Note on families of pairing-friendly elliptic curves with small embedding degree
Abstract
Pairing-based cryptographic schemes require so-called pairing-friendly elliptic curves, which have special properties. The set of pairing-friendly elliptic curves that are generated by given polynomials form a complete family. Although a complete family with a -value of 1 is the ideal case, there is only one such example that is known, this was given by Barreto and Naehrig. We prove that there are no ideal families with embedding degree 3, 4, or 6 and that many complete families with embedding degree 8 or 12 are nonideal, even if we chose noncyclotomic families.
Turn this paper into a lesson
ArcXiv compiles a structured reading guide from this paper's metadata: plain-English importance, contributions, prerequisite concepts, which sections to read first, flashcards, and a quiz. Grounded in the abstract, never invented.