Faster Subgroup Checks for BLS12-381

Faster Subgroup Checks for BLS12-381
复制标题

BLS12-381 更快的子组检查

DOI:
--
复制
发表时间:
2019
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Sean Bowe
Sean Bowe
中科院分区:
--
文献类型:
--
作者:
Sean Bowe

文献摘要

被引文献

相似文献

配对友好的椭圆曲线构造提供了两个都是素数阶q且通常每个都有一个非平凡余因子h的椭圆曲线群。由于这些曲线的典型构造方式,自同态可以用来执行快速余因子乘法。然而,余因数乘法有时不足以处理余因数,例如延展性攻击。在这篇简短的笔记中,我们描述了用于检查点是否存在于BLS12-381椭圆曲线构造的正确Q阶子群内的有效技术,这是基于配对的协议标准化的焦点。我们使用自同态来消除q-挠率,同时修改(但不是杀死)h-挠率分量,而不是乘以q并将点与恒等式进行比较。然后可以将结果与身份进行比较。
Pairing-friendly elliptic curve constructions provide two elliptic curve groups which are both of prime order q and usually each have a nontrivial cofactor h. Due to the way these curves are typically constructed, endomorphisms can be applied to perform fast cofactor multiplication. However, cofactor multiplication is sometimes insufficient for dealing with cofactors, such as with malleability attacks. In this brief note, we describe efficient techniques for checking that points exist within the correct q-order subgroups of the BLS12-381 elliptic curve construction, which is the focus of standardization for pairing-based protocols. Instead of multiplying by q and comparing the point with the identity, we use endomorphisms to eliminate the q-torsion while modifying (but not killing) the h-torsion components. The result can then be compared against the identity.