Abstract
Pairing-based cryptosystems rely on the existence of bilinear, nondegenerate, efficiently computable maps (called pairings) over certain groups. Currently, all such pairings used in practice are related to the Tate pairing on elliptic curve groups whose embedding degree is large enough to maintain a good security level, but small enough for arithmetic operations to be feasible. In this paper we describe how to construct ordinary (non-supersingular) elliptic curves containing groups with arbitrary embedding degree, and show how to compute the Tate pairing on these groups efficiently.
Article PDF
Similar content being viewed by others
Avoid common mistakes on your manuscript.
Author information
Authors and Affiliations
Corresponding authors
Rights and permissions
About this article
Cite this article
Barreto, P., Lynn, B. & Scott, M. Efficient Implementation of Pairing-Based Cryptosystems. J Cryptology 17, 321–334 (2004). https://doi.org/10.1007/s00145-004-0311-z
Received:
Revised:
Published:
Issue Date:
DOI: https://doi.org/10.1007/s00145-004-0311-z