Cost Evaluation of The Improvement of Twisted Ate Pairing That Uses Integer Variable X of Small Hamming Weight

Sakemi, Yumi
Kato, hidehiro
Morikawa, Yoshikawa
Barreto–Naehrig (BN) curve has been introduced as an efficient pairing-friendly elliptic curve over prime field F(p) whose embedding degree is 12. The characteristic and Frobenius trace are given as polynomials of integer variable X. The authors proposed an improvement of Miller's algorithm of twisted Ate pairing with BN curve by applying X of small hamming weight in ITC–CSCC2008; however, its cost evaluation has not been explicitly shown. This paper shows the detail of the cost evaluation.