On a Relation between the Ate Pairing and the Weil Pairing for Supersingular Elliptic Curves

Takakazu Satoh

Abstract: The hyperelliptic curve Ate pairing provides an efficient way to compute a bilinear pairing on the Jacobian variety of a hyperelliptic curve. We prove that, for supersingular elliptic curves with embedding degree two, square of the Ate pairing is nothing but the Weil pairing. Using the formula, we develop an X-coordinate only pairing inversion method. However, the algorithm is still infeasible for cryptographic size problems.

Category / Keywords: public-key cryptography / Ate pairing, Weil pairing

Date: received 25 Aug 2013, last revised 1 Oct 2013

Note: Introduction: some changes for clarification. Theorem 2.1(ii): vanishing of linear terms is added Lemma 4.4(ii): the statement is corrected. Conjecture on (5.3): an obvious necessary condition is added.

