Using abelian varieties to improve pairing-based cryptography
\) to the same problem in the field \(\mathbb{F}_{q^k}\), where \(k\), called the embedding degree, is the multiplicative order of \(q\) modulo \(l\). Such embedding degree should be neither too small (to avoid MOV-like attacks) nor too large (for computational reasons). For this and other motivations supersingular varieties are usually used in Pairing-Based Cryptography. The paper (Section 4) introduces two new invariants: the cryptographic exponent \(c_{A,q}\) and the security parameter \(\alpha(A,q)\). The authors argue that the cryptographic exponent (a number in \(1/2Z\)) is a better security measure than the embedding degree: theorem 6.3 shows that for an elementary supersingular abelian variety and \(l\) large enough \(\mathbb{F}_{q^{c_{A,q}}}\) is the smallest extension of \(\mathbb{F}_p\) whose multiplicative group contains the \(l-th\)-roots of unity. The security parameter \(\alpha(A,q)=c_{A,q}/\dim(A)\), measures MOV security per bit and allows to compare security among abelian varieties of different dimension. Section 7 determines which values can occur as the security parameters. The results are also collected in Table 1 (Section 1) and show that it is possible to obtain higher MOV security per bit than using supersingular elliptic curves. The authors also discuss (Section 9) the cryptographic security of \textit{primitive} subgroups \(V_{q^r|q}\) of the Weil restriction of scalars. They prove that given a supersingular elliptic curve \(E\) defined over \(\mathbb{F}_q\) and a suitable prime \(r\) there exists an abelian variety \(E_r\) over \(\mathbb{F}_q\) (the \(rth\) primitive subgroup) with security parameter better, by a factor \(r/(r-1)\), than the parameter of \(E\). If \(A_0\) denotes the trace zero subgroup of \(E(\mathbb{F}_{q^r})\) then \(E_r(\mathbb{F}_q)\cong A_0\subseteq E(\mathbb{F}_{q^r})\). Section 10 gives a compression/decompression algorithm for the points of \(A_0\) which compresses by a factor of \(r/(r-1)\). The algorithm is efficient when \(r=3, p\neq 3\) (Section 10.3) and \(r=5, p=3\) (Section 10.4) . Section 12, keeping in mind the results of Table 1, constructs explicit examples of optimal abelian varieties (varieties with the highest \(c_{A,q}\) among abelian varieties of the same dimension) for those dimensions providing the highest MOV security per bit.
- A new proof for the non-degeneracy of the Frey-Rück pairing and a connection to isogenies over the base field
- A Remark Concerning m-Divisibility and the Discrete Logarithm in the Divisor Class Group of Curves
- A study on theoretical and practical aspects of Weil-restrictions of varieties
- Abelian varieties over finite fields
- Advances in Cryptology - CRYPTO 2003
- Adèles and algebraic groups. (Appendix 1: The case of the group \(G_2\), by M. Demazure. Appendix 2: A short survey of subsequent research on Tamagawa numbers, by T. Ono)
- Algorithmic Number Theory
- Compact Group Signatures Without Random Oracles
- Compression in Finite Fields and Torus-Based Cryptography
- Conjunctive, Subset, and Range Queries on Encrypted Data
- Constructive and destructive facets of Weil descent on elliptic curves
- Cyclotomic Polynomials and Factorization Theorems
- Efficient pairing computation on supersingular abelian varieties
- Endomorphisms of Abelian varieties over finite fields
- Fully Collusion Resistant Traitor Tracing with Short Ciphertexts and Private Keys
- Group structures of elementary supersingular abelian varieties over finite fields.
- scientific article; zbMATH DE number 1594291 (Why is no real title available?)
- scientific article; zbMATH DE number 1643939 (Why is no real title available?)
- scientific article; zbMATH DE number 4067040 (Why is no real title available?)
- scientific article; zbMATH DE number 3748927 (Why is no real title available?)
- scientific article; zbMATH DE number 1009708 (Why is no real title available?)
- scientific article; zbMATH DE number 1024494 (Why is no real title available?)
- scientific article; zbMATH DE number 1106523 (Why is no real title available?)
- scientific article; zbMATH DE number 1942430 (Why is no real title available?)
- scientific article; zbMATH DE number 2012338 (Why is no real title available?)
- scientific article; zbMATH DE number 2081083 (Why is no real title available?)
- scientific article; zbMATH DE number 2081084 (Why is no real title available?)
- scientific article; zbMATH DE number 1461531 (Why is no real title available?)
- scientific article; zbMATH DE number 1759768 (Why is no real title available?)
- scientific article; zbMATH DE number 2155360 (Why is no real title available?)
- scientific article; zbMATH DE number 1842494 (Why is no real title available?)
- scientific article; zbMATH DE number 872245 (Why is no real title available?)
- scientific article; zbMATH DE number 3336595 (Why is no real title available?)
- scientific article; zbMATH DE number 3353452 (Why is no real title available?)
- Index calculus for abelian varieties of small dimension and the elliptic curve discrete logarithm problem
- Isogeny classes of abelian varieties over finite fields
- KASH: recent developments
- On the Minimal Embedding Field
- Perfect Non-interactive Zero Knowledge for NP
- Reducing elliptic curve logarithms to logarithms in a finite field
- Short signatures from the Weil pairing
- Supersingular Abelian varieties over finite fields
- The Function Field Sieve in the Medium Prime Case
- The improbability that an elliptic curve has subexponential discrete log problem under the Menezes-Okamoto-Vanstone algorithm
- Theory of Cryptography
- Twisting commutative algebraic groups
- Point compression for the trace zero subgroup over a small degree extension field
- Constructing pairing-friendly hyperelliptic curves using Weil restriction
- Ordinary Abelian varieties having small embedding degree
- Optimal Eta Pairing on Supersingular Genus-2 Binary Hyperelliptic Curves
- Heuristics on pairing-friendly abelian varieties
- A new method for constructing pairing-friendly abelian surfaces
- On the Security of Pairing-Friendly Abelian Varieties over Non-prime Fields
- scientific article; zbMATH DE number 1942430 (Why is no real title available?)
- An optimal representation for the trace zero subgroup
- On cycles of pairing-friendly abelian varieties
- Index calculus in the trace zero variety
This page was built for publication: Using abelian varieties to improve pairing-based cryptography
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q1027984)