Affine pairings on ARM

T. Acar, K. Lauter, M. Naehrig, D. Shumow

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

10 Citations (Scopus)


We report on relative performance numbers for affine and projective pairings on a dual-core Cortex A9 ARM processor. Using a fast inversion in the base field and doing inversion in extension fields by using the norm map to reduce to inversions in smaller fields, we find a very low ratio of inversion-to-multiplication costs. In our implementation, this favors using affine coordinates, even for the current 128-bit minimum security level specified by NIST. We use Barreto-Naehrig (BN) curves and report on the performance of an optimal ate pairing for curves covering security levels between 128 and 192 bits.We compare with other reported performance numbers for pairing computation on ARM CPUs.
Original languageEnglish
Title of host publicationPairing-Based Cryptography – Pairing 2012 ()
EditorsM. Abdalla, T. Lange
Place of PublicationBerlin
ISBN (Print)978-3-642-36333-7
Publication statusPublished - 2013
Eventconference; Pairing 2012; 2012-05-16; 2012-05-18 -
Duration: 16 May 201218 May 2012

Publication series

NameLecture Notes in Computer Science
ISSN (Print)0302-9743


Conferenceconference; Pairing 2012; 2012-05-16; 2012-05-18
OtherPairing 2012


Dive into the research topics of 'Affine pairings on ARM'. Together they form a unique fingerprint.

Cite this