[Paper Review] Trilinear maps for cryptography II
This paper proposes a cryptographically secure trilinear map over abelian varieties using Weil descent to elevate security by embedding the map on a higher-dimensional descent variety. By leveraging trapdoor descent bases and affine models, it enables efficient computation and public identity testing while resisting known attacks on projective constructions.
We continue to study the construction of cryptographic trilinear maps involving abelian varieties over finite fields. We introduce Weil descent as a tool to strengthen the security of a trilinear map. We form the trilinear map on the descent variety of an abelian variety of small dimension defined over a finite field of a large extension degree over a ground field. The descent bases, with respect to which the descents are performed, are trapdoor secrets for efficient construction of the trilinear map which pairs three trapdoor DDH-groups. The trilinear map also provides efficient public identity testing for the third group. We present a concrete construction involving the jacobian varieties of hyperelliptic curves.
Motivation & Objective
- To construct a cryptographically secure trilinear map using abelian varieties over finite fields.
- To strengthen security by applying Weil descent to increase the effective dimension of the underlying abelian variety.
- To ensure the discrete logarithm problem remains hard in all three groups by embedding trapdoor secrets in descent bases.
- To enable efficient public identity testing for the third group using the trilinear map.
- To resist known attacks on projective models by using only affine representations of maps and varieties.
Proposed method
- Weil descent is applied to an abelian variety $ A $ of small dimension over a large extension field $ K $, producing a descent variety $ ilde{A} $ defined over the base field $ k $, with dimension $ dg $ where $ d = [K:k] $.
- The trilinear map is constructed on $ ilde{A}[ ho] $, with three groups $ G_1, G_2, G_3 $, where $ G_3 $ is formed as a quotient $ U_1/U $ of an $ bF_ ho $-algebra module.
- The map is defined as $ (x ilde{D}_eta, yD_eta, z+U) o ho^{xyz} $, where $ ho = E( ilde{D}_eta, D_eta) $, and $ E $ is a Weil pairing.
- Descent bases are used as trapdoor secrets: they are not published but enable efficient construction of the pairing and group operations.
- Affine models are used exclusively for maps and varieties, avoiding global descent descriptions that could expose the structure to attacks.
- Sparse encodings of elements in $ G_3 $ are used to ensure efficient evaluation of the trilinear map, with representatives chosen as sparse linear combinations of basis maps $ ho_i $.
Experimental results
Research questions
- RQ1Can Weil descent be used to construct a secure trilinear map on abelian varieties that resists known attacks on projective models?
- RQ2Is the discrete logarithm problem in $ G_3 $ hard when the descent basis is kept secret, even if the trilinear map and group elements are published?
- RQ3Can the descent variety $ ilde{A} $ be efficiently reconstructed from the published trilinear map and sampled points on $ ilde{A}[ ho ] $?
- RQ4Does using only affine models for the maps and varieties prevent attacks that exploit homogeneous polynomial representations in projective models?
- RQ5Can public identity testing be efficiently implemented for $ G_3 $ using the trilinear map, without exposing the group structure?
Key findings
- The trilinear map is efficiently computable due to sparse encoding and affine model usage, enabling practical evaluation of $ E(xD'_eta, ho( ext{enc}(z))(yD_eta)) = ho^{xyz} $.
- The discrete logarithm problem in $ G_3 $ is secure under the assumption that the descent basis cannot be recovered from the published trilinear map and group elements.
- The construction resists attacks that exploit projective representations, as the maps are defined only via affine models without global descent.
- The trilinear map supports efficient public identity testing for $ G_3 $, where $ z+U $ is verified via the pairing without revealing the group structure.
- The descent variety $ ilde{A} $, though defined over $ k $, cannot be efficiently reconstructed from the published data unless the descent basis is known, preserving security.
- The use of $ bF_ ho $-algebras and sparse representatives ensures that the map remains efficient even as the dimension $ dg $ increases.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.