close
Skip to main content

Advertisement

Springer Nature Link
Log in
Menu
Find a journal Publish with us Track your research
Search
Saved research
Cart
  1. Home
  2. Selected Areas in Cryptography
  3. Conference paper

Pairing-Friendly Elliptic Curves of Prime Order

  • Conference paper
  • pp 319–331
  • Cite this conference paper
Save conference paper
View saved research
Selected Areas in Cryptography (SAC 2005)
Pairing-Friendly Elliptic Curves of Prime Order
  • Paulo S. L. M. Barreto18 &
  • Michael Naehrig19 

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 3897))

Included in the following conference series:

  • International Workshop on Selected Areas in Cryptography
  • 4122 Accesses

  • 692 Citations

  • 18 Altmetric

Abstract

Previously known techniques to construct pairing-friendly curves of prime or near-prime order are restricted to embedding degree \(k \leqslant 6 \). More general methods produce curves over \({\mathbb F}_{p}\) where the bit length of p is often twice as large as that of the order r of the subgroup with embedding degree k; the best published results achieve ρ ≡ log(p)/log(r) ~ 5/4. In this paper we make the first step towards surpassing these limitations by describing a method to construct elliptic curves of prime order and embedding degree k = 12. The new curves lead to very efficient implementation: non-pairing operations need no more than \({\mathbb F}_{p^4}\) arithmetic, and pairing values can be compressed to one third of their length in a way compatible with point reduction techniques. We also discuss the role of large CM discriminants D to minimize ρ; in particular, for embedding degree k = 2q where q is prime we show that the ability to handle log(D)/log(r) ~ (q–3)/(q–1) enables building curves with ρ ~ q/(q–1).

Download to read the full chapter text

Chapter PDF

Similar content being viewed by others

Revisiting Pairing-Friendly Curves with Embedding Degrees 10 and 14

Chapter © 2025

A New Family of Pairing-Friendly Elliptic Curves

Chapter © 2018

Galois subcovers of the Hermitian curve in characteristic p with respect to subgroups of order dp with \(d\not =p\) prime

Article Open access 14 March 2025

Explore related subjects

Discover the latest articles, books and news in related subjects, suggested using machine learning.
  • Computational Complexity
  • Computational Number Theory
  • Geometry
  • Lead Optimization
  • Non-homologous-end joining
  • Number Theory
  • Arithmetic Geometry of Elliptic Curves

References

  1. Barreto, P.S.L.M., Lynn, B., Scott, M.: Constructing elliptic curves with prescribed embedding degrees. In: Cimato, S., Galdi, C., Persiano, G. (eds.) SCN 2002. LNCS, vol. 2576, pp. 257–267. Springer, Heidelberg (2003)

    Chapter  Google Scholar 

  2. Barreto, P.S.L.M., Lynn, B., Scott, M.: On the selection of pairing-friendly groups. In: Matsui, M., Zuccherato, R.J. (eds.) SAC 2003. LNCS, vol. 3006, pp. 17–25. Springer, Heidelberg (2004)

    Chapter  Google Scholar 

  3. Barreto, P.S.L.M., Lynn, B., Scott, M.: Efficient implementation of pairing based cryptosystems. Journal of Cryptology 17(4), 321–334 (2004)

    Article  MathSciNet  MATH  Google Scholar 

  4. Blake, I., Seroussi, G., Smart, N.: Advances in Elliptic Curve Cryptography. London Mathematical Society Lecture Note Series, vol. 317. Cambridge University Press, Cambridge (2005)

    Book  MATH  Google Scholar 

  5. Boneh, D., Franklin, M.: Identity-based encryption from the Weil pairing. SIAM Journal of Computing 32(3), 586–615 (2003)

    Article  MathSciNet  MATH  Google Scholar 

  6. Boneh, D., Lynn, B., Shacham, H.: Short Signatures from the Weil Pairing. In: Boyd, C. (ed.) ASIACRYPT 2001. LNCS, vol. 2248, pp. 514–532. Springer, Heidelberg (2002)

    Chapter  Google Scholar 

  7. Boneh, D., Lynn, B., Shacham, H.: Short signatures from the Weil pairing. Journal of Cryptology 17(4), 297–319 (2004)

    Article  MathSciNet  MATH  Google Scholar 

  8. Brezing, F., Weng, A.: Elliptic curves suitable for pairing based cryptography. Cryptology ePrint Archive, Report 2003/143 (2003), Available from: http://eprint.iacr.org/2003/143

  9. Dupont, R., Enge, A., Morain, F.: Building curves with arbitrary small MOV degree over finite prime fields. Journal of Cryptology 18(2), 79–89 (2005)

    Article  MathSciNet  MATH  Google Scholar 

  10. Galbraith, S., McKee, J., Valença, P.: Ordinary abelian varieties having small embedding degree. Cryptology ePrint Archive, Report 2004/365 (2004), Available from: http://eprint.iacr.org/2004/365

