{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T14:19:37Z","timestamp":1783520377493,"version":"3.55.0"},"publisher-location":"Cham","reference-count":81,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032311290","type":"print"},{"value":"9783032311306","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-31130-6_12","type":"book-chapter","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T13:38:41Z","timestamp":1783517921000},"page":"288-315","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Batch Subgroup Membership Testing on\u00a0Pairing-Friendly Curves"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4796-8989","authenticated-orcid":false,"given":"Dimitri","family":"Koshelev","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2873-3479","authenticated-orcid":false,"given":"Youssef","family":"El Housni","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9699-3817","authenticated-orcid":false,"given":"Georgios","family":"Fotiadis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,9]]},"reference":[{"key":"12_CR1","unstructured":"The decaf377 group. https:\/\/protocol.penumbra.zone\/main\/crypto\/decaf377.html"},{"key":"12_CR2","doi-asserted-by":"publisher","unstructured":"Aranha, D.F., Salling Hvass, B., Spitters, B., Tibouchi, M.: Faster constant-time evaluation of the Kronecker symbol with application to elliptic curve hashing. In: CCS 2023: ACM SIGSAC Conference on Computer and Communications Security, pp. 3228\u20133238. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3576915.3616597","DOI":"10.1145\/3576915.3616597"},{"key":"12_CR3","unstructured":"Aumasson, J.P., Nguyen, Q.T.M., Sanso, A.: Security of BLS batch verification (2021). https:\/\/ethresear.ch\/t\/security-of-bls-batch-verification\/10748"},{"key":"12_CR4","doi-asserted-by":"publisher","unstructured":"Barbulescu, R., Duquesne, S.: Updating key size estimations for pairings. J. Cryptol. 32(4), 1298\u20131336 (2019). https:\/\/doi.org\/10.1007\/s00145-018-9280-5","DOI":"10.1007\/s00145-018-9280-5"},{"key":"12_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/978-3-319-22174-8_14","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2015","author":"PSLM Barreto","year":"2015","unstructured":"Barreto, P.S.L.M., Costello, C., Misoczki, R., Naehrig, M., Pereira, G.C.C.F., Zanon, G.: Subgroup security in pairing-based cryptography. In: Lauter, K., Rodr\u00edguez-Henr\u00edquez, F. (eds.) LATINCRYPT 2015. LNCS, vol. 9230, pp. 245\u2013265. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-22174-8_14"},{"key":"12_CR6","doi-asserted-by":"publisher","unstructured":"Barreto, P.S.L.M., Lynn, B., Scott, M.: Constructing elliptic curves with prescribed embedding degrees. In: Cimato, S., Persiano, G., Galdi, C. (eds.) Security in Communication Networks. SCN 2002. Lecture Notes in Computer Science, vol.\u00a02576, pp. 257\u2013267. Springer, Berlin, Heidelberg (2003). https:\/\/doi.org\/10.1007\/3-540-36413-7_19","DOI":"10.1007\/3-540-36413-7_19"},{"key":"12_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/11693383_22","volume-title":"Selected Areas in Cryptography","author":"PSLM Barreto","year":"2006","unstructured":"Barreto, P.S.L.M., Naehrig, M.: Pairing-friendly elliptic curves of prime order. In: Preneel, B., Tavares, S. (eds.) SAC 2005. LNCS, vol. 3897, pp. 319\u2013331. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11693383_22"},{"key":"12_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1007\/BFb0054130","volume-title":"Advances in Cryptology \u2014 EUROCRYPT\u201998","author":"M Bellare","year":"1998","unstructured":"Bellare, M., Garay, J.A., Rabin, T.: Fast batch verification for modular exponentiation and digital signatures. In: Nyberg, K. (ed.) EUROCRYPT 1998. LNCS, vol. 1403, pp. 236\u2013250. