Pairing Inversion via Non-degenerate Auxiliary Pairings

نویسندگان

  • Seunghwan Chang
  • Hoon Hong
  • Eunjeong Lee
  • Hyang-Sook Lee
چکیده

The security of pairing-based cryptosystems is closely related to the difficulty of the pairing inversion problem(PI). In this paper, we discuss the difficulty of pairing inversion on the generalized ate pairings of Vercauteren. First, we provide a simpler approach for PI by generalizing and simplifying Kanayama-Okamotos approach; our approach involves modifications of exponentiation inversion(EI) and Miller inversion(MI), via an auxiliary pairing. Then we provide a complexity of the modified MI, showing that the complexity depends on the sum-norm of the integer vector defining the auxiliary pairing. Next, we observe that degenerate auxiliary pairings expect to make modified EI harder. We provide a sufficient condition on the integer vector, in terms of its max norm, so that the corresponding auxiliary paring is non-degenerate. Finally, we define an infinite set of curve parameters, which includes those of typical pairing friendly curves, and we show that, within those parameters, PI of arbitrarily given generalized ate pairing can be reduced to modified EI in polynomial time.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Reducing Pairing Inversion to Exponentiation Inversion using Non-degenerate Auxiliary Pairing

The security of pairing-based cryptosystems is closely related to the difficulty of the pairing inversion problem. Building on previous works, we provide further contributions on the difficulty of pairing inversion. In particular, we revisit the approach of Kanayama-Okamoto who modified exponentiation inversion and Miller inversion by considering an “auxiliary” pairing. First, by generalizing a...

متن کامل

Compressed Pairings

Pairing-based cryptosystems rely on bilinear non-degenerate maps called pairings, such as the Tate and Weil pairings defined over certain elliptic curve groups. In this paper we show how to compress pairing values, how to couple this technique with that of point compression, and how to benefit from the compressed representation to speed up exponentiations involving pairing values, as required i...

متن کامل

Invariant Differential Pairings

In this paper the notion of an M -th order invariant bilinear differential pairing is introduced and a formal definition is given. If the manifold has an AHS structure, then various first order pairings are constructed. This yields a classification of all first order invariant bilinear differential pairings on homogeneous spaces with an AHS structure except for certain totally degenerate cases....

متن کامل

Height Pairings

generalizing the Neron-Tate pairing on abelian varieties. Note that our cycles are of a dimension where their expected intersection has dimension −1. Example 1.1 ([9], [3]) Let C/K be a smooth projective curve, with ∞ ∈ C(K) giving i : C ↪→ Pic(C). Let 〈·, ·〉NT : Pic(C)(K)×Pic(C)(K)→ R be the Neron-Tate height pairing, identifying P̂ic(A) ∼= Pic(A) via the theta divisor. Then, once we have defin...

متن کامل

An Analysis of Affine Coordinates for Pairing Computation

In this paper we analyze the use of affine coordinates for pairing computation. We observe that in many practical settings, e. g. when implementing optimal ate pairings in high security levels, affine coordinates are faster than using the best currently known formulas for projective coordinates. This observation relies on two known techniques for speeding up field inversions which we analyze in...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013