IACR Communications in Cryptology IACR CiC

Simpler and Faster Pairings from the Montgomery Ladder

Authors

Giacomo Pope, Krijn Reijnders, Damien Robert, Alessandro Sferlazza, Benjamin Smith
Giacomo Pope ORCID
NCC Group, United Kingdom
University of Bristol, United Kingdom
giacomopope at gmail dot com
Krijn Reijnders ORCID
COSIC, KU Leuven, Belgium
crypto dot krijn at gmail dot com
Damien Robert ORCID
Inria Bordeaux, Institut de Mathématiques de Bordeaux, France
damien dot robert at inria dot fr
Alessandro Sferlazza ORCID
Technical University of Munich, Germany
alessandro dot sferlazza at tum dot de
Benjamin Smith ORCID
Inria, France
LIX, CNRS, École polytechnique, Institut Polytechnique de Paris, France
smith at lix dot polytechnique dot fr

Abstract

We show that Montgomery ladders compute pairings as a by-product, and explain how a small adjustment to the ladder results in simple and efficient algorithms for the Weil and Tate pairing on elliptic curves using cubical arithmetic. We demonstrate the efficiency of the resulting cubical pairings in several applications from isogeny-based cryptography. Cubical pairings are simpler and more performant than pairings computed using Miller's algorithm: we get a speed-up of over 40 per cent for use-cases in SQIsign, and a speed-up of about 7 per cent for use-cases in CSIDH. While these results arise from a deep connection to biextensions and cubical arithmetic, in this article we keep things as concrete (and digestible) as possible. We provide a concise and complete introduction to cubical arithmetic as an appendix.