  11. Granger, R., Page, D., Stam, M.: On small characteristic algebraic tori in pairing-based cryptography. Cryptology ePrint Archive, Report 2004/132, Available from: http://eprint.iacr.org/2004/132

  12. IEEE Computer Society, New York, USA. IEEE Standard Specifications for Public- Key Cryptography – IEEE Std 1363-2000 (2000)

    Google Scholar 

  13. Lay, G.-J., Zimmer, H.G.: Constructing elliptic curves with given group order over large finite fields. In: Huang, M.-D.A., Adleman, L.M. (eds.) ANTS 1994. LNCS, vol. 877, pp. 250–263. Springer, Heidelberg (1994)

    Chapter  Google Scholar 

  14. Lenstra, A.K., Verheul, E.R.: The XTR Public Key System. In: Bellare, M. (ed.) CRYPTO 2000. LNCS, vol. 1880, pp. 1–19. Springer, Heidelberg (2000)

    Chapter  Google Scholar 

  15. Miyaji, A., Nakabayashi, M., Takano, S.: New explicit conditions of elliptic curve traces for FR-reduction. IEICE Transactions on Fundamentals E84-A(5), 1234–1243 (2001)

    Google Scholar 

  16. Morain, F.: Building cyclic elliptic curves modulo large primes. In: Davies, D.W. (ed.) EUROCRYPT 1991. LNCS, vol. 547, pp. 328–336. Springer, Heidelberg (1991)

    Chapter  Google Scholar 

  17. Rubin, K., Silverberg, A.: Supersingular abelian varieties in cryptology. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol. 2442, pp. 336–353. Springer, Heidelberg (2002)

    Chapter  Google Scholar 

  18. Scott, M., Barreto, P.S.L.M.: Compressed pairings. In: Franklin, M. (ed.) CRYPTO 2004. LNCS, vol. 3152, pp. 140–156. Springer, Heidelberg (2004)

    Chapter  Google Scholar 

  19. Scott, M., Barreto, P.S.L.M.: Generating more MNT elliptic curves. Designs, Codes and Cryptography (2005) (to appear)

    Google Scholar 

Download references

Author information

Authors and Affiliations

  1. Escola Politécnica, Universidade de São Paulo, Av. Prof. Luciano Gualberto, tr. 3, n. 158, BR 05508-900, São Paulo (SP), Brazil

    Paulo S. L. M. Barreto

  2. Lehrstuhl für Theoretische Informationstechnik, Rheinisch-Westfälische Technische Hochschule Aachen, Sommerfeldstr. 24, D-52074, Aachen, Germany

    Michael Naehrig

Authors
  1. Paulo S. L. M. Barreto
    View author publications

    Search author on:PubMed Google Scholar

  2. Michael Naehrig
    View author publications

    Search author on:PubMed Google Scholar

Editor information

Editors and Affiliations

  1. Interdisciplinary Institute for BroadBand Technology (IBBT), Belgium

    Bart Preneel

  2. Department of Electrical and Computer Engineering, Queen’s University Kingston, K7L 3N6, Kingston, Ontario, Canada

    Stafford Tavares

Rights and permissions

Reprints and permissions

Copyright information

© 2006 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Barreto, P.S.L.M., Naehrig, M. (2006). Pairing-Friendly Elliptic Curves of Prime Order. In: Preneel, B., Tavares, S. (eds) Selected Areas in Cryptography. SAC 2005. Lecture Notes in Computer Science, vol 3897. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11693383_22

Download citation

  • .RIS
  • .ENW
  • .BIB
  • DOI: https://doi.org/10.1007/11693383_22

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-33108-7

  • Online ISBN: 978-3-540-33109-4

  • eBook Packages: Computer ScienceComputer Science (R0)Springer Nature Proceedings Computer Science

Share this paper

Anyone you share the following link with will be able to read this content:

Sorry, a shareable link is not currently available for this article.

Provided by the Springer Nature SharedIt content-sharing initiative

Keywords

  • elliptic curves
  • pairing-based cryptosystems

Publish with us

Policies and ethics

Profiles

  1. Paulo S. L. M. Barreto View author profile

Search

Navigation

  • Find a journal
  • Publish with us
  • Track your research

Footer Navigation

Discover content

  • Journals A-Z
  • Books A-Z
  • Subjects A-Z

Publish with us

  • Journal finder
  • Publish your research
  • Language editing
  • Open access publishing

Products and services

  • Our products
  • Librarians
  • Societies
  • Partners and advertisers

Our brands

  • Springer
  • Nature Portfolio
  • BMC
  • Palgrave Macmillan
  • Apress
  • Discover

Corporate Navigation

  • Your US state privacy rights
  • Accessibility statement
  • Terms and conditions
  • Privacy policy
  • Help and support
  • Legal notice
  • Cancel contracts here

104.23.243.59

Not affiliated

Springer Nature

© 2026 Springer Nature