본문 바로가기 메뉴바로가기

Papers

Pairing-Friendly Curves with Minimal Security Loss by Cheon's Algorithm

https://doi.org/10.4218/etrij.11.0210.0338|


In ICISC 2007, Comuta and others showed that among the methods for constructing pairing­friendly curves, those using cyclotomic polynomials, that is, the Brezing­Weng method and the Freeman­Scott­Teske method, are affected by Cheon's algorithm. This paper proposes a method for searching parameters of pairing­friendly elliptic curves that induces minimal security loss by Cheon's algorithm. We also provide a sample set of parameters of BN­curves, FST­curves, and KSS­curves for pairing­based cryptography.


In ICISC 2007, Comuta and others showed that among the methods for constructing pairing­friendly curves, those using cyclotomic polynomials, that is, the Brezing­Weng method and the Freeman­Scott­Teske method, are affected by Cheon's algorithm. This paper proposes a method for searching parameters of pairing­friendly elliptic curves that induces minimal security loss by Cheon's algorithm. We also provide a sample set of parameters of BN­curves, FST­curves, and KSS­curves for pairing­based cryptography.