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0054130"},{"key":"12_CR9","doi-asserted-by":"publisher","unstructured":"Bernstein, D.J., Doumen, J., Lange, T., Oosterwijk, J.J.: Faster batch forgery identification. In: Galbraith, S., Nandi, M. (eds.) Progress in Cryptology \u2013 INDOCRYPT 2012. Lecture Notes in Computer Science, vol.\u00a07668, pp. 454\u2013473. Springer, Berlin, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34931-7_26","DOI":"10.1007\/978-3-642-34931-7_26"},{"key":"12_CR10","unstructured":"Boneh, D., et al.: BLS signatures (2025). https:\/\/datatracker.ietf.org\/doc\/draft-irtf-cfrg-bls-signature"},{"key":"12_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1007\/978-3-030-03329-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"D Boneh","year":"2018","unstructured":"Boneh, D., Drijvers, M., Neven, G.: Compact multi-signatures for smaller blockchains. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11273, pp. 435\u2013464. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03329-3_15"},{"key":"12_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/3-540-44647-8_13","volume-title":"Advances in Cryptology \u2014 CRYPTO 2001","author":"D Boneh","year":"2001","unstructured":"Boneh, D., Franklin, M.: Identity-based encryption from the Weil pairing. In: Kilian, J. (ed.) CRYPTO 2001. LNCS, vol. 2139, pp. 213\u2013229. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44647-8_13"},{"key":"12_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"416","DOI":"10.1007\/3-540-39200-9_26","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2003","author":"D Boneh","year":"2003","unstructured":"Boneh, D., Gentry, C., Lynn, B., Shacham, H.: Aggregate and verifiably encrypted signatures from bilinear maps. In: Biham, E. (ed.) EUROCRYPT 2003. LNCS, vol. 2656, pp. 416\u2013432. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/3-540-39200-9_26"},{"key":"12_CR14","doi-asserted-by":"publisher","unstructured":"Boneh, D., Lynn, B., Shacham, H.: Short signatures from the Weil pairing. J. Cryptol. 17(4), 297\u2013319 (2004). https:\/\/doi.org\/10.1007\/s00145-004-0314-9","DOI":"10.1007\/s00145-004-0314-9"},{"key":"12_CR15","unstructured":"Botrel, G., Piellard, T., El Housni, Y., Tabaie, A., Gutoski, G., Kubjas, I.: Consensys\/gnark-crypto: v0.19.2 (2025). https:\/\/doi.org\/10.5281\/zenodo.5815453"},{"key":"12_CR16","unstructured":"Bowe, S.: BLS12-381: New zk-SNARK elliptic curve construction (2017). https:\/\/electriccoin.co\/blog\/new-snark-curve"},{"key":"12_CR17","unstructured":"Bowe, S.: Switch from BN254 to BLS12-381 (2017). https:\/\/github.com\/zcash\/zcash\/issues\/2502"},{"key":"12_CR18","unstructured":"Bowe, S.: Faster subgroup checks for BLS12-381 (2019). https:\/\/eprint.iacr.org\/2019\/814"},{"key":"12_CR19","doi-asserted-by":"publisher","unstructured":"Bowe, S., Chiesa, A., Green, M., Miers, I., Mishra, P., Wu, H.: Zexe: enabling decentralized private computation. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 947\u2013964. IEEE, New York (2020). https:\/\/doi.org\/10.1109\/SP40000.2020.00050","DOI":"10.1109\/SP40000.2020.00050"},{"key":"12_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1007\/3-540-44448-3_5","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2000","author":"C Boyd","year":"2000","unstructured":"Boyd, C., Pavlovski, C.: Attacking and repairing batch verification schemes. In: Okamoto, T. (ed.) ASIACRYPT 2000. LNCS, vol. 1976, pp. 58\u201371. