Skip to main content
QUICK REVIEW

[Paper Review] Faster Pairing Computation

Christophe Arène, Tanja Lange|arXiv (Cornell University)|Apr 6, 2009
Cryptography and Residue Arithmetic19 references9 citations
TL;DR

This paper introduces optimized explicit formulas for doubling and addition in Miller’s algorithm for pairing computation on Edwards and Weierstrass curves. By reinterpreting Edwards curve arithmetic geometrically and deriving new coefficient computation methods, the proposed formulas achieve faster pairing evaluation than prior Edwards curve methods and are competitive with Weierstrass curve formulas, including new pairing-friendly twisted Edwards curves with embedding degree k = 6.

ABSTRACT

Abstract. This paper proposes new explicit formulas for the doubling and addition step in Miller’s algorithm to compute pairings. For Edwards curves the formulas come from a new way of seeing the arithmetic. We state the first geometric interpretation of the group law on Edwards curves by presenting the functions which arise in the addition and doubling. Computing the coefficients of the functions and the sum or double of the points is faster than with all previously proposed formulas for pairings on Edwards curves. They are even competitive with all published formulas for pairing computation on Weierstrass curves. We also speed up pairing computation on Weierstrass curves in Jacobian coordinates. Finally, we present examples of pairing-friendly twisted Edwards curves with embedding degree k = 6.

Motivation & Objective

  • To accelerate pairing computation on elliptic curves by deriving new explicit formulas for the doubling and addition steps in Miller’s algorithm.
  • To provide a geometric interpretation of the group law on Edwards curves through the functions used in pairing computation.
  • To improve performance on Edwards curves to match or exceed that of existing Weierstrass curve pairing formulas.
  • To optimize pairing computation on Weierstrass curves using Jacobian coordinates.
  • To construct examples of pairing-friendly twisted Edwards curves with embedding degree k = 6.

Proposed method

  • Deriving new arithmetic formulas for point doubling and addition on Edwards curves using a novel algebraic and geometric perspective on their group law.
  • Expressing the functions arising in Miller’s algorithm explicitly, enabling efficient coefficient computation and point operations.
  • Optimizing the evaluation of pairing functions by minimizing field operations through formula simplification.
  • Applying similar optimization techniques to Weierstrass curves in Jacobian coordinates to improve performance.
  • Constructing twisted Edwards curves with embedding degree k = 6 that are suitable for pairing-based cryptography.

Experimental results

Research questions

  • RQ1How can the arithmetic of Edwards curves be reinterpreted to yield faster pairing computation formulas?
  • RQ2What geometric insight underlies the group law on Edwards curves, and how can it be leveraged in pairing algorithms?
  • RQ3Can pairing computation on Edwards curves be made competitive with that on Weierstrass curves through formula optimization?
  • RQ4What are the performance gains of the proposed formulas compared to existing methods on both Edwards and Weierstrass curves?
  • RQ5What are the properties and construction criteria for pairing-friendly twisted Edwards curves with embedding degree k = 6?

Key findings

  • The proposed formulas for Edwards curve point operations are faster than all previously published formulas for pairing computation on Edwards curves.
  • The new formulas for Edwards curves are competitive with the fastest known formulas for pairing computation on Weierstrass curves.
  • The geometric interpretation of the group law on Edwards curves is derived through explicit functions used in Miller’s algorithm.
  • The performance of pairing computation on Weierstrass curves in Jacobian coordinates is improved via optimized formulas.
  • The paper presents explicit examples of pairing-friendly twisted Edwards curves with embedding degree k = 6, enabling efficient pairing-based cryptographic schemes.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.