Paper 2024/1627
Cycles of supersingular elliptic curves for pairing-based proof systems
Abstract
We give new constructions of cycles of pairing-friendly elliptic curves with a view towards unbounded recursive pairing-based proof systems. Unlike the only known prior cycle of elliptic curves - the ordinary MNT cycle - our construction uses elliptic curves that are supersingular. A trade-off of our approach is that the supersingular cycles are defined over extension fields (quadratic extensions in the optimal case), which makes elements and computations in $\mathbb{G}_1$ less compact and efficient than those in the MNT cycle. On the other hand, the supersingular cycles in this paper offer a key advantage over their MNT counterpart: every instance of our infinite family of supersingular curves can be efficiently constructed via Broker's algorithm, whereas it is only feasible to construct a relatively small, bounded number of MNT instances via the CM method. In other words, while both constructions give infinite families of pairing-friendly curves in theory, only the supersingular construction gives rise to infinite numbers of cycles that can be realised in practice. Supersingular cycles offer benefits that are relevant in the context of recursive pairing-based proof systems. They afford flexibility in the choices of underlying finite fields; one can choose primes $p$ for which the underlying field arithmetic is efficient and for which $p-1$ is divisible by a large power of 2. Or, as we study in detail, using supersingular cycles unlocks the possibility of connecting the cycle with other pairing-friendly elliptic curves that are defined over much smaller finite fields, where proof system arithmetic is much more efficient. Indeed, constructing these so-called lollipops of pairing-friendly curves was the motivating problem (posed by researchers back in 2019) that inspired the present work.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- Published by the IACR in CIC 2026
- Keywords
- Proof systemsCompositionPairing-friendly cyclesMNT curves
- Contact author(s)
-
craig costello @ qut edu au
gkorpal @ arizona edu - History
- 2025-12-11: last of 3 revisions
- 2024-10-10: received
- See all versions
- Short URL
- https://ia.cr/2024/1627
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1627,
author = {Craig Costello and Gaurish Korpal},
title = {Cycles of supersingular elliptic curves for pairing-based proof systems},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/1627},
year = {2024},
url = {https://eprint.iacr.org/2024/1627}
}