2001; Zbl 0981.94009)]. Section 3 states and proves Theorem 1, which provides the wanted formula for the self-pairing. The authors stress that in that formula the exponentiation step \` \` has a simple expression in terms of \(p\) and that \` \` the parameter \(T_1\)\, is optimal in efficiency.NEWLINENEWLINEFinally Section 4 discusses the efficiency of the different self-pairings on supersingular curves with \(k=3\) and compares the efficiency of self-pairings on elliptic curves with embedding degree \(k=2\)\, and \(k=3\),\, for elliptic curves over finite fields of large characteristic at the 128-bit security level (Table 1).
- Fast symmetric pairing revisited
- Constructing symmetric pairings over supersingular elliptic curves with embedding degree three
- Efficient self-pairing on ordinary elliptic curves
- Faster Pairings on Special Weierstrass Curves
- Faster and lower memory scalar multiplication on supersingular curves in characteristic three
- Pairing Calculation on Supersingular Genus 2 Curves
- Efficient pairing computation on supersingular abelian varieties
- Faster explicit formulae for computing pairings via elliptic nets and their parallel computation
- A new signature scheme without random oracles from bilinear pairings
- A taxonomy of pairing-friendly elliptic curves
- A variant of Miller's formula and algorithm
- Advances in Cryptology - ASIACRYPT 2003
- An Analysis of the Vector Decomposition Problem
- Ate Pairing on Hyperelliptic Curves
- Computing bilinear pairings on elliptic curves with automorphisms
- Cover and decomposition index calculus on elliptic curves made practical. Application to a previously unreachable curve over \(\mathbb{F}_{p^6}\)
- Cryptography and Coding
- Efficient and Generalized Pairing Computation on Abelian Varieties
- Efficient pairing computation on supersingular abelian varieties
- Fast symmetric pairing revisited
- Faster Computation of Self-Pairings
- scientific article; zbMATH DE number 1722679 (Why is no real title available?)
- scientific article; zbMATH DE number 1349933 (Why is no real title available?)
- scientific article; zbMATH DE number 1942431 (Why is no real title available?)
- scientific article; zbMATH DE number 3303655 (Why is no real title available?)
- On the function field sieve and the impact of higher splitting probabilities. Application to discrete logarithms in \(\mathbb{F}_{2^{1971}}\) and \(\mathbb{F}_{2^{3164}}\)
- Optimal Pairings
- Pairing Lattices
- Pairings on Hyperelliptic Curves with a Real Model
- Selected Areas in Cryptography
- Self-pairings on hyperelliptic curves
- The Eta Pairing Revisited
- The improbability that an elliptic curve has subexponential discrete log problem under the Menezes-Okamoto-Vanstone algorithm
- The Magma algebra system. I: The user language
- The Weil pairing and the Hilbert symbol
- The Weil pairing, and its efficient calculation
- Weakness of \(\mathbb{F}_{3^{6 \cdot 1429}}\) and \(\mathbb{F}_{2^{4 \cdot 3041}}\) for discrete logarithm cryptography
This page was built for publication: Self-pairings on supersingular elliptic curves with embedding degree \textit{three}
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q402545)