{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,8]],"date-time":"2026-08-08T22:05:15Z","timestamp":1786226715826,"version":"build-2736575974"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,9,2]],"date-time":"2022-09-02T00:00:00Z","timestamp":1662076800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,9,2]],"date-time":"2022-09-02T00:00:00Z","timestamp":1662076800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2023,4]]},"DOI":"10.1007\/s13389-022-00296-9","type":"journal-article","created":{"date-parts":[[2022,9,5]],"date-time":"2022-09-05T11:31:04Z","timestamp":1662377464000},"page":"125-128","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Subgroup membership testing on elliptic curves via the Tate pairing"],"prefix":"10.1007","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4796-8989","authenticated-orcid":false,"given":"Dmitrii","family":"Koshelev","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,2]]},"reference":[{"key":"296_CR1","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Birkner, P., Joye, M., Lange, T., Peters, C.: Twisted Edwards curves. Progress in Cryptology - AFRICACRYPT 2008, LNCS 5023, Springer, Berlin, Heidelberg, pp. 389\u2013405 (2008)","DOI":"10.1007\/978-3-540-68164-9_26"},{"key":"296_CR2","doi-asserted-by":"crossref","unstructured":"Chen, L., Moody, D., Regenscheid, A., Randall, K.: Recommendations for discrete logarithm-based cryptography: Elliptic curve domain parameters (Draft NIST special publication 800-186) https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-186\/draft (2019)","DOI":"10.6028\/NIST.SP.800-186-draft"},{"key":"296_CR3","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Curve25519: New Diffie-Hellman speed records Yung M., Dodis Y., Kiayias A., Malkin T. Public Key