References

[AAA+25]
Marius A. Aardal, Gora Adj, Diego F. Aranha, Andrea Basso, Isaac Andrés Canales Martínez, Jorge Chávez-Saab, Maria Corte-Real Santos, Pierrick Dartois, Luca De Feo, Max Duparc, Jonathan Komada Eriksen, Tako Boris Fouotsa, Décio Luiz Gazzoni Filho, Basil Hess, David Kohel, Antonin Leroux, Patrick Longa, Luciano Maino, Michael Meyer, Kohei Nakagawa, Hiroshi Onuki, Lorenz Panny, Sikhar Patranabis, Christophe Petit, Giacomo Pope, Krijn Reijnders, Damien Robert, Francisco Rodríguez-Henríquez, Sina Schaeffler, and Benjamin Wesolowski. SQIsign. Technical report, National Institute of Standards and Technology. 2025.
[AHG23]
Diego F. Aranha, Youssef El Housni, and Aurore Guillevic. A survey of elliptic curves for proof systems. Des. Codes Cryptogr., 91(11):3333–3378, 2023. DOI: 10.1007/S10623-022-01135-Y
[BDD+24]
Andrea Basso, Pierrick Dartois, Luca De Feo, Antonin Leroux, Luciano Maino, Giacomo Pope, Damien Robert, and Benjamin Wesolowski. SQIsign2D-West - The Fast, the Small, and the Safer. In Kai-Min Chung and Yu Sasaki, editors, ASIACRYPT 2024, Part III, volume 15486 of LNCS, pages 339–370, Kolkata, India. 2024. Springer, Singapore, Singapore. DOI: 10.1007/978-981-96-0891-1_11
[BF01]
Dan Boneh and Matthew K. Franklin. Identity-Based Encryption from the Weil Pairing. In Joe Kilian, editor, CRYPTO 2001, volume 2139 of LNCS, pages 213–229, Santa Barbara, CA, USA. 2001. Springer Berlin Heidelberg, Germany. DOI: 10.1007/3-540-44647-8_13
[BGS22]
Gustavo Banegas, Valerie Gilchrist, and Benjamin Smith. Efficient supersingularity testing over $\mathbb{F}_p$ and CSIDH key validation. Mathematical Cryptology, 2(1):21–35, 2022.
[BJ02]
Eric Brier and Marc Joye. Weierstraß Elliptic Curves and Side-Channel Attacks. In David Naccache and Pascal Paillier, editors, Public Key Cryptography, 5th International Workshop on Practice and Theory in Public Key Cryptosystems, PKC 2002, Paris, France, February 12-14, 2002, Proceedings, volume 2274 of Lecture Notes in Computer Science, pages 335–345. 2002. Springer. DOI: 10.1007/3-540-45664-3_24
[BLS04]
Dan Boneh, Ben Lynn, and Hovav Shacham. Short Signatures from the Weil Pairing. Journal of Cryptology, 17(4):297–319, September 2004. DOI: 10.1007/s00145-004-0314-9
[Bre83]
Lawrence Breen. Fonctions thêta et théoreme du cube, volume 980 of Lecture Notes in Mathematics. Lecture Notes in Mathematics. Springer 1983. DOI: 10.1007/BFb0065683
[CCC+24]
Fabio Campos, Jorge Chávez-Saab, Jesús-Javier Chi-Domínguez, Michael Meyer, Krijn Reijnders, Francisco Rodríguez-Henríquez, Peter Schwabe, and Thom Wiggers. Optimizations and Practicality of High-Security CSIDH. CiC, 1(1):5, 2024. DOI: 10.62056/anjbksdja
[CD23]
Wouter Castryck and Thomas Decru. An Efficient Key Recovery Attack on SIDH. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 423–447, Lyon, France. 2023. Springer, Cham, Switzerland. DOI: 10.1007/978-3-031-30589-4_15
[CHM+23]
Wouter Castryck, Marc Houben, Simon-Philipp Merz, Marzio Mula, Sam van Buuren, and Frederik Vercauteren. Weak Instances of Class Group Action Based Cryptography via Self-pairings. In Helena Handschuh and Anna Lysyanskaya, editors, CRYPTO 2023, Part III, volume 14083 of LNCS, pages 762–792, Santa Barbara, CA, USA. 2023. Springer, Cham, Switzerland. DOI: 10.1007/978-3-031-38548-3_25
[CHMR25]
Fabio Campos, Andreas Hellenbrand, Michael Meyer, and Krijn Reijnders. dCTIDH: Fast and Deterministic CTIDH. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025(3):516–541, 2025. DOI: 10.46586/tches.v2025.i3.516-541
[CJL+17]
Craig Costello, David Jao, Patrick Longa, Michael Naehrig, Joost Renes, and David Urbanik. Efficient Compression of SIDH Public Keys. In Jean-Sébastien Coron and Jesper Buus Nielsen, editors, EUROCRYPT 2017, Part I, volume 10210 of LNCS, pages 679–706, Paris, France. 2017. Springer, Cham, Switzerland. DOI: 10.1007/978-3-319-56620-7_24