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44448-3_5"},{"key":"12_CR21","unstructured":"Brier, E., G\u00e9raud-Stewart, R., Joye, M., Naccache, D.: Primary elements in cyclotomic fields with applications to power residue symbols, and more (2021). https:\/\/eprint.iacr.org\/2021\/1106"},{"key":"12_CR22","unstructured":"Brier, E., Naccache, D.: The thirteenth power residue symbol (2019). https:\/\/eprint.iacr.org\/2019\/1176"},{"key":"12_CR23","doi-asserted-by":"publisher","unstructured":"Budroni, A., Pintore, F.: Efficient hash maps to $$\\mathbb{G} _2$$ on BLS curves. Appl. Algebra Eng. Commun. Comput. 33(3), 261\u2013281 (2022). https:\/\/doi.org\/10.1007\/s00200-020-00453-9","DOI":"10.1007\/s00200-020-00453-9"},{"key":"12_CR24","doi-asserted-by":"crossref","unstructured":"Chen, L., Moody, D., Regenscheid, A., Robinson, A., Randall, K.: Recommendations for discrete logarithm-based cryptography: elliptic curve domain parameters (NIST Special Publication 800-186) (2023). https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-186\/final","DOI":"10.6028\/NIST.SP.800-186"},{"key":"12_CR25","doi-asserted-by":"publisher","unstructured":"Chen, Y., Peng, C., Dai, Y., Luo, M., He, D.: Load-balanced parallel implementation on GPUs for multi-scalar multiplication algorithm. IACR Trans. Cryptographic Hardware Embed. Syst. 2024(2), 522\u2013544 (2024). https:\/\/doi.org\/10.46586\/tches.v2024.i2.522-544","DOI":"10.46586\/tches.v2024.i2.522-544"},{"key":"12_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-030-65411-5_14","volume-title":"Cryptology and Network Security","author":"R Clarisse","year":"2020","unstructured":"Clarisse, R., Duquesne, S., Sanders, O.: Curves with fast computations in the first pairing group. In: Krenn, S., Shulman, H., Vaudenay, S. (eds.) CANS 2020. LNCS, vol. 12579, pp. 280\u2013298. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-65411-5_14"},{"key":"12_CR27","doi-asserted-by":"publisher","unstructured":"Dai, Y., He, D., Koshelev, D., Peng, C., Yang, Z.: Revisiting subgroup membership testing on pairing-friendly curves via the tate pairing. In: Public-Key Cryptography \u2013 PKC 2026: 29th IACR International Conference on Practice and Theory of Public-Key Cryptography, West Palm Beach, FL, USA, May 25\u201328, 2026, Proceedings, Part III, pp. 92\u2013120. Springer-Verlag, Berlin, Heidelberg (2026). https:\/\/doi.org\/10.1007\/978-3-032-26737-5_4","DOI":"10.1007\/978-3-032-26737-5_4"},{"key":"12_CR28","doi-asserted-by":"publisher","unstructured":"Dai, Y., Lin, K., Zhao, C.A., Zhou, Z.: Fast subgroup membership testings for $$\\mathbb{G}_1$$, $$\\mathbb{G}_2$$ and $$\\mathbb{G}_{T}$$ on pairing-friendly curves. Designs, Codes Crypt. 91(10), 3141\u20133166 (2023). https:\/\/doi.org\/10.1007\/s10623-023-01223-7","DOI":"10.1007\/s10623-023-01223-7"},{"key":"12_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-3-030-65411-5_13","volume-title":"Cryptology and Network Security","author":"Y El Housni","year":"2020","unstructured":"El Housni, Y., Guillevic, A.: Optimized and secure pairing-friendly elliptic curves suitable for one layer proof composition. In: Krenn, S., Shulman, H., Vaudenay, S. (eds.) CANS 2020. LNCS, vol. 12579, pp. 259\u2013279. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-65411-5_13"},{"key":"12_CR30","doi-asserted-by":"crossref","unstructured":"El Housni, Y., Guillevic, A., Piellard, T.: Co-factor clearing and subgroup membership testing on pairing-friendly curves. In: Batina, L., Daemen, J. (eds.) Progress in Cryptology \u2013 AFRICACRYPT 2022. Lecture Notes in Computer Science, vol. 13503, pp. 518\u2013536. