Paper 2026/1522
Efficient Ternary Computation of Optimal Ate Pairing on BLS27 Curves
Abstract
The computation of optimal Ate pairings on elliptic curves with embedding degree $k=27$ (BLS27) is highly relevant for achieving the 256-bit security level, especially in the context of recent advances in the Number Field Sieve (NFS) and its variants (exTNFS, SexTNFS). Traditional binary approaches fail to fully exploit the degree-3 extension tower of $\Fpk{27}$. In this work, we propose an efficient ternary version of the Miller loop, restricting the seed representation to sparse ternary digits $\{0, 1\}$ to streamline point operations and eliminate costly inversions. Furthermore, we generate two new parameter seeds tailored for exTNFS and SexTNFS security levels. These seeds feature sparse ternary representations that simultaneously guarantee the efficiency of the Miller loop and allow the full exploitation of cyclotomic cubing in $\mathbb{F}_{p^{27}}$ during the hard part of the final exponentiation. Compared to the state of the art binary approach by Fouotsa et al. (2020), our exTNFS seed yields a $22\%$ improvement in the overall optimal Ate pairing computation cost. Concurrently, our proposed SexTNFS seed ensures a higher level of security against the most advanced NFS variants.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Optimal Ate pairingBLS27 curvesTernary Miller algorithmCyclotomic cubingFinal exponentiationexTNFSSexTNFS.
- Contact author(s)
- haddajiwalid95 @ gmail com
- History
- 2026-07-27: approved
- 2026-07-24: received
- See all versions
- Short URL
- https://ia.cr/2026/1522
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1522,
author = {Walid Haddaji},
title = {Efficient Ternary Computation of Optimal Ate Pairing on {BLS27} Curves},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1522},
year = {2026},
url = {https://eprint.iacr.org/2026/1522}
}