constantine
constantine copied to clipboard
Miller Loop Quadruple-and-add and Octuple-and-add
The paper
- Avoiding Full Extension Field Arithmetic inPairing Computations
Craig Costello, Colin Boyd, Juan Manuel Gonz alez Nieto, and Kenneth Koon-Ho Wong, 2010
https://eprint.iacr.org/2010/104.pdf
Proposes quadruple-and-add and octuple-and-add to trade multiplication in Fp12 for lots of multiplication in Fp


Multiplication in Fp12 is at the moment over 100x more costly than Fp