{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T15:34:00Z","timestamp":1772724840332,"version":"3.50.1"},"reference-count":20,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des. Codes Cryptogr."],"published-print":{"date-parts":[[2024,12]]},"DOI":"10.1007\/s10623-024-01472-0","type":"journal-article","created":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T08:01:56Z","timestamp":1725177716000},"page":"4131-4143","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Bandersnatch: a fast elliptic curve built over the BLS12-381 scalar field"],"prefix":"10.1007","volume":"92","author":[{"given":"Simon","family":"Masson","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8878-5761","authenticated-orcid":false,"given":"Antonio","family":"Sanso","sequence":"additional","affiliation":[]},{"given":"Zhenfei","family":"Zhang","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2024,9,1]]},"reference":[{"key":"1472_CR1","unstructured":"Bowe, S.: BLS12-381: New zk-SNARK elliptic curve construction. https:\/\/electriccoin.co\/blog\/new-snark-curve\/ (2017)."},{"key":"1472_CR2","unstructured":"ZCash Team. Jubjub. https:\/\/z.cash\/technology\/jubjub\/ (2018)."},{"key":"1472_CR3","first-page":"190","volume-title":"Faster Point Multiplication on Elliptic Curves with Efficient Endomorphisms","author":"RP Gallant","year":"2001","unstructured":"Gallant R.P., Lambert R.J., Vanstone S.A.: Faster Point Multiplication on Elliptic Curves with Efficient Endomorphisms, pp. 190\u2013200. Springer, Berlin (2001)."},{"key":"1472_CR4","unstructured":"Gallant, R., Lambert, R., Vanstone, S.A.: Method for accelerating cryptographic operations on elliptic curves. https:\/\/patents.google.com\/patent\/US7110538B2\/en (2020)."},{"key":"1472_CR5","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1090\/S0025-5718-1993-1199989-X","volume":"61","author":"AOL Atkin","year":"1993","unstructured":"Atkin A.O.L., Morain F.: Elliptic curves and primality proving. Math. Comp. 61, 29\u201368 (1993).","journal-title":"Math. Comp."},{"key":"1472_CR6","unstructured":"Arkworks Contributors: Arkworks: An ecosystem for developing and programming with zkSNARKs. http:\/\/arkworks.rs"},{"key":"1472_CR7","unstructured":"Bandersnatch Team: Bandersnatch: a fast elliptic curve built over the BLS12-381 scalar field. https:\/\/github.com\/zhenfeizhang\/bandersnatch"},{"key":"1472_CR8","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4757-1920-8","volume-title":"The Arithmetic of Elliptic Curves","author":"JH Silverman","year":"1986","unstructured":"Silverman J.H.: The Arithmetic of Elliptic Curves, vol. 106. Springer, Cham (1986)."},{"key":"1472_CR9","first-page":"238","volume":"273","author":"Jacques V\u00e9lu","year":"1971","unstructured":"V\u00e9lu Jacques: Isog\u00e9nies entre courbes elliptiques. C. R. Acad. Sci. 273, 238\u2013241 (1971).","journal-title":"C. R. Acad. Sci."},{"key":"1472_CR10","doi-asserted-by":"publisher","first-page":"250","DOI":"10.1007\/3-540-58691-1_64","volume-title":"Algorithmic Number Theory","author":"GJ Lay","year":"1994","unstructured":"Lay G.J., Zimmer H.G.: Constructing elliptic curves with given group order over large finite fields. In: Adleman L.M., Huang M.D. (eds.) Algorithmic Number Theory, pp. 250\u2013263. Springer, Berlin, Heidelberg (1994)."},{"key":"1472_CR11","doi-asserted-by":"publisher","first-page":"328","DOI":"10.1007\/3-540-46416-6_28","volume-title":"Advances in Cryptology-EUROCRYPT \u201991","author":"F Morain","year":"1991","unstructured":"Morain F.: Building cyclic elliptic curves modulo large primes. In: Davies D.W. (ed.) Advances in Cryptology-EUROCRYPT \u201991, pp. 328\u2013336. Springer, Berlin, Heidelberg (1991)."},{"key":"1472_CR12","first-page":"403","volume-title":"Complete Addition Formulas for Prime Order Elliptic Curves","author":"J Renes","year":"2016","unstructured":"Renes J., Costello C., Batina L.: Complete Addition Formulas for Prime Order Elliptic Curves, pp. 403\u2013428. Springer, Berlin (2016)."},{"key":"1472_CR13","first-page":"326","volume-title":"Twisted Edwards Curves Revisited","author":"H Hisil","year":"2008","unstructured":"Hisil H., Koon-Ho W.K., Carter G., Dawson E.: Twisted Edwards Curves Revisited, pp. 326\u2013343. Springer, Berlin (2008)."},{"issue":"3","key":"1472_CR14","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/s13389-017-0157-6","volume":"8","author":"C Costello","year":"2018","unstructured":"Costello C., Smith B.: Montgomery curves and their arithmetic: the case of large characteristic fields. J. Cryptogr. Eng. 8(3), 227\u2013240 (2018).","journal-title":"J. Cryptogr. Eng."},{"issue":"2","key":"1472_CR15","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1137\/0209022","volume":"9","author":"Nicholas Pippenger","year":"1980","unstructured":"Pippenger Nicholas: On the evaluation of powers and monomials. SIAM J. Comput. 9(2), 230\u2013250 (1980).","journal-title":"SIAM J. Comput."},{"key":"1472_CR16","unstructured":"Bootle, J.: Efficient multi-exponentiation. https:\/\/jbootle.github.io\/Misc\/pippenger.pdf"},{"key":"1472_CR17","first-page":"305","volume-title":"On the Size of Pairing-Based Non-interactive Arguments","author":"J Groth","year":"2016","unstructured":"Groth J.: On the Size of Pairing-Based Non-interactive Arguments, pp. 305\u2013326. Springer, Berlin (2016)."},{"key":"1472_CR18","unstructured":"Gabizon, A., Williamson, Z.J., Ciobotaru, O.: PLONK: Permutations over lagrange-bases for oecumenical noninteractive arguments of knowledge. Cryptology ePrint Archive, Report 2019\/953. https:\/\/eprint.iacr.org\/2019\/953 (2019)."},{"key":"1472_CR19","unstructured":"Gabizon, A., Williamson, Z.J.: Plookup: A simplified polynomial protocol for lookup tables. Cryptology ePrint Archive, Report 2020\/315. https:\/\/eprint.iacr.org\/2020\/315 (2020)."},{"key":"1472_CR20","unstructured":"Xiong, A.L., Chen, B., Zhang, Z., B\u00fcnz, B., Fisch, B., Krell, F., Camacho, P.: Veri-zexe: Decentralized private computation with universal setup. Cryptology ePrint Archive, Paper 2022\/802. https:\/\/eprint.iacr.org\/2022\/802 (2022)."}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01472-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10623-024-01472-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01472-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T21:24:22Z","timestamp":1732310662000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10623-024-01472-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,1]]},"references-count":20,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2024,12]]}},"alternative-id":["1472"],"URL":"https:\/\/doi.org\/10.1007\/s10623-024-01472-0","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"value":"0925-1022","type":"print"},{"value":"1573-7586","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9,1]]},"assertion":[{"value":"30 May 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 June 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 July 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}