Secure and Efficient Pairing at 256-Bit Security Level

Secure and Efficient Pairing at 256-Bit Security Level
复制标题

DOI:
10.1007/978-3-319-61204-1_4
复制
发表时间:
2017-07
期刊:
--
影响因子:
--
通讯作者:
Yutaro Kiyomura;Akiko Inoue;Yuto Kawahara;Masaya Yasuda;T. Takagi;Tetsutaro Kobayashi
Yutaro Kiyomura;Akiko Inoue;Yuto Kawahara;Masaya Yasuda;T. Takagi;Tetsutaro Kobayashi
中科院分区:
其他
文献类型:
--
作者:
Yutaro Kiyomura;Akiko Inoue;Yuto Kawahara;Masaya Yasuda;T. Takagi;Tetsutaro Kobayashi

文献摘要

被引文献

相似文献

2016年,Kim和Barbulescu提出了一种有效的数域筛(NFS)算法,用于有限域中的离散对数问题(DLP)。配对密码的安全性是建立在求解DLP的困难性上的。因此,有必要修改DLP在计算上不可行的位长度,以对抗高效的NFS算法。PBC的主要运算(即,配对、椭圆曲线上的标量乘法和有限域上的幂运算)的定时通常随着位长度变得更长而变得更慢,因此更有效地计算PBC的主要运算变得越来越重要。在众多的配对友好曲线中选择合适的配对友好曲线是影响PBC主要运算计算效率的因素之一。为了准确地选择合适的配对友好曲线,需要实现PBC的主要操作,并对配对友好曲线之间的时序进行比较。在本文中,我们重点研究了Barreto-Lynn-Scott(BLS)和Kachisa-Schaefer-Scott(KSS)系列中的五个候选配对友好曲线作为256位安全配对友好曲线,并给出了以下两个结果:(1)对于每个候选配对友好曲线,DLP相对于有效NFS算法在计算上不可行的修正位长度,(2)通过使用修改后的位长在候选配对友好曲线之间比较PBC的主要操作的定时来确定合适的配对友好曲线。
At CRYPTO 2016, Kim and Barbulescu proposed an efficient number field sieve (NFS) algorithm for the discrete logarithm problem (DLP) in a finite field. The security of pairing-based cryptography (PBC) is based on the difficulty in solving the DLP. Hence, it has become necessary to revise the bitlength that the DLP is computationally infeasible against the efficient NFS algorithms. The timing of the main operations of PBC (i.e. pairing, scalar multiplication on the elliptic curves, and exponentiation on the finite field) generally becomes slower as the bitlength becomes longer, so it has become increasingly important to compute the main operations of PBC more efficiently. To choose a suitable pairing-friendly curve from among various pairing-friendly curves is one of the factors that affect the efficiency of computing the main operations of PBC. We should implement the main operations of PBC and compare the timing among some pairing-friendly curves in order to choose the suitable pairing-friendly curve precisely. In this paper, we focus on the five candidate pairing-friendly curves from the Barreto-Lynn-Scott (BLS) and Kachisa-Schaefer-Scott (KSS) families as the 256-bit secure pairing-friendly curves and show the following two results; (1) the revised bitlength that the DLP is computationally infeasible against the efficient NFS algorithms for each candidate pairing-friendly curve, (2) the suitable pairing-friendly curve by comparing the timing of the main operations of PBC among the candidate pairing-friendly curves using the revised bitlength.