In ICISC 2007, Comuta and others showed that among the methods for constructing pairingfriendly curves, those using cyclotomic polynomials, that is, the BrezingWeng method and the FreemanScottTeske method, are affected by Cheon's algorithm. This paper proposes a method for searching parameters of pairingfriendly elliptic curves that induces minimal security loss by Cheon's algorithm. We also provide a sample set of parameters of BNcurves, FSTcurves, and KSScurves for pairingbased cryptography.
In ICISC 2007, Comuta and others showed that among the methods for constructing pairingfriendly curves, those using cyclotomic polynomials, that is, the BrezingWeng method and the FreemanScottTeske method, are affected by Cheon's algorithm. This paper proposes a method for searching parameters of pairingfriendly elliptic curves that induces minimal security loss by Cheon's algorithm. We also provide a sample set of parameters of BNcurves, FSTcurves, and KSScurves for pairingbased cryptography.