International Association for Cryptologic Research

International Association
for Cryptologic Research


Paper: A Note on the Ate Pairing

Chang-An Zhao
Fangguo Zhang
Jiwu Huang
Search ePrint
Search Google
Abstract: The Ate pairing has been suggested since it can be computed efficiently on ordinary elliptic curves with small values of the traces of Frobenius $t$. However, not all pairing-friendly elliptic curves have this property. In this paper, we generalize the Ate pairing and find a series of variations of the Ate pairing. We show that the shortest Miller loop of the variations of the Ate pairing can possibly be as small as $r^{1/\varphi(k)}$ on more pairing-friendly curves generated by the method of complex multiplications, and hence speed up the pairing computation significantly.
  title={A Note on the Ate Pairing},
  booktitle={IACR Eprint archive},
  keywords={Tate pairing, Ate pairing, Elliptic curves, Pairing-based cryptosystems},
  note={ zhcha@mail2 sysu edu cn 13843 received 20 Jun 2007, last revised 25 Nov 2007},
  author={Chang-An Zhao and Fangguo Zhang and Jiwu Huang},