A comparison of MNT curves and supersingular curves

D. Page and N.P. Smart and F. Vercauteren

Abstract: We compare both the security and performance issues related to the choice of MNT curves against supersingular curves in characteristic three, for pairing based systems. We pay particular attention to equating the relevant security levels and comparing not only computational performance and bandwidth performance. The paper focuses on the BLS signature scheme and the Boneh--Franklin encryption scheme, but a similar analysis can be applied to many other pairing based schemes.

Date: received 12 Jul 2004, last revised 25 Oct 2005

