Subgroup membership testing on elliptic curves via the Tate pairing

被引:0
作者
Dmitrii Koshelev
机构
[1] Computer Sciences and Networks Department,
[2] Télécom Paris,undefined
来源
Journal of Cryptographic Engineering | 2023年 / 13卷
关键词
Non-prime-order elliptic curves; Power residue symbol; Subgroup membership testing; Tate pairing;
D O I
暂无
中图分类号
学科分类号
摘要
This note explains how to guarantee the membership of a point in the prime-order subgroup of an elliptic curve (over a finite field) satisfying some moderate conditions. For this purpose, we apply the Tate pairing on the curve; however, it is not required to be pairing-friendly. Whenever the cofactor is small, the new subgroup test is much more efficient than other known ones, because it needs to compute at most two n-th power residue symbols (with small n) in the basic field. More precisely, the running time of the test is (sub-)quadratic in the bit length of the field size, which is comparable with the Decaf-style technique. The test is relevant, e.g., for the zk-SNARK friendly curves Bandersnatch and Jubjub proposed by the Ethereum and Zcash research teams, respectively.
引用
收藏
页码:125 / 128
页数:3
相关论文
共 26 条
  • [21] Faster Ate pairing computation on Selmer's model of elliptic curves
    Fouotsa, Emmanuel
    Ciss, Abdoul Aziz
    GROUPS COMPLEXITY CRYPTOLOGY, 2016, 8 (01) : 55 - 67
  • [22] Compact Hardware for Computing the Tate Pairing over 128-Bit-Security Supersingular Curves
    Estibals, Nicolas
    PAIRING-BASED CRYPTOGRAPHY-PAIRING 2010, 2010, 6487 : 397 - 416
  • [23] On Instantiating Pairing-Based Protocols with Elliptic Curves of Embedding Degree One
    Chatterjee, Sanjit
    Menezes, Alfred
    Rodriguez-Henriquez, Francisco
    IEEE TRANSACTIONS ON COMPUTERS, 2017, 66 (06) : 1061 - 1070
  • [24] Fast Architectures for the ηT Pairing over Small-Characteristic Supersingular Elliptic Curves
    Beuchat, Jean-Luc
    Detrey, Jeremie
    Estibals, Nicolas
    Okamoto, Eiji
    Rodriguez-Henriquez, Francisco
    IEEE TRANSACTIONS ON COMPUTERS, 2011, 60 (02) : 266 - 281
  • [25] Comparing the pairing efficiency over composite-order and prime-order elliptic curves
    Guillevic, Aurore
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2013, 7954 LNCS : 357 - 372
  • [26] A method for building more non-supersingular elliptic curves suitable for pairing-based cryptosystems
    Cui, S
    Duan, P
    Chan, CW
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2005, E88A (09) : 2468 - 2470