1. the powerful device learns nothing about the points being paired (A and B), nor about the pairing’s result e(A,B), 2. and the limited device is able to detect when the powerful device is cheating.
We also describe more efficient variants of our protocol when one of the points or both are already known, and further efficiency gains when constant points are used.
Category / Keywords: cryptographic protocols / Pairings, Smartcards Date: received 24 May 2005, last revised 26 May 2005 Contact author: noel mccullagh at computing dcu ie Available format(s): Postscript (PS) | Compressed Postscript (PS.GZ) | PDF | BibTeX Citation Version: 20050526:075019 (All versions of this report) Short URL: ia.cr/2005/150 Discussion forum: Show discussion | Start new discussion