[CLM+18]
Wouter Castryck, Tanja Lange, Chloe Martindale, Lorenz Panny, and Joost Renes. CSIDH: An Efficient Post-Quantum Commutative Group Action. In Thomas Peyrin and Steven Galbraith, editors, ASIACRYPT 2018, Part III, volume 11274 of LNCS, pages 395–427, Brisbane, Queensland, Australia. 2018. Springer, Cham, Switzerland. DOI: 10.1007/978-3-030-03332-3_15
[CLZ24]
Shiping Cai, Kaizhan Lin, and Chang-An Zhao. Pairing Optimizations for Isogeny-Based Cryptosystems. IET Information Security, 2024(1):9631360, 2024. DOI: https://doi.org/10.1049/2024/9631360
[CR24]
Maria Corte-Real Santos and Krijn Reijnders. Return of the Kummer: a Toolbox for Genus-2 Cryptography. Cryptology ePrint Archive, Paper 2024/948. 2024.
[CS18]
Craig Costello and Benjamin Smith. Montgomery curves and their arithmetic - The case of large characteristic fields. Journal of Cryptographic Engineering, 8(3):227–240, September 2018. DOI: 10.1007/s13389-017-0157-6
[DJP14]
Luca De Feo, David Jao, and Jérôme Plût. Towards quantum-resistant cryptosystems from supersingular elliptic curve isogenies. Journal of Mathematical Cryptology, 8(3):209–247, 2014. DOI: doi:10.1515/jmc-2012-0015
[DKL+20]
Luca De Feo, David Kohel, Antonin Leroux, Christophe Petit, and Benjamin Wesolowski. SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies. In Shiho Moriai and Huaxiong Wang, editors, ASIACRYPT 2020, Part I, volume 12491 of LNCS, pages 64–93, Daejeon, South Korea. 2020. Springer, Cham, Switzerland. DOI: 10.1007/978-3-030-64837-4_3
[Dol18]
Javad Doliskani. On division polynomial PIT and supersingularity. Applicable Algebra in Engineering, Communication and Computing, 29(5):393–407, 2018. DOI: 10.1007/s00200-018-0349-z
[FR94]
Gerhard Frey and Hans-Georg Rück. A remark concerning $m$-divisibility and the discrete logarithm in the divisor class group of curves. Mathematics of computation, 62(206):865–874, 1994. DOI: 10.2307/2153546
[Gro72]
Alexandre Grothendieck. Groupes de Monodromie en Géométrie Algébrique: SGA 7. Springer-Verlag 1972.
[HSV06]
Florian Hess, Nigel P. Smart, and Frederik Vercauteren. The Eta Pairing Revisited. IEEE Trans. Inf. Theory, 52(10):4595–4602, 2006. DOI: 10.1109/TIT.2006.881709
[IT02]
Tetsuya Izu and Tsuyoshi Takagi. A Fast Parallel Elliptic Curve Multiplication Resistant against Side Channel Attacks. In David Naccache and Pascal Paillier, editors, Public Key Cryptography, 5th International Workshop on Practice and Theory in Public Key Cryptosystems, PKC 2002, Paris, France, February 12-14, 2002, Proceedings, volume 2274 of Lecture Notes in Computer Science, pages 280–296. 2002. Springer. DOI: 10.1007/3-540-45664-3_20
[JAC+22]
David Jao, Reza Azarderakhsh, Matthew Campagna, Craig Costello, Luca De Feo, Basil Hess, Amir Jalali, Brian Koziel, Brian LaMacchia, Patrick Longa, Michael Naehrig, Joost Renes, Vladimir Soukharev, David Urbanik, Geovandro Pereira, Koray Karabina, and Aaron Hutchinson. SIKE. Technical report, National Institute of Standards and Technology. available at https://csrc.nist.gov/Projects/post-quantum-cryptography/round-4-submissions. 2022.
[Jou00]
Antoine Joux. A One Round Protocol for Tripartite Diffie-Hellman. In Wieb Bosma, editor, Algorithmic Number Theory, 4th International Symposium, ANTS-IV, Leiden, The Netherlands, July 2-7, 2000, Proceedings, volume 1838 of Lecture Notes in Computer Science, pages 385–394. 2000. Springer. DOI: 10.1007/10722028_23
[Lic69]
Stephen Lichtenbaum. Duality theorems for curves over $p$-adic fields. Inventiones mathematicae, 7(2):120–136, 1969. DOI: 10.1007/BF01389795
[LR16]
David Lubicz and Damien Robert. Arithmetic on Abelian and Kummer Varieties. Finite Fields and Their Applications, 39:130–158, May 2016. DOI: 10.1016/j.ffa.2016.01.009
