Efficient implementation of pairing-based cryptosystems

被引:9
作者
Barreto, PSLM
Lynn, B
Scott, M
机构
[1] Univ Sao Paulo, Escola Politecn, BR-05508900 Sao Paulo, Brazil
[2] Stanford Univ, Dept Comp Sci, Stanford, CA 94305 USA
[3] Dublin City Univ, Sch Comp Applicat, Dublin 9, Ireland
关键词
pairing-based cryptosystem; elliptic curve construction; efficient implementation; Tate pairing;
D O I
10.1007/s00145-004-0311-z
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Pairing-based cryptosystems rely on the existence of bilinear, nondegenerate, efficiently computable maps (called pairings) over certain groups. Currently, all such pairings used in practice are related to the Tate pairing on elliptic curve groups whose embedding degree is large enough to maintain a good security level, but small enough for arithmetic operations to be feasible. In this paper we describe how to construct ordinary (non-supersingular) elliptic curves containing groups with arbitrary embedding degree, and show how to compute the Tate pairing on these groups efficiently.
引用
收藏
页码:321 / 334
页数:14
相关论文
共 28 条
[1]   The improbability that an elliptic curve has subexponential discrete log problem under the Menezes-Okamoto-Vanstone algorithm [J].
Balasubramanian, R ;
Koblitz, N .
JOURNAL OF CRYPTOLOGY, 1998, 11 (02) :141-145
[2]  
BARRETO PSL, 2002, LECT NOTES COMPUTER, V2576, P263
[3]  
BARRETO PSL, 2002, LECT NOTES COMPUTER, V2442
[4]  
Barreto PSLM, 2004, LECT NOTES COMPUT SC, V3006, P17
[5]  
Blake I.F., 1999, ELLIPTIC CURVES CRYP
[6]   Identity-based encryption from the Weil pairing [J].
Boneh, D ;
Franklin, M .
SIAM JOURNAL ON COMPUTING, 2003, 32 (03) :586-615
[7]  
Boneh D., 2001, LNCS, P514, DOI [DOI 10.1007/3-540-45682-1_30, DOI 10.1007/3-540-45682-130]
[8]  
BREZING F, 2001, 2003143 CRYPT EPR AR
[9]   FAST EVALUATION OF LOGARITHMS IN FIELDS OF CHARACTERISTIC 2 [J].
COPPERSMITH, D .
IEEE TRANSACTIONS ON INFORMATION THEORY, 1984, 30 (04) :587-594
[10]  
Crandall R., 2001, PRIME NUMBERS COMPUT