Paper 2026/1884
Corrigendum to: Computing Optimal Ate Pairings on Elliptic Curves with Embedding Degree 9, 15 and 27
Abstract
We correct two errors in Section~8 of the above-mentioned paper concerning the seed parameters proposed for BLS27 elliptic curves (embedding degree $k=27$) at the $256$-bit and $192$-bit security levels. In both instances, the disclosed seeds produce a composite $r(x)$, violating the primality condition essential for constructing pairing-friendly curves. Additionally, for the $192$-bit seed the characteristic $p(x)$ is also composite. We provide verified corrected seeds for each security level, obtained by exhaustive search, and confirm with SageMath that both $p(x)$ and $r(x)$ are prime in each case. All other results of the original paper remain valid.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- Preprint.
- Keywords
- BLS27 curvespairing friendly curvesbilinear pairingsseed correctionSageMath.
- Contact author(s)
- haddajiwalid95 @ gmail com
- History
- 2026-09-07: approved
- 2026-09-03: received
- See all versions
- Short URL
- https://ia.cr/2026/1884
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1884,
author = {Walid Haddaji},
title = {Corrigendum to: Computing Optimal Ate Pairings on Elliptic Curves with Embedding Degree 9, 15 and 27},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1884},
year = {2026},
url = {https://eprint.iacr.org/2026/1884}
}