Simple and exact formula for minimum loop length in Ate i pairing based on Brezing-Weng curves

Hoon Hong, Eunjeong Lee, Hyang Sook Lee, Cheol Min Park

Research output: Contribution to journalArticlepeer-review

7 Scopus citations


We provide a simple and exact formula for the minimum Miller loop length in Ate i pairing based on Brezing-Weng curves, in terms of the involved parameters, under a mild condition on the parameters. It will also be shown that almost all cryptographically useful/meaningful parameters satisfy the mild condition. Hence the simple and exact formula is valid for them. It will also turn out that the formula depends only on essentially two parameters, providing freedom to choose the other parameters to address the design issues other than minimizing the loop length.

Original languageEnglish
Pages (from-to)271-292
Number of pages22
JournalDesigns, Codes, and Cryptography
Issue number2
StatePublished - May 2013

Bibliographical note

Funding Information:
Acknowledgement Eunjeong Lee was supported by the Priority Research Centers Program through the National Research Foundation of Korea (NRF) grant funded by the Ministry of Education, Science and Technology (No. 2009-0093827). Hyang-Sook Lee and Cheol-Min Park were supported by the National Research Foundation of Korea (NRF) grant funded by the Ministry of Education, Science and Technology. (No.2010-0000402). We would like to thank the anonymous referees for their insightful and helpful suggestions.


  • Elliptic curves
  • Miller algorithm
  • Pairing-based cryptosystem


Dive into the research topics of 'Simple and exact formula for minimum loop length in Ate i pairing based on Brezing-Weng curves'. Together they form a unique fingerprint.

Cite this