AI 中文总结
该研究针对无界递归基于配对的证明系统,构造了超奇异椭圆曲线循环,其可通过Bröker算法高效生成无限个循环,还可与小有限域上的配对友好型曲线连接。
AI 中文摘要
针对无界递归基于配对的证明系统,我们给出了配对友好型椭圆曲线循环的新构造。与已知的唯一先前椭圆曲线循环——普通MNT循环不同,我们的构造使用超奇异椭圆曲线。我们方法的一个权衡是,超奇异循环在扩域上定义(最优情况下为二次扩域),这使得$\boldsymbol{G}_1$中的元素和计算不如MNT循环紧凑高效。另一方面,本文中的超奇异循环相比其MNT对应物具有关键优势:我们的无限族超奇异曲线的每个实例都可通过Br{ö}ker算法高效构造,而通过CM方法构造MNT实例仅可行于数量相对较少的有限个实例。换言之,虽然两种构造在理论上都给出配对友好型曲线的无限族,但仅超奇异构造能产生可在实践中实现的无限个循环。超奇异循环在递归基于配对的证明系统语境中具有相关优势,它们为底层有限域的选择提供灵活性:可选择素数$p$,使底层域算术高效且$p-1$被2的大幂整除;或如我们详细研究的,使用超奇异循环可实现将该循环与在小得多的有限域上定义的其他配对友好型椭圆曲线相连接的可能性,其中证明系统算术高效。实际上,构造这些所谓的配对友好型曲线“棒棒糖”是本工作的激励性问题(2019年由研究人员提出)。
英文摘要
We give new constructions of cycles of pairing-friendly elliptic curves with a view towards unbounded recursive pairing-based proof systems. Unlike the only known prior cycle of elliptic curves - the ordinary MNT cycle - our construction uses elliptic curves that are supersingular. A trade-off of our approach is that the supersingular cycles are defined over extension fields (quadratic extensions in the optimal case), which makes elements and computations in $\mathbb{G}_1$ less compact and efficient than those in the MNT cycle. On the other hand, the supersingular cycles in this paper offer a key advantage over their MNT counterpart: every instance of our infinite family of supersingular curves can be efficiently constructed via Br{ö}ker's algorithm, whereas it is only feasible to construct a relatively small, bounded number of MNT instances via the CM method. In other words, while both constructions give infinite families of pairing-friendly curves in theory, only the supersingular construction gives rise to infinite numbers of cycles that can be realised in practice. Supersingular cycles offer benefits that are relevant in the context of recursive pairing-based proof systems. They afford flexibility in the choices of underlying finite fields; one can choose primes $p$ for which the underlying field arithmetic is efficient and for which $p-1$ is divisible by a large power of 2. Or, as we study in detail, using supersingular cycles unlocks the possibility of connecting the cycle with other pairing-friendly elliptic curves that are defined over much smaller finite fields, where proof system arithmetic is much more efficient. Indeed, constructing these so-called lollipops of pairing-friendly curves was the motivating problem (posed by researchers back in 2019) that inspired the present work.
Comments24 pages, 6 figures, IACR Communications in Cryptology
Journal refCraig Costello and Gaurish Korpal, Cycles of supersingular elliptic curves for pairing-based proof systems. IACR Communications in Cryptology, vol. 2, no. 4, Jan 08, 2026