Talks and presentations

Elliptic curve pairings as a by-product of Montgomery ladders (July 2025)

Pairings are an important tool in elliptic curve- and isogeny-based cryptography. We show pairing computations can be practical even over generic elliptic curves and field characteristics without optimized parameters, via an approach proposed by Robert (2024). Using cubical arithmetic on an elliptic curve, resulting from a small adjustment to standard projective x-only point arithmetic, pairing information comes as a direct by-product of Montgomery ladders. Cubical pairings are simpler and more performant than state-of-the-art pairings computed using Miller’s algorithm, in the case of generic base fields and curves. We observe speedups in use-cases in isogeny based cryptography (around 1.7x in SQIsign, 1.075x in CSIDH) and we discuss the practicality of the new approach when applied to other contexts.

slides

Montgomery ladders already compute pairings (April 2025)

Discussion of eprint 2025/672, with focus on the relevant aspects to pairing-based cryptography.

slides

Montgomery ladders already compute pairings (April 2025)

Pairings are an important tool in elliptic curve- and isogeny-based cryptography. We show pairing computations can be practical even over generic elliptic curves and field characteristics without optimized parameters, via an approach proposed by Robert (2024). Using cubical arithmetic on an elliptic curve, resulting from a small adjustment to standard projective x-only point arithmetic, pairing information comes as a direct by-product of Montgomery ladders. Cubical pairings are simpler and more performant than state-of-the-art pairings computed using Miller’s algorithm, in the case of generic base fields and curves. We observe speedups in use-cases in isogeny based cryptography (around 1.7x in SQIsign, 1.075x in CSIDH) and we discuss the practicality of the new approach when applied to other contexts.

slides