[LRZZ25]
Jianming Lin, Damien Robert, Chang-An Zhao, and Yuhao Zheng. Biextensions in pairing-based cryptography. Cryptology ePrint Archive, Paper 2025/670. 2025.
[Mil04]
Victor S Miller. The Weil pairing, and its efficient calculation. Journal of cryptology, 17(4):235–261, 2004. DOI: 10.1007/s00145-004-0315-8
[MMP+23]
Luciano Maino, Chloe Martindale, Lorenz Panny, Giacomo Pope, and Benjamin Wesolowski. A Direct Key Recovery Attack on SIDH. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 448–471, Lyon, France. 2023. Springer, Cham, Switzerland. DOI: 10.1007/978-3-031-30589-4_16
[Mon87]
Peter L Montgomery. Speeding the Pollard and elliptic curve methods of factorization. Mathematics of computation, 48(177):243–264, 1987. DOI: 10.2307/2007888
[Mor85]
L. Moret-Bailly. Pinceaux de variétés abéliennes. Société mathématique de France 1985.
[MS24]
Joseph Macula and Katherine E Stange. Extending class group action attacks via sesquilinear pairings. 2024.
[MVO91]
Alfred Menezes, Scott A. Vanstone, and Tatsuaki Okamoto. Reducing Elliptic Curve Logarithms to Logarithms in a Finite Field. In 23rd ACM STOC, pages 80–89, New Orleans, LA, USA. 1991. ACM Press. DOI: 10.1145/103418.103434
[NR19]
Michael Naehrig and Joost Renes. Dual Isogenies and Their Application to Public-Key Compression for Isogeny-Based Cryptography. In Steven D. Galbraith and Shiho Moriai, editors, ASIACRYPT 2019, Part II, volume 11922 of LNCS, pages 243–272, Kobe, Japan. 2019. Springer, Cham, Switzerland. DOI: 10.1007/978-3-030-34621-8_9
[Por20]
Thomas Pornin. Optimized Binary GCD for Modular Inversion. Cryptology ePrint Archive, Paper 2020/972. 2020.
[Rei23]
Krijn Reijnders. Effective Pairings in Isogeny-Based Cryptography. In Abdelrahaman Aly and Mehdi Tibouchi, editors, Progress in Cryptology - LATINCRYPT 2023 - 8th International Conference on Cryptology and Information Security in Latin America, LATINCRYPT 2023, Quito, Ecuador, October 3-6, 2023, Proceedings, volume 14168 of Lecture Notes in Computer Science, pages 109–128. 2023. Springer. DOI: 10.1007/978-3-031-44469-2_6
[Rob23]
Damien Robert. Breaking SIDH in Polynomial Time. In Carmit Hazay and Martijn Stam, editors, EUROCRYPT 2023, Part V, volume 14008 of LNCS, pages 472–503, Lyon, France. 2023. Springer, Cham, Switzerland. DOI: 10.1007/978-3-031-30589-4_17
[Rob24]
Damien Robert. Fast pairings via biextensions and cubical arithmetic. Cryptology ePrint Archive, Report 2024/517. April 2024.
[Sfe24]
Alessandro Sferlazza. Hyperelliptic biextension pairings. SageMath 10.3 library. 2024.
[Sta03]
Martijn Stam. Speeding up subgroup cryptosystems. PhD thesis. Technische Universiteit Eindhoven, 2003.
[Sta07]
Katherine E Stange. The Tate pairing via elliptic nets. In Pairing-Based Cryptography–Pairing 2007: First International Conference, Tokyo, Japan, July 2-4, 2007. Proceedings 1, pages 329–348. 2007. Springer. DOI: 10.1007/978-3-540-73489-5_19
[Sta08]
Katherine Stange. Elliptic nets and elliptic curves. PhD thesis. Brown University, 2008.
[Tat62]
John Tate. Duality theorems in Galois cohomology over number fields. In Proc. Internat. Congr. Mathematicians (Stockholm, 1962), pages 288–295. 1962.
[Wei40]
André Weil. Sur les fonctions algébriques à corps de constantes fini. CR Acad. Sci. Paris, 210(1940):592–594, 1940.

PDFPDF Open access

History
Submitted: 2025-04-08
Accepted: 2025-06-02
Published: 2025-07-07
Crossmark logo
How to cite

Giacomo Pope, Krijn Reijnders, Damien Robert, Alessandro Sferlazza, and Benjamin Smith, Simpler and Faster Pairings from the Montgomery Ladder. IACR Communications in Cryptology, vol. 2, no. 2, Jul 07, 2025, doi: 10.62056/ah2i893y6.

Citations

There are at least 6 citations.

License

Copyright is held by the author(s)

This work is licensed under a Creative Commons Attribution (CC BY) license.