On the Selection of Pairing-Friendly Groups.
Paulo S. L. M. Barreto, Ben Lynn, Michael Scott · 2003
Abstract. We propose a simple algorithm to select group generators suitable for pairing-based cryptosystems. The selected parameters are shown to favor implementations of the Tate pairing that are at once conceptually simple and efficient, with an observed performance about 2 to 10 times better than previously reported implementations, depending on the embedding degree. Our algorithm has beneficial side effects: various non-pairing operations become faster, and bandwidth may be saved. Keywords: pairing-based cryptosystems, group generators, elliptic curves, Tate pairing. 1 Introduction Pairing-based cryptosystems are currently one of the most active areas of re-search in elliptic curve cryptography, as we see from the abundance of recent literature on the subject. This interest is not unfounded, as previously unsolvedproblems have been cracked by using pairings.