Optimal Pairings
Fréderik Vercauteren
Abstract
Open-access reader
Fréderik Vercauteren
Abstract
Open-access reader
In this paper, we introduce the concept of an optimal pairing, which by definition can be computed using onlylog2r/¿(k) basic Miller iterations, withrthe order of the groups involved andkthe embedding degree. We describe an algorithm to construct optimal ate pairings on all parametrized families of pairing friendly elliptic curves. Finally, we conjecture that any nondegenerate pairing on an elliptic curve without efficiently computable endomorphisms different from powers of Frobenius requires at leastlog2r/¿(k) basic Miller iterations.
OpenAlex reports 335 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In this paper, we introduce the concept of an optimal pairing, which by definition can be computed using onlylog2r/¿(k) basic Miller iterations, withrthe order of the groups involved andkthe embedding degree. We describe an algorithm to construct optimal ate pairings on all parametrized families of pairing friendly elliptic curves. Finally, we conjecture that any nondegenerate pairing on an elliptic curve without efficiently computable endomorphisms different from powers of Frobenius requires at leastlog2r/¿(k) basic Miller iterations.
Key concepts: Conjecture, Computer science, Algorithm, Combinatorics, Mathematics