SearcharxivSearch

arXiv · 2002.11920

Optimal Ate Pairing on Elliptic Curves with Embedding Degree $9,15$ and $27$

Abstract

Much attention has been given to the efficient computation of pairings on elliptic curves with even embedding degree since the advent of pairing-based cryptography. The few existing works in the case of odd embedding degrees require some improvements. This paper considers the computation of optimal ate pairings on elliptic curves of embedding degrees $k=9$, $15$, $27$ which have twists of order three. Our main goal is to provide a detailed arithmetic and cost estimation of operations in the tower extensions field of the corresponding extension fields. A good selection of parameters enables us to improve the theoretical cost for the Miller step and the final exponentiation using the lattice-based method as compared to the previous few works that exist in these cases. In particular, for $k=15$, $k=27$, we obtain an improvement, in terms of operations in the base field, of up to 25% and 29% respectively in the computation of the final exponentiation. We also find that elliptic curves with embedding degree $k=15$ present faster results than BN12 curves at the 128-bit security level. We provide a MAGMA implementation in each case to ensure the correctness of the formulas used in this work.

Explore related subjects

Keep this discovery

BibTeXRIS

Emmanuel Fouotsa, Nadia El Mrabet, Aminatou Pecha. 2020-02-27. Optimal Ate Pairing on Elliptic Curves with Embedding Degree $9,15$ and $27$. https://doi.org/10.46298/jgcc.2020.12.1.6167

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Perverse Euler Characteristics of Hermitian Locally Symmetric Spaces

We prove that finite-volume locally Hermitian symmetric spaces of noncompact type have nonnegative perverse Euler characteristics. To show this, we obtain a nefness result for the logarithmic cotangent bundle of a smooth toroidal compactification. Combining this with a positivity criterion for Euler characteristics of perverse sheaves, we deduce the nonnegativity result. We further prove that the inequality is strict for perverse sheaves with full support. As applications, we get nonnegativity results for perverse Euler characteristics on various moduli spaces.

math.AG

Coupled Pklt Tuples and Varieties of Pklt Type

We introduce asymptotic multiplier ideal sheaves and log canonical thresholds associated with tuples of pseudoeffective divisors on a projective klt pair. We prove that the threshold of a coupled potentially klt tuple is computed by a quasi-monomial valuation. For varieties of potentially klt type, we prove that every big divisor admits a birational Zariski decomposition with semiample positive part. We also prove finite generation of multisection rings of big divisors and give a criterion for a variety of potentially klt type to be a Mori dream space.

math.AG

Graded Betti numbers of general curves of large degree

Let $C$ be a smooth projective complex curve of genus $g$ and gonality $k$, and $L$ be a very ample line bundle on $C$. When $L$ has sufficiently large degree, the vanishing and nonvanishing of the Koszul cohomology groups $K_{p,q}(C,L)$ have been determined previously, but the exact values of the graded Betti numbers $\kappa_{p,q}(C, L)$ remain largely unknown. In this paper, we give explicit closed formulas for all graded Betti numbers $\kappa_{p,q}(C, L)$ when the Brill--Noether locus $W_k^1(C)$ has the expected dimension and $H^1(C, L \otimes \omega_C^{-1})=0$. Consequently, we determine the complete Betti table for a general curve when $\deg L \geq 4g-3$ or when $\deg L \geq 3g-3$ and $L$ is general. We also explicitly compute the Boij--S\"{o}derberg coefficient of the section ring $R(C, L)$ governing asymptotic purity, and show eventual monotonicity of the remaining coefficients: they decrease for hyperelliptic curves and increase under a natural generic reducedness assumption on the relevant Brill--Noether loci.

math.AG