Re: [Cfrg] I-D Action: draft-irtf-cfrg-pairing-friendly-curves-08.txt

Yumi Sakemi <> Wed, 30 September 2020 12:48 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id F06CA3A041B for <>; Wed, 30 Sep 2020 05:48:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id DArPOOhAPkSD for <>; Wed, 30 Sep 2020 05:48:30 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:4864:20::c2d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 5DB533A0410 for <>; Wed, 30 Sep 2020 05:48:30 -0700 (PDT)
Received: by with SMTP id g26so431716ooa.9 for <>; Wed, 30 Sep 2020 05:48:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=VEbHgltGM7cb25JJFU5mGWhlmX+qqGkAF4olbsS3iks=; b=OEceGePy1GdFtzXtDptKfKVRfqmulOaT80QY/o8HTLo0wbkCUjweipcjLYG2zveCzI deTbRa6JP4cmdE4h4aRlK8sjmCxssNhZH7mcYsqoZKjwF/LaXZg/AIxI494IveGsZebK 4hvqo/Li5apmsa/nHdlXVWTqdww/VujiLA6PAGwc241i7pLg7b6oqDeY1LErM4fiX8IW uc88LExy+RaW2F7Nky8yW1hgRIV5upGbfX2o5ZWY039aI7zaqZO/u03fKC6G3f8Hdl5c FGcJ3GByj12HQbkMzDWzk6tK30vRgOuujSEgeu9qYR4+q8LXaAFcWYYmAlzeWrhWenio rldg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=VEbHgltGM7cb25JJFU5mGWhlmX+qqGkAF4olbsS3iks=; b=OGZy1cPkRn9Jg6p85G1xgp9qF6PqEl9A/OqBIvYuXDknxffvnnSo43Tj4DP75Eno1B 2jgMGB2+s+0prOhzsdMSeWCoHMzqreulcHta5z+tVAWg7OAX3CSdV92c38nQa6ZwlbfX e73Grb04l5gtHvw7A0AvKI8GhOAxybovhhmOneiWgwNHhjHjcApsyX0y0PBrTisSTXNV QsVhLNQpFipqvw3btIghz8j5qwjuOZMhIsUyPkWXuocL+J8oCILQxMRm4T2GZ9CJ0Ry9 RDmgpQExIPFe4iTIpA9O9HpQuYnh8gdi7V4Sl2TtE0GjZDqDQtOuH5nXipFc6DaDelU7 C6jQ==
X-Gm-Message-State: AOAM5326KlOri613yWlLS5n0grod7bSmj/LdENogrE5SS+Aiee/1LsM7 oRkRTZmPYaTMCKc1C5zovORpAQYkiNWlNslj2qRapNiwvEgA2Q==
X-Google-Smtp-Source: ABdhPJyY8eMyRPOYt04yjgK38rzIwRW51H+2UjkiocCYzlY34g89wUuoEoD9ehyTdLxInnZyRTqhtAWtMwBR65hWGSw=
X-Received: by 2002:a4a:1a44:: with SMTP id 65mr1913321oof.30.1601470109145; Wed, 30 Sep 2020 05:48:29 -0700 (PDT)
MIME-Version: 1.0
References: <>
In-Reply-To: <>
From: Yumi Sakemi <>
Date: Wed, 30 Sep 2020 21:48:18 +0900
Message-ID: <>
To: CFRG <>
Cc: Tetsutaro Kobayashi <>, SAITO Tsunekazu <>, "Riad S. Wahby" <>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <>
Subject: Re: [Cfrg] I-D Action: draft-irtf-cfrg-pairing-friendly-curves-08.txt
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 30 Sep 2020 12:48:32 -0000

Dear CFRG members

We submitted the version 08 of the draft "Pairing-Friendly Curves".

In the latest draft, about 50 comments given from CFRG members after
the RGLC were considered and reflected, as necessary.
We greatly appreciate Rene and Armando for a lot of comments!

We have deeply discussed the received comments, and our consideration
results were answered one by one on CFRG's official GitHub page.
You can check them by the following page.
If you find any issues with the revisions, we'd be glad to contact from you.

Many of the revisions are editorial, adding citations, a revision of
Table1 and to make the description of the fundamental technology more
Regarding Table 1, several CFRG members complained that it was too
large, so we leave only the adoption status with safe parameters in
the main section and move the rest to the appendix.

The 08 version is unchanged in the essence of the proposal, and the
quality of the draft is improved through editorial comments and more
detailed technical explanations.

Best regards,

2020年9月30日(水) 21:42 <>:
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Crypto Forum RG of the IRTF.
>         Title           : Pairing-Friendly Curves
>         Authors         : Yumi Sakemi
>                           Tetsutaro Kobayashi
>                           Tsunekazu Saito
>                           Riad S. Wahby
>         Filename        : draft-irtf-cfrg-pairing-friendly-curves-08.txt
>         Pages           : 54
>         Date            : 2020-09-30
> Abstract:
>    Pairing-based cryptography, a subfield of elliptic curve
>    cryptography, has received attention due to its flexible and
>    practical functionality.  Pairings are special maps defined using
>    elliptic curves and it can be applied to construct several
>    cryptographic protocols such as identity-based encryption, attribute-
>    based encryption, and so on.  At CRYPTO 2016, Kim and Barbulescu
>    proposed an efficient number field sieve algorithm named exTNFS for
>    the discrete logarithm problem in a finite field.  Several types of
>    pairing-friendly curves such as Barreto-Naehrig curves are affected
>    by the attack.  In particular, a Barreto-Naehrig curve with a 254-bit
>    characteristic was adopted by a lot of cryptographic libraries as a
>    parameter of 128-bit security, however, it ensures no more than the
>    100-bit security level due to the effect of the attack.  In this
>    memo, we list the security levels of certain pairing-friendly curves,
>    and motivate our choices of curves.  First, we summarize the adoption
>    status of pairing-friendly curves in standards, libraries and
>    applications, and classify them in the 128-bit, 192-bit, and 256-bit
>    security levels.  Then, from the viewpoints of "security" and "widely
>    used", we select the recommended pairing-friendly curves considering
>    exTNFS.
> The IETF datatracker status page for this draft is:
> There is also a HTML versions available at:
> A diff from the previous version is available at:
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at
> Internet-Drafts are also available by anonymous FTP at:
> _______________________________________________
> Cfrg mailing list

Yumi Sakemi, Ph. D.
Lepidum Co. Ltd.