Computing the sum of two points or the double of a point and the coefficients of the corresponding functions is faster with our formulas than with all previ ously proposed formulas for pairings on Edwards curves. They are even competitive with all published formulas for pairing computation on Weierstrass curves. We also improve the formulas for Tate pairing computation on Weierstrass curve s in Jacobian coordinates. Finally, we present several examples of pairing-friendly Edwards curves.
Category / Keywords: public-key cryptography / Pairing, Miller function, explicit formulas, Edwards curves Date: received 3 Apr 2009, last revised 22 May 2010 Contact author: tanja at hyperelliptic org Available format(s): PDF | BibTeX Citation Version: 20100523:014032 (All versions of this report) Short URL: ia.cr/2009/155 Discussion forum: Show discussion | Start new discussion