The original paper is in English. Non-English content has been machine-translated and may contain typographical errors or mistranslations. ex. Some numerals are expressed as "XNUMX".
Copyrights notice
The original paper is in English. Non-English content has been machine-translated and may contain typographical errors or mistranslations. Copyrights notice
AES 128 보안 수준의 경우 페어링에 적합한 타원 곡선에 대한 몇 가지 자연스러운 선택이 있습니다. 특히 설명하겠지만 다음과 같은 곡선을 선택할 수 있습니다. k=9 또는 곡선 k=12. 경우 k=9는 문헌에서 연구되지 않았으므로 이 경우 쌍이 얼마나 효율적으로 계산될 수 있는지는 명확하지 않습니다. 본 논문에서는 효율적인 방법을 제시한다. k=9개의 경우, 더 짧은 밀러 루프를 사용한 타원 곡선 생성, 분모 제거 및 최종 지수화 속도 향상을 포함합니다. 그런 다음 이러한 선택의 성능을 비교합니다. 분석 결과, AES 128 보안 수준의 페어링 기반 암호화의 경우 Barreto-Naehrig 곡선이 가장 효율적인 선택이며 사례 성능이 우수하다는 결론을 내렸습니다. k=9는 Barreto-Naehrig 곡선과 유사합니다.
The copyright of the original papers published on this site belongs to IEICE. Unauthorized use of the original or translated papers is prohibited. See IEICE Provisions on Copyright for details.
부
Xibin LIN, Chang-An ZHAO, Fangguo ZHANG, Yanming WANG, "Computing the Ate Pairing on Elliptic Curves with Embedding Degree k=9" in IEICE TRANSACTIONS on Fundamentals,
vol. E91-A, no. 9, pp. 2387-2393, September 2008, doi: 10.1093/ietfec/e91-a.9.2387.
Abstract: For AES 128 security level there are several natural choices for pairing-friendly elliptic curves. In particular, as we will explain, one might choose curves with k=9 or curves with k=12. The case k=9 has not been studied in the literature, and so it is not clear how efficiently pairings can be computed in that case. In this paper, we present efficient methods for the k=9 case, including generation of elliptic curves with the shorter Miller loop, the denominator elimination and speed up of the final exponentiation. Then we compare the performance of these choices. From the analysis, we conclude that for pairing-based cryptography at the AES 128 security level, the Barreto-Naehrig curves are the most efficient choice, and the performance of the case k=9 is comparable to the Barreto-Naehrig curves.
URL: https://global.ieice.org/en_transactions/fundamentals/10.1093/ietfec/e91-a.9.2387/_p
부
@ARTICLE{e91-a_9_2387,
author={Xibin LIN, Chang-An ZHAO, Fangguo ZHANG, Yanming WANG, },
journal={IEICE TRANSACTIONS on Fundamentals},
title={Computing the Ate Pairing on Elliptic Curves with Embedding Degree k=9},
year={2008},
volume={E91-A},
number={9},
pages={2387-2393},
abstract={For AES 128 security level there are several natural choices for pairing-friendly elliptic curves. In particular, as we will explain, one might choose curves with k=9 or curves with k=12. The case k=9 has not been studied in the literature, and so it is not clear how efficiently pairings can be computed in that case. In this paper, we present efficient methods for the k=9 case, including generation of elliptic curves with the shorter Miller loop, the denominator elimination and speed up of the final exponentiation. Then we compare the performance of these choices. From the analysis, we conclude that for pairing-based cryptography at the AES 128 security level, the Barreto-Naehrig curves are the most efficient choice, and the performance of the case k=9 is comparable to the Barreto-Naehrig curves.},
keywords={},
doi={10.1093/ietfec/e91-a.9.2387},
ISSN={1745-1337},
month={September},}
부
TY - JOUR
TI - Computing the Ate Pairing on Elliptic Curves with Embedding Degree k=9
T2 - IEICE TRANSACTIONS on Fundamentals
SP - 2387
EP - 2393
AU - Xibin LIN
AU - Chang-An ZHAO
AU - Fangguo ZHANG
AU - Yanming WANG
PY - 2008
DO - 10.1093/ietfec/e91-a.9.2387
JO - IEICE TRANSACTIONS on Fundamentals
SN - 1745-1337
VL - E91-A
IS - 9
JA - IEICE TRANSACTIONS on Fundamentals
Y1 - September 2008
AB - For AES 128 security level there are several natural choices for pairing-friendly elliptic curves. In particular, as we will explain, one might choose curves with k=9 or curves with k=12. The case k=9 has not been studied in the literature, and so it is not clear how efficiently pairings can be computed in that case. In this paper, we present efficient methods for the k=9 case, including generation of elliptic curves with the shorter Miller loop, the denominator elimination and speed up of the final exponentiation. Then we compare the performance of these choices. From the analysis, we conclude that for pairing-based cryptography at the AES 128 security level, the Barreto-Naehrig curves are the most efficient choice, and the performance of the case k=9 is comparable to the Barreto-Naehrig curves.
ER -