Paper 2011/040

Simple and Exact Formula for Minimum Loop Length in Ate_i Pairing based on Brezing-Weng Curves

Hoon Hong, Eunjeong Lee, Hyang-Sook Lee, and Cheol-Min Park

Abstract

We provide a simple and exact formula for the minimum Miller loop length in Ate_i pairing based on Brezing-Weng curves, in terms of the involved parameters, under a mild condition on the parameters. It will be also shown that almost all cryptographically useful parameters satisfy the mild condition. Hence the simple and exact formula is valid for them. It will also turn out that the formula depends only on two parameters, providing freedom to choose the other parameters to address the design issues other than minimizing the loop length.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Unknown where it was published
Keywords
elliptic curve cryptosystempairingnumber theory
Contact author(s)
ejlee127 @ ewha ac kr
History
2011-01-21: received
Short URL
https://ia.cr/2011/040
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2011/040,
      author = {Hoon Hong and Eunjeong Lee and Hyang-Sook Lee and Cheol-Min Park},
      title = {Simple and Exact Formula for Minimum Loop Length  in Ate_i  Pairing based on Brezing-Weng Curves},
      howpublished = {Cryptology ePrint Archive, Paper 2011/040},
      year = {2011},
      note = {\url{https://eprint.iacr.org/2011/040}},
      url = {https://eprint.iacr.org/2011/040}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.