2012
DOI: 10.1090/s0025-5718-2012-02625-1
|View full text |Cite
|
Sign up to set email alerts
|

Squaring in cyclotomic subgroups

Abstract: Abstract. We propose new squaring formulae for cyclotomic subgroups of certain finite fields. Our formulae use a compressed representation of elements having the property that decompression can be performed at a very low cost. The squaring formulae lead to new exponentiation algorithms in cyclotomic subgroups which outperform the fastest previously-known exponentiation algorithms when the exponent has low Hamming weight. Our algorithms can be adapted to accelerate the final exponentiation step of pairing compu… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
21
0

Year Published

2012
2012
2023
2023

Publication Types

Select...
9

Relationship

1
8

Authors

Journals

citations
Cited by 40 publications
(21 citation statements)
references
References 25 publications
0
21
0
Order By: Relevance
“…In [29], it was shown that one can compress g to C(g) = [g 2 , g 3 , g 4 , g 5 ], and the compressed representation of g 2 is computed as C(g 2 ) = [h 2 , h 3 , h 4 , h 5 ], where h i is computed as follows:…”
Section: Computing U-th Powers Inmentioning
confidence: 99%
“…In [29], it was shown that one can compress g to C(g) = [g 2 , g 3 , g 4 , g 5 ], and the compressed representation of g 2 is computed as C(g 2 ) = [h 2 , h 3 , h 4 , h 5 ], where h i is computed as follows:…”
Section: Computing U-th Powers Inmentioning
confidence: 99%
“…It can be shown that exponentiation by our choice of the z parameter requires 107 compressed squarings, simultaneous decompression of 4 field elements, and 3 multiplications in F p 12 when Karabina's exponentiation technique [18] is employed. The cost of an exponentiation by z is 107(6s)+4(3m+ 3s) + 3(3m) +ĩ + 3(18m) = 75m + 654s +ĩ, whence the total cost of the final exponentiation is (23m + 11s +ĩ) + 2(9s) + 12(18m) + 60m 640 + 5(75m + 654s +ĩ) = 614m + 3299s + 6ĩ = 8464m 640 + 6i 640 .…”
Section: Bls12 Pairingsmentioning
confidence: 99%
“…Further, assume that the relative cost of a field multiplication compared to a cyclotomic squaring on F p k is given as M ≈ 4.5S [1,15]. Then, the total cost to perform the exponentiations…”
Section: A Comparison With Scott Et Almentioning
confidence: 99%
“…Using different strategies, that research effort has produced several remarkable algorithm improvements that include: construction of pairingfriendly elliptic curves with prescribed embedding degree [4,8,23], decreases of the Miller loop length [3,13,14,29], and reductions in the associated towering field arithmetic costs [6,11,15,17].…”
Section: Introductionmentioning
confidence: 99%