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-17433-9_22","DOI":"10.1007\/978-3-031-17433-9_22"},{"key":"12_CR31","unstructured":"Electric Coin Company: What is Jubjub?. https:\/\/bitzecbzc.github.io\/technology\/jubjub"},{"key":"12_CR32","doi-asserted-by":"publisher","unstructured":"Fan, X., Kuchta, V., Sica, F., Xu, L.: Speeding up multi-scalar multiplications for pairing-based zkSNARKs. J. Cryptol. 38(2), 21 (2025). https:\/\/doi.org\/10.1007\/s00145-025-09540-x","DOI":"10.1007\/s00145-025-09540-x"},{"key":"12_CR33","unstructured":"Faraoun, K.M.: Why not BLS12-461 with equivalent performance? (2019). https:\/\/github.com\/zcash\/zcash\/issues\/4065"},{"key":"12_CR34","unstructured":"Gabizon, A.: Possible improvements in subgroup testing (2018). https:\/\/github.com\/zcash\/zcash\/issues\/3470"},{"key":"12_CR35","doi-asserted-by":"publisher","unstructured":"Galbraith, S.D.: Mathematics of public key cryptography. Cambridge University Press, New York (2012). https:\/\/doi.org\/10.1017\/CBO9781139012843","DOI":"10.1017\/CBO9781139012843"},{"key":"12_CR36","unstructured":"Guillevic, A., Masson, S.: Embedded curves and embedded families for SNARK-friendly curves (2024). https:\/\/eprint.iacr.org\/2024\/1737"},{"key":"12_CR37","unstructured":"Guillevic, A., Singh, S.: On the alpha value of polynomials in the tower number field sieve algorithm. Trans. Math. Cryptol. 1(1), 1\u201339 (2021). https:\/\/journals.flvc.org\/mathcryptology\/article\/view\/125142"},{"key":"12_CR38","unstructured":"Haboeck, U.: Security estimates of pairing-friendly curves (2020). https:\/\/github.com\/arkworks-rs\/algebra\/issues\/732"},{"key":"12_CR39","unstructured":"Haddaji, W., Ghammam, L., El Mrabet, N., Ben Abdelghani, L.: On computing the multidimensional scalar multiplication on elliptic curves (2024). https:\/\/eprint.iacr.org\/2024\/038"},{"key":"12_CR40","unstructured":"Hamburg, M.: Computing the Jacobi symbol using Bernstein\u2013Yang (2021). https:\/\/eprint.iacr.org\/2021\/1271"},{"key":"12_CR41","doi-asserted-by":"crossref","unstructured":"Harn, L.: Batch verifying multiple RSA digital signatures. Electron. Lett. 34(12), 1219\u20131220 (1998). https:\/\/doi.org\/10.1049\/el:19980833","DOI":"10.1049\/el:19980833"},{"key":"12_CR42","unstructured":"Henry, R.: Pippenger\u2019s multiproduct and multiexponentiation algorithms (2010). https:\/\/cacr.uwaterloo.ca\/techreports\/2010\/cacr2010-26.pdf"},{"key":"12_CR43","unstructured":"Hopwood, D.E.: Understand the concrete security level of the BN_128 curve in libsnark (2024). https:\/\/github.com\/zcash\/zcash\/issues\/714"},{"key":"12_CR44","doi-asserted-by":"crossref","unstructured":"Jiang, R., Peng, C., Luo, M., Chen, R., He, D.: SimdMSM: SIMD-accelerated multi-scalar multiplication framework for zkSNARKs. IACR Trans. Crypt. Hardware Embed. Syst. 2025(2), 681\u2013704 (2025). https:\/\/doi.org\/10.46586\/tches.v2025.i2.681-704","DOI":"10.46586\/tches.v2025.i2.681-704"},{"key":"12_CR45","doi-asserted-by":"publisher","unstructured":"Joux, A.: A one round protocol for tripartite Diffie\u2013Hellman. J. Cryptol. 17(4), 263\u2013276 (2004). https:\/\/doi.org\/10.1007\/s00145-004-0312-y","DOI":"10.1007\/s00145-004-0312-y"},{"key":"12_CR46","doi-asserted-by":"publisher","unstructured":"Joye, M., Lapiha, O., Nguyen, K., Naccache, D.: The eleventh power residue symbol. J. Math. Cryptol. 