Indexed metadata

Simplified pairing computation and security implications

Steven D. Galbraith, Colm Ó hÉigeartaigh, Caroline Sheedy

Source record

Source: Crossref

Published: Aug 13, 2007

DOI: 10.1515/jmc.2007.013

Open original source ↗

Source abstract

Recent progress on pairing implementation has made certain pairings extremely simple and fast to compute. Hence, it is natural to examine if there are consequences for the security of pairing-based cryptography. This paper gives a method to compute eta pairings on certain supersingular curves with a greatly simplified final exponentiation. The method does not lead to any improvement in the speed of pairing implementation. However, we show that it leads to a multivariate attack on the pairing inversion problem. We analyse this attack and show that it is infeasible for elliptic curves.

Evidence graph

No public relationships recorded yet.

Integrity note: This page is a factual metadata record created by deterministic ingestion. It is not a claim that the work moves a mathematical frontier or has been independently verified.

Simplified pairing computation and security implications — Mathematical Frontier Network