Accelerating Twisted Ate Pairing with Frobenius Map, Small Scalar Multiplication, and Multi-pairing

نویسندگان

  • Yumi Sakemi
  • Shoichi Takeuchi
  • Yasuyuki Nogami
  • Yoshitaka Morikawa
چکیده

In the case of Barreto-Naehrig pairing-friendly curves of embedding degree 12 of order r, recent efficient Ate pairings such as R-ate, optimal, and Xate pairings achieve Miller loop lengths of (1/4) log2 r . On the other hand, the twisted Ate pairing requires (3/4) log2 r loop iterations, and thus is usually slower than the recent efficient Ate pairings. This paper proposes an improved twisted Ate pairing using Frobenius maps and a small scalar multiplication. The proposal splits the Miller’s algorithm calculation into several independent parts, for which multi-pairing techniques apply efficiently. The maximum number of loop iterations in Miller’s algorithm for the proposed twisted Ate pairing is equal to the (1/4) log2 r attained by the most efficient Ate pairings.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Improvement of Twisted Ate Pairing Using Integer Variable with Small Hamming Weight

Barreto–Naehrig (BN) curve has been introduced as a pairing-friendly elliptic curve over prime field Fp which has embedding degree 12. Characteristic and Frobenius trace are given as polynomials of integer variable χ. This paper proposes an improvement of Miller’s algorithm of twisted Ate pairing with BN curve by χ of small hamming weight. Then, in order to show the efficiency of the proposed m...

متن کامل

Scalar Multiplication on Pairing Friendly Elliptic Curves

Efficient computation of elliptic curve scalar multiplication has been a significant problem since Koblitz [13] and Miller [14] independently proposed elliptic curve cryptography, and several efficient methods of scalar multiplication have been proposed (e.g., [8], [9], [12]). A standard approach for computing scalar multiplication is to use the Frobenius endomorphism. If we compute the s-multi...

متن کامل

Cost Evaluation of The Improvement of Twisted Ate Pairing That Uses Integer Variable χ of Small Hamming Weight

Barreto–Naehrig (BN) curve has been introduced as an efficient pairing-friendly elliptic curve over prime field Fp whose embedding degree is 12. The characteristic and Frobenius trace are given as polynomials of integer variable χ. The authors proposed an improvement of Miller’s algorithm of twisted Ate pairing with BN curve by applying χ of small hamming weight in ITC–CSCC2008; however, its co...

متن کامل

Speeding Up Ate Pairing Computation in Affine Coordinates

At Pairing 2010, Lauter et al’s analysis showed that Ate pairing computation in affine coordinates may be much faster than projective coordinates at high security levels. In this paper, we further investigate techniques to speed up Ate pairing computation in affine coordinates. On the one hand, we improve Ate pairing computation over elliptic curves admitting an even twist by describing an 4-ar...

متن کامل

On Efficient Pairings on Elliptic Curves over Extension Fields

In implementation of elliptic curve cryptography, three kinds of finite fields have been widely studied, i.e. prime field, binary field and optimal extension field. In pairing-based cryptography, however, pairingfriendly curves are usually chosen among ordinary curves over prime fields and supersingular curves over extension fields with small characteristics. In this paper, we study pairings on...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2009