15(1), 111\u2013122 (2021). https:\/\/doi.org\/10.1515\/jmc-2020-0077","DOI":"10.1515\/jmc-2020-0077"},{"key":"12_CR47","doi-asserted-by":"publisher","unstructured":"Keilty, A.P., Aranha, D.F., Pagnin, E., Rodr\u00edguez-Henr\u00edquez, F.: That\u2019s AmorE: amortized efficiency for pairing delegation. In: Tauman Kalai, Y., Kamara, S.F. (eds.) Advances in Cryptology \u2013 CRYPTO 2025. Lecture Notes in Computer Science, vol. 16007, pp. 211\u2013246. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-032-01913-4_7","DOI":"10.1007\/978-3-032-01913-4_7"},{"key":"12_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"543","DOI":"10.1007\/978-3-662-53018-4_20","volume-title":"Advances in Cryptology \u2013 CRYPTO 2016","author":"T Kim","year":"2016","unstructured":"Kim, T., Barbulescu, R.: Extended tower number field sieve: a new complexity for the medium prime case. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016. LNCS, vol. 9814, pp. 543\u2013571. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53018-4_20"},{"key":"12_CR49","doi-asserted-by":"publisher","unstructured":"Koshelev, D.: Subgroup membership testing on elliptic curves via the Tate pairing. J. Crypt. Eng. 13(1), 125\u2013128 (2023). https:\/\/doi.org\/10.1007\/s13389-022-00296-9","DOI":"10.1007\/s13389-022-00296-9"},{"key":"12_CR50","doi-asserted-by":"publisher","unstructured":"Koshelev, D.: Correction to: subgroup membership testing on elliptic curves via the Tate pairing. J. Crypt. Eng. 14(1), 127\u2013128 (2024). https:\/\/doi.org\/10.1007\/s13389-023-00331-3","DOI":"10.1007\/s13389-023-00331-3"},{"key":"12_CR51","doi-asserted-by":"publisher","unstructured":"Koshelev, D.: Application of Mordell\u2013Weil lattices with large kissing numbers to acceleration of multiscalar multiplication on elliptic curves. J. Math. Crypt. 19(1), 20240034 (2025). https:\/\/doi.org\/10.1515\/jmc-2024-0034","DOI":"10.1515\/jmc-2024-0034"},{"key":"12_CR52","unstructured":"Koshelev, D., El Housni, Y., Fotiadis, G.: Batch-subgroup-membership-testing (2025). https:\/\/github.com\/yelhousni\/batch-subgroup-membership-testing"},{"key":"12_CR53","unstructured":"Koshelev, D., Sanso, A.: Endomorphisms for faster cryptography on elliptic curves of moderate CM discriminants. In: Capuano, L., Civino, R., Romeo, F., Santilli, G. (eds.) CIFRIS25 ACTA. De Cifris Koine, vol.\u00a07, pp. 97\u2013121. De Cifris Press, Milano (2025). https:\/\/doi.org\/10.69091\/koine\/vol-7-W09"},{"key":"12_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/BFb0052240","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201997","author":"CH Lim","year":"1997","unstructured":"Lim, C.H., Lee, P.J.: A key recovery attack on discrete log-based schemes using a prime order subgroup. In: Kaliski, B.S. (ed.) CRYPTO 1997. LNCS, vol. 1294, pp. 249\u2013263. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0052240"},{"key":"12_CR55","doi-asserted-by":"publisher","unstructured":"Lin, J., Robert, D., Zhao, C.A., Zheng, Y.: Biextensions in pairing-based cryptography. Designs, Codes Crypt. 94(1), 5 (2026). https:\/\/doi.org\/10.1007\/s10623-025-01762-1","DOI":"10.1007\/s10623-025-01762-1"},{"key":"12_CR56","doi-asserted-by":"publisher","unstructured":"Masson, S., Sanso, A., Zhang, Z.: Bandersnatch: a fast elliptic curve built over the BLS12-381 scalar field. Designs, Codes Crypt. 92(12), 4131\u20134143 (2024). https:\/\/doi.org\/10.1007\/s10623-024-01472-0","DOI":"10.1007\/s10623-024-01472-0"},{"key":"12_CR57","doi-asserted-by":"publisher","unstructured":"Moody, D., Peralta, R., Perlner, R., Regenscheid, A., Roginsky, A., Chen, L.: Report on pairing-based cryptography. J. Res. National Inst. Standards Technol. 