On the Final Exponentiation for Calculating Pairings on Ordinary Elliptic Curves

Michael Scott,Naomi Benger,Manuel Charlemagne,Luis J. Dominguez Perez,Ezekiel J. Kachisa
DOI: https://doi.org/10.1007/978-3-642-03298-1_6
2009-01-01
Abstract:When performing a Tate pairing (or a derivative thereof) on an ordinary pairing-friendly elliptic curve, the computation can be looked at as having two stages, the Miller loop and the so-called final exponentiation. As a result of good progress being made to reduce the Miller loop component of the algorithm (particularly with the discovery of "truncated loop" pairings like the R-ate pairing [18]), the final exponentiation has become a more significant component of the overall calculation. Here we exploit the structure of pairing-friendly elliptic curves to reduce to a minimum the computation required for the final exponentiation.
What problem does this paper attempt to address?