Area-Efficient Hardware Implementation of the Optimal Ate Pairing over BN curves. *
Anissa Sghaier, Loubna Ghammam, Medien Zeghid, Sylvain Duquesne, Mohsen Machhout · 2016
To have an efficient asymmetric key encryption scheme, such as el-liptic curves, hyperelliptic curves, pairing... etc we have to go through arithmetic optimization then hardware optimization. Regarding restricted environments ’ compromises, we should strike a balance between efficiency and memory resources. For this reason, we studied the mathematical as-pect of pairing computation and gave new development of the methods that compute the hard part of the final exponentiation in [1]. They prove that these new methods save an important number of temporary variables and they are certainly faster than the existing one. In this paper, we will also present a new way of computing Miller loop, more precisely in the doubling algorithm, so we will use this result and the arithmetic optimiza-tion presented in [1], then we will apply hardware optimization to find a satisfactory design which give the best compromise between area occu-pation and execution time. Our hardware implementation, on a Virtex-6 FPGA(XC6VHX250T), used only 9476 Slices, which is less resources used compared with state-of-the-art hardware implementations, so we can say that our approach cope with the limited resources of restricted environ-ment.