Institutional Repository
| efficient pairing computation on ordinary elliptic curves of embedding degree 1 and 2 | |
| Zhang Xusheng; Lin Dongdai | |
| 2011 | |
| 会议名称 | Cryptography and Coding 13th IMA International Conference, IMACC 2011 |
| 会议录名称 | Cryptography and Coding |
| 页码 | 309-326 |
| 会议日期 | 2011 |
| 会议地点 | Oxford UK |
| 收录类别 | SPRINGER ; EI |
| ISSN | 0302-9743 |
| ISBN | 978-3-642-25515-1 |
| 部门归属 | SKLOIS Institute of Software Chinese Academy of Sciences Beijing China |
| 摘要 | In pairing-based cryptography, most researches are focused on elliptic curves of embedding degrees greater than six, but less on curves of small embedding degrees, although they are important for pairing-based cryptography over composite-order groups. This paper analyzes efficient pairings on ordinary elliptic curves of embedding degree 1 and 2 from the point of shortening Miller’s loop. We first show that pairing lattices presented by Hess can be redefined on composite-order groups. Then we give a simpler variant of the Weil pairing lattice which can also be regarded as an Omega pairing lattice, and extend it to ordinary curves of embedding degree 1. In our analysis, the optimal Omega pairing, as the super-optimal pairing on elliptic curves of embedding degree 1 and 2, could be more efficient than Weil and Tate pairings. On the other hand, elliptic curves of embedding degree 2 are also very useful for pairings on elliptic curves over RSA rings proposed by Galbraith and McKee. So we analyze the construction of such curves over RSA rings, and redefine pairing lattices over RSA rings. Specially, modified Omega pairing lattices over RSA rings can be computed without knowing the RSA trapdoor. Furthermore, for keeping the trapdoor secret, we develop an original idea of evaluating pairings without leaking the group order.; In pairing-based cryptography, most researches are focused on elliptic curves of embedding degrees greater than six, but less on curves of small embedding degrees, although they are important for pairing-based cryptography over composite-order groups. This paper analyzes efficient pairings on ordinary elliptic curves of embedding degree 1 and 2 from the point of shortening Miller’s loop. We first show that pairing lattices presented by Hess can be redefined on composite-order groups. Then we give a simpler variant of the Weil pairing lattice which can also be regarded as an Omega pairing lattice, and extend it to ordinary curves of embedding degree 1. In our analysis, the optimal Omega pairing, as the super-optimal pairing on elliptic curves of embedding degree 1 and 2, could be more efficient than Weil and Tate pairings. On the other hand, elliptic curves of embedding degree 2 are also very useful for pairings on elliptic curves over RSA rings proposed by Galbraith and McKee. So we analyze the construction of such curves over RSA rings, and redefine pairing lattices over RSA rings. Specially, modified Omega pairing lattices over RSA rings can be computed without knowing the RSA trapdoor. Furthermore, for keeping the trapdoor secret, we develop an original idea of evaluating pairings without leaking the group order. |
| 关键词 | Miller’ s Algorithm – Composite Order Pairing – Omega Pairing Lattices – Rsa Ring |
| 主办者 | The Institute of Mathematics and its Applications; Cryptomathic Ltd.; Hewlett-Packard Laboratories; Vodafone Ltd. |
| 语种 | 英语 |
| 内容类型 | 会议论文 |
| URI标识 | http://ir.iscas.ac.cn/handle/311060/16235 |
| 专题 | 中国科学院软件研究所 |
| 推荐引用方式 GB/T 7714 | Zhang Xusheng,Lin Dongdai. efficient pairing computation on ordinary elliptic curves of embedding degree 1 and 2[C],2011:309-326. |
| 条目包含的文件 | 条目无相关文件。 | |||||
| 个性服务 |
| 推荐该条目 |
| 保存到收藏夹 |
| 查看访问统计 |
| 导出为Endnote文件 |
| 谷歌学术 |
| 谷歌学术中相似的文章 |
| [Zhang Xusheng]的文章 |
| [Lin Dongdai]的文章 |
| 百度学术 |
| 百度学术中相似的文章 |
| [Zhang Xusheng]的文章 |
| [Lin Dongdai]的文章 |
| 必应学术 |
| 必应学术中相似的文章 |
| [Zhang Xusheng]的文章 |
| [Lin Dongdai]的文章 |
| 相关权益政策 |
| 暂无数据 |
| 收藏/分享 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论