Compact hardware for computing the Tate pairing over 128-bit-security supersingular curves

Nicolas Estibals 1
1 CARAMEL - Cryptology, Arithmetic: Hardware and Software
Inria Nancy - Grand Est, LORIA - ALGO - Department of Algorithms, Computation, Image and Geometry
Abstract : This paper presents a novel method for designing compact yet efficient hardware implementations of the Tate pairing over supersingular curves in small characteristic. Since such curves are usually restricted to lower levels of security because of their bounded embedding degree, aiming for the recommended security of 128 bits implies considering them over very large finite fields. We however manage to mitigate this effect by considering curves over field extensions of moderately-composite degree, hence taking advantage of a much easier tower field arithmetic. This technique of course lowers the security on the curves, which are then vulnerable to Weil descent attacks, but a careful analysis allows us to maintain their security above the 128-bit threshold. As a proof of concept of the proposed method, we detail an FPGA ac- celerator for computing the Tate pairing on a supersingular curve over GF(3^(5·97)) , which satisfies the 128-bit security target. On a mid-range Xilinx Virtex-4 FPGA, this accelerator computes the pairing in 2.2 ms while requiring no more than 4755 slices.
Type de document :
Communication dans un congrès
Marc Joye and Atsuko Miyaji and Akira Otsuka. Pairing 2010 -- 4th International Conference on Pairing-Based Cryptography, Dec 2010, Yamanaka Hot Spring, Japan. 6487, pp.397-416, 2010, Lecture Notes in Computer Science. 〈10.1007/978-3-642-17455-1〉
Liste complète des métadonnées

Littérature citée [48 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/inria-00539926
Contributeur : Nicolas Estibals <>
Soumis le : jeudi 25 novembre 2010 - 15:28:08
Dernière modification le : mardi 13 décembre 2016 - 15:41:29
Document(s) archivé(s) le : samedi 3 décembre 2016 - 00:35:14

Fichier

pairing2010.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

Collections

Citation

Nicolas Estibals. Compact hardware for computing the Tate pairing over 128-bit-security supersingular curves. Marc Joye and Atsuko Miyaji and Akira Otsuka. Pairing 2010 -- 4th International Conference on Pairing-Based Cryptography, Dec 2010, Yamanaka Hot Spring, Japan. 6487, pp.397-416, 2010, Lecture Notes in Computer Science. 〈10.1007/978-3-642-17455-1〉. 〈inria-00539926〉

Partager

Métriques

Consultations de la notice

136

Téléchargements de fichiers

150