On a Relation between the Ate Pairing and the Weil Pairing for Supersingular Elliptic Curves

Takakazu Satoh

Abstract: The hyperelliptic curve Ate pairing provides an efficient way to compute a bilinear pairing on the Jacobian variety of a hyperelliptic curve. We prove that, for supersingular elliptic curves with embedding degree two, square of the Ate pairing is nothing but the Weil pairing. Using the formula, we develop an X-coordinate only pairing inversion method. However, the algorithm is still infeasible for cryptographic size problems.

Category / Keywords: public-key cryptography / Ate pairing, Weil pairing

Date: received 25 Aug 2013, last revised 6 Apr 2019

Contact author: satoh df603 at gmail com

Note: Errors in Lemma 3.2, Lemma 4.1 and Theorem 4.3 are corrected. Statements of main results are not affected.