120, 11\u201327 (2015). https:\/\/doi.org\/10.6028\/jres.120.002","DOI":"10.6028\/jres.120.002"},{"key":"12_CR58","doi-asserted-by":"publisher","unstructured":"Naccache, D., M\u2019Ra\u00efhi, D., Vaudenay, S., Raphaeli, D.: Can D.S.A. be improved? Complexity trade-offs with the digital signature standard. In: De Santis, A. (ed.) Advances in Cryptology \u2013 EUROCRYPT 1994. Lecture Notes in Computer Science, vol.\u00a0950, pp. 77\u201385. Springer, Berlin, Heidelberg (1995). https:\/\/doi.org\/10.1007\/BFb0053426","DOI":"10.1007\/BFb0053426"},{"key":"12_CR59","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1007\/978-3-540-46588-1_3","volume-title":"Public Key Cryptography","author":"J Pastuszak","year":"2000","unstructured":"Pastuszak, J., Micha\u0142ek, D., Pieprzyk, J., Seberry, J.: Identification of bad signatures in batches. In: Imai, H., Zheng, Y. (eds.) PKC 2000. LNCS, vol. 1751, pp. 28\u201345. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/978-3-540-46588-1_3"},{"key":"12_CR60","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1007\/3-540-44495-5_13","volume-title":"Progress in Cryptology \u2014INDOCRYPT 2000","author":"J Pastuszak","year":"2000","unstructured":"Pastuszak, J., Pieprzyk, J., Seberry, J.: Codes identifying bad signatures in batches. In: Roy, B., Okamoto, E. (eds.) INDOCRYPT 2000. LNCS, vol. 1977, pp. 143\u2013154. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-44495-5_13"},{"key":"12_CR61","doi-asserted-by":"publisher","unstructured":"Pope, G., Reijnders, K., Robert, D., Sferlazza, A., Smith, B.: Simpler and faster pairings from the Montgomery ladder. IACR Commun. Crypt. 2(2), 29 (2025). https:\/\/doi.org\/10.62056\/ah2i893y6","DOI":"10.62056\/ah2i893y6"},{"key":"12_CR62","unstructured":"Pornin, T.: X25519 implementation for ARM Cortex-M0\/M0+ (2020). https:\/\/github.com\/pornin\/x25519-cm0"},{"key":"12_CR63","unstructured":"Pornin, T.: Point-halving and subgroup membership in twisted Edwards curves (2022). https:\/\/eprint.iacr.org\/2022\/1164"},{"key":"12_CR64","doi-asserted-by":"publisher","unstructured":"Pottier, X., de\u00a0Ruijter, T., Bertels, J., Legiest, W., Van Beirendonck, M., Verbauwhede, I.: OPTIMSM: FPGA hardware accelerator for zero-knowledge MSM. IACR Trans. Crypt. Hardware Embed. Syst. 2025(2), 489\u2013510 (2025). https:\/\/doi.org\/10.46586\/tches.v2025.i2.489-510","DOI":"10.46586\/tches.v2025.i2.489-510"},{"key":"12_CR65","unstructured":"Robert, D.: Fast pairings via biextensions and cubical arithmetic (2024). https:\/\/eprint.iacr.org\/2024\/517"},{"key":"12_CR66","unstructured":"Sanso, A.: Fast $$\\mathbb{G}_2$$ subgroup check in BN254 (2022). https:\/\/ethresear.ch\/t\/fast-mathbb-g-2-subgroup-check-in-bn254\/13974"},{"key":"12_CR67","unstructured":"Sanso, A.: The return of torus based cryptography: Whisk and Curdleproof in the target group (2023). https:\/\/ethresear.ch\/t\/the-return-of-torus-based-cryptography-whisk-and-curdleproof-in-the-target-group\/16678"},{"key":"12_CR68","doi-asserted-by":"publisher","unstructured":"Sanso, A., El Housni, Y.: Families of prime-order endomorphism-equipped embedded curves on pairing-friendly curves. J. Crypt. 