On the Disadvantages of Pairing-based Cryptography.
Zhengjun Cao, Lihua Liu · 2015
Abstract. Pairing-based cryptography (PBC) has many elegant properties. It is claimed that PBC can offer a desired security level with smaller parameters as the general elliptic curve cryptography (ECC). In the note, we remark that this view is misleading. Suppose that an elliptic curve E is defined over the field Fq. Then ECC is working with elements which are defined over Fq. But PBC is working with the functions and elements defined over Fqk, where k is the embedding degree. The security of PBC depends directly on the intractable level of either elliptic curve discrete log problem (ECDLP) in the group E(Fq) or discrete log problem (DLP) in the group F∗ qk. That means PBC protocols have to work in a running environment with parameters of 1024 bits so as to offer 80 bits security level. The shortcoming makes PBC lose its competitive advantages significantly.