Choosing and generating parameters for pairing implementation on BN curves

Abstract : Because pairings have many applications, many hardware and software pairing implementations can be found in the literature. However, the parameters generally used have been invalidated by the recent results on the discrete logarithm problem over pairing friendly elliptic curves (Kim and Barbulescu in CRYPTO 2016, volume 9814 of lecture notes in computer science, Springer, Berlin, pp 543–571, 2016). New parameters must be generated to insure enough security in pairing based protocols. More generally it could be useful to generate nice pairing parameters in many real-world applications (specific security level, resistance to specific attacks on a protocol, database of curves). The main purpose of this paper is to describe explicitly and exhaustively what should be done to generate the best possible parameters and to make the best choices depending on the implementation context (in terms of pairing algorithm, ways to build the tower field, Fp12 arithmetic, groups involved and their generators, system of coordinates). We focus on low level implementations, assuming that Fp additions have a significant cost compared to other Fp operations. However, our results are still valid if Fp additions can be neglected. We also explain why the best choice for the polynomials defining the tower field Fp12 is only dependent on the value of the BN parameter u mod small integers (like 12 for instance) as a nice application of old elementary arithmetic results. This should allow a faster generation of this parameter. Moreover, we use this opportunity to give some new slight improvements on Fp12 arithmetic (in a pairing context).
Liste complète des métadonnées

https://hal.archives-ouvertes.fr/hal-01542564
Contributor : Sylvain Duquesne <>
Submitted on : Monday, June 19, 2017 - 8:29:29 PM
Last modification on : Thursday, March 14, 2019 - 8:28:08 PM

Identifiers

Citation

Sylvain Duquesne, Nadia El Mrabet, Safia Haloui, Franck Rondepierre. Choosing and generating parameters for pairing implementation on BN curves. Applicable Algebra in Engineering, Communication and Computing, Springer Verlag, 2018, 29 (2), pp.113-147. ⟨10.1007/s00200-017-0334-y⟩. ⟨hal-01542564⟩

Share

Metrics

Record views

561