This paper presents efficient formulas to compute Miller doubling and Miller addition utilizing degree-3 twists on curves with j-invariant 0 written in Hessian form. We give the formulas for both odd and even embedding degrees and for pairings on both G 1 × G 2 and G 2 × G 1 . We propose the use of embedding degrees 15 and 21 for 128-bit and 192-bit security respectively in light of the NFS attacks and their variants. We give a comprehensive comparison with other curve models; our formulas give the fastest known pairing computation for embedding degrees 15, 21, and 24.
CITATION STYLE
Chuengsatiansup, C., & Martindale, C. (2018). Pairing-friendly twisted hessian curves. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 11356 LNCS, pp. 228–247). Springer Verlag. https://doi.org/10.1007/978-3-030-05378-9_13
Mendeley helps you to discover research relevant for your work.