Paper 2024/1790
Revisiting subgroup membership testing on pairing-friendly curves via the Tate pairing
Abstract
The two groups $\mathbb{G}_1$ and $\mathbb{G}_2$ on pairing-friendly curves typically have nontrivial cofactors, which may give rise to security vulnerabilities (e.g., small subgroup attacks) in pairing-based protocols. In order to avoid the pitfalls of cofactors, it is necessary to perform subgroup membership testing. Previous testing methods for such curves relied on efficiently computable endomorphisms. In 2023, Koshelev introduced a novel technique of subgroup membership testing for a list of non-pairing-friendly curves, requiring at most two small Tate pairings. In fact, this technique can also be applied to certain pairing-friendly curves, such as those from the BLS and BW13 families. In this paper, we revisit Koshelev's method and propose simplified formulas for computing the two Tate pairings. Compared to the original formulas, ours reduce both the number of Miller's iterations and the storage requirements. Moreover, we provide a high-speed software implementation on a 64-bit processor. Our experimental results show that the new method outperforms the state-of-the-art one by up to $62.0\%$ and $41.2\%$ on for singular $\mathbb{G}_1$ membership testing on the BW13-310 and BLS48-575 curves, respectively. When precomputation is utilized, the improvements increase to $110.6\%$ and $74.4\%$ on the two curves, respectively.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- pairing-friendly curvessubgroup membership testingTate pairing
- Contact author(s)
-
eccdaiy39 @ gmail com
hedebiao @ whu edu cn
dimitri koshelev @ gmail com
cpeng @ whu edu cn
zjyang math @ whu edu cn - History
- 2026-02-23: last of 3 revisions
- 2024-11-02: received
- See all versions
- Short URL
- https://ia.cr/2024/1790
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1790,
author = {Yu Dai and Debiao He and Dimitri Koshelev and Cong Peng and Zhijian Yang},
title = {Revisiting subgroup membership testing on pairing-friendly curves via the Tate pairing},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/1790},
year = {2024},
url = {https://eprint.iacr.org/2024/1790}
}