Paper 2013/532

On a Relation between the Ate Pairing and the Weil Pairing for Supersingular Elliptic Curves

Takakazu Satoh

Abstract

The hyperelliptic curve Ate pairing provides an efficient way to compute a bilinear pairing on the Jacobian variety of a hyperelliptic curve. We prove that, for supersingular elliptic curves with embedding degree two, square of the Ate pairing is nothing but the Weil pairing. Using the formula, we develop an X-coordinate only pairing inversion method. However, the algorithm is still infeasible for cryptographic size problems.

Note: Errors in Lemma 3.2, Lemma 4.1 and Theorem 4.3 are corrected. Statements of main results are not affected.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint. MINOR revision.
Keywords
Ate pairingWeil pairing
Contact author(s)
satoh df603 @ gmail com
History
2019-04-07: last of 2 revisions
2013-08-30: received
See all versions
Short URL
https://ia.cr/2013/532
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2013/532,
      author = {Takakazu Satoh},
      title = {On a Relation between the Ate Pairing and the Weil Pairing for Supersingular Elliptic Curves},
      howpublished = {Cryptology ePrint Archive, Paper 2013/532},
      year = {2013},
      note = {\url{https://eprint.iacr.org/2013/532}},
      url = {https://eprint.iacr.org/2013/532}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.