2009
DOI: 10.1109/tit.2009.2013048
|View full text |Cite
|
Sign up to set email alerts
|

Efficient and Generalized Pairing Computation on Abelian Varieties

Abstract: In this paper, we propose a new method for constructing a bilinear pairing over (hyper)elliptic curves, which we call the R-ate pairing. This pairing is a generalization of the Ate and Ate i pairing, and also improves efficiency of the pairing computation. Using the R-ate pairing, the loop length in Miller's algorithm can be as small as log(r 1/φ(k) ) for some pairing-friendly elliptic curves which have not reached this lower bound. Therefore we obtain from 29% to 69% savings in overall costs compared to the A… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
100
0
8

Year Published

2009
2009
2022
2022

Publication Types

Select...
8
1

Relationship

0
9

Authors

Journals

citations
Cited by 137 publications
(108 citation statements)
references
References 21 publications
0
100
0
8
Order By: Relevance
“…Several papers have proposed methods for loop shortening [30,32,43,42,25]. For example, for the twisted ate pairing one can replace T e by any of its powers modulo r and choose the smallest of those.…”
Section: Background On Pairingsmentioning
confidence: 99%
See 1 more Smart Citation
“…Several papers have proposed methods for loop shortening [30,32,43,42,25]. For example, for the twisted ate pairing one can replace T e by any of its powers modulo r and choose the smallest of those.…”
Section: Background On Pairingsmentioning
confidence: 99%
“…For example, for the twisted ate pairing one can replace T e by any of its powers modulo r and choose the smallest of those. A good choice for the ate pairing is to use the R-ate pairing [30], which often achieves an optimal loop length of log(r)/ϕ(k), yielding an optimal pairing [42].…”
Section: Background On Pairingsmentioning
confidence: 99%
“…In practise, pairings are typically instantiated using an elliptic or a hyperelliptic curve over a finite field, via the Weil or Tate pairing (see [7]) -or a variant of the latter such as the ate [19], or R-ate pairing [25]. These pairings map pairs of points on such curves to elements of a subgroup of the multiplicative group of an extension field, which is contained in the so-called cyclotomic subgroup.…”
Section: Introductionmentioning
confidence: 99%
“…For maximum efficiency P and Q are drawn from the groups G 1 of points on E(F p ) and G 2 , a group of points on the twisted curve E (F p d ) where d divides the embedding degree k. For the Tate pairing the first parameter P is chosen from G 1 and the second Q from G 2 . However recent discoveries of the faster ate [9] and R-ate [11] pairings require P to be chosen from G 2 and Q from G 1 . In either case P must be of prime order r, where k, the embedding degree, is the smallest integer for which r|Φ k (t−1) [2], where Φ k (.)…”
Section: Introductionmentioning
confidence: 99%