37(4), 37 (2024), https:\/\/doi.org\/10.1007\/s00145-024-09514-5","DOI":"10.1007\/s00145-024-09514-5"},{"key":"12_CR69","unstructured":"Scott, M.: Unbalancing pairing-based key exchange protocols (2013). https:\/\/eprint.iacr.org\/2013\/688"},{"key":"12_CR70","unstructured":"Scott, M.: Pairing implementation revisited (2019). https:\/\/eprint.iacr.org\/2019\/077"},{"key":"12_CR71","unstructured":"Scott, M.: A note on group membership tests for $$\\mathbb{G}_1$$, $$\\mathbb{G}_2$$ and $$\\mathbb{G}_{T}$$ on BLS pairing-friendly curves (2021). https:\/\/eprint.iacr.org\/2021\/1130"},{"key":"12_CR72","unstructured":"Shlomovits, O.: Baby sharks: injecting small order points to threshold EdDSA (2020). https:\/\/medium.com\/zengo\/baby-sharks-a3b9ceb4efe0"},{"key":"12_CR73","unstructured":"Spagni, R.: Disclosure of a major bug in CryptoNote based currencies (2017). https:\/\/www.getmonero.org\/2017\/05\/17\/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html"},{"key":"12_CR74","doi-asserted-by":"publisher","unstructured":"Straus, E.G.: Addition chains of vectors (problem 5125). Am. Math. Monthly 71(7), 806\u2013808 (1964). https:\/\/doi.org\/10.2307\/2310929","DOI":"10.2307\/2310929"},{"key":"12_CR75","doi-asserted-by":"publisher","unstructured":"Teruya, T.: A note on subgroup security in discrete logarithm-based cryptography. IEICE Trans. Fundam. Electron. Commun. Comput. Sci. E104-A(1), 104\u2013120 (2021). https:\/\/doi.org\/10.1587\/transfun.2020CIP0019","DOI":"10.1587\/transfun.2020CIP0019"},{"key":"12_CR76","doi-asserted-by":"crossref","unstructured":"Valenta, L., et al.: Measuring small subgroup attacks against Diffie\u2013Hellman (2016). https:\/\/eprint.iacr.org\/2016\/995","DOI":"10.14722\/ndss.2017.23171"},{"key":"12_CR77","unstructured":"Vlasov, A.: EIP-2537 (BLS12 precompile) discussion thread (2020). https:\/\/ethereum-magicians.org\/t\/eip-2537-bls12-precompile-discussion-thread\/4187"},{"key":"12_CR78","unstructured":"Vlasov, A.: EIP-2539: BLS12-377 curve operations (2020). https:\/\/eips.ethereum.org\/EIPS\/eip-2539"},{"key":"12_CR79","unstructured":"Wang, J.: BN254 for the rest of us (2024). https:\/\/hackmd.io\/@jpw\/bn254"},{"key":"12_CR80","doi-asserted-by":"publisher","unstructured":"Zaverucha, G.M., Stinson, D.R.: Group testing and batch verification. In: Kurosawa, K. (ed.) Information Theoretic Security. ICITS 2009. Lecture Notes in Computer Science, vol.\u00a05973, pp. 140\u2013157. Springer, Berlin, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14496-7_12","DOI":"10.1007\/978-3-642-14496-7_12"},{"key":"12_CR81","doi-asserted-by":"publisher","unstructured":"Zhu, X., He, H., Yang, Z., Deng, Y., Zhao, L., Hou, R.: Elastic MSM: a fast, elastic and modular preprocessing technique for multi-scalar multiplication algorithm on GPUs. IACR Trans. Crypt. Hardware Embed. Syst. 2024(4), 258\u2013284 (2024). https:\/\/doi.org\/10.46586\/tches.v2024.i4.258-284","DOI":"10.46586\/tches.v2024.i4.258-284"}],"container-title":["Lecture Notes in Computer Science","Progress in Cryptology - AFRICACRYPT 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-31130-6_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T13:38:47Z","timestamp":1783517927000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-31130-6_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032311290","9783032311306"],"references-count":81,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-31130-6_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"9 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"AFRICACRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Cryptology in Africa","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hammamet","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tunisia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"africacrypt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/africacrypt2026.tn","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}