2005Unpublished venueRequires access

Pairing-Friendly Elliptic Curves of Prime Order.

Paulo S. L. M. Barreto, Michael Naehrig

Open publisher page 104 citations

Abstract

Abstract. Previously known techniques to construct pairing-friendly curves of prime or near-prime order are restricted to embedding degree k � 6. More general methods produce curves over Fp where the bit length of p is often twice as large as that of the order r of the subgroup with embedding degree k; the best published results achieve ρ ≡ log(p) / log(r) ∼ 5/4. In this paper we make the first step towards surpassing these limitations by describing a method to construct elliptic curves of prime order and embedding degree k = 12. The new curves lead to very efficient implementation: non-pairing operations need no more than Fp4 arithmetic, and pairing values can be compressed to one third of their length in a way compatible with point reduction techniques. We also discuss the role of large CM discriminants D to minimize ρ; in particular, for embedding degree k = 2q where q is prime we show that the ability to handle log(D) / log(r) ∼ (q − 3)/(q − 1) enables building curves with ρ ∼ q/(q − 1).

About this research paper

What this paper is about

Abstract. Previously known techniques to construct pairing-friendly curves of prime or near-prime order are restricted to embedding degree k � 6. More general methods produce curves over Fp where the bit length of p is often twice as large as that of the order r of the subgroup with embedding degree k; the best published results achieve ρ ≡ log(p) / log(r) ∼ 5/4. In this paper we make the first step towards surpassing these limitations by describing a method to construct elliptic curves of prime order and embedding degree k = 12. The new curves lead to very efficient implementation: non-pairing operations need no more than Fp4 arithmetic, and pairing values can be compressed to one third of their length in a way compatible with point reduction techniques. We also discuss the role of large CM discriminants D to minimize ρ; in particular, for embedding degree k = 2q where q is prime we show that the ability to handle log(D) / log(r) ∼ (q − 3)/(q − 1) enables building curves with ρ ∼ q/(q − 1).

Why it matters

OpenAlex reports 104 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Abstract. Previously known techniques to construct pairing-friendly curves of prime or near-prime order are restricted to embedding degree k � 6. More general methods produce curves over Fp where the bit length of p is often twice as large as that of the order r of the subgroup with embedding degree k; the best published results achieve ρ ≡ log(p) / log(r) ∼ 5/4. In this paper we make the first step towards surpassing these limitations by describing a method to construct elliptic curves of prime order and embedding degree k = 12. The new curves lead to very efficient implementation: non-pairing operations need no more than Fp4 arithmetic, and pairing values can be compressed to one third of their length in a way compatible with point reduction techniques. We also discuss the role of large CM discriminants D to minimize ρ; in particular, for embedding degree k = 2q where q is prime we show that the ability to handle log(D) / log(r) ∼ (q − 3)/(q − 1) enables building curves with ρ ∼ q/(q − 1).

Key concepts: Degree (music), Embedding, Prime (order theory), Pairing, Elliptic curve, Order (exchange), Construct (python library), Mathematics

Related papers

Back to paper searchBrowse research topicsOriginal source
Pairing-Friendly Elliptic Curves of Prime Order. — Research Paper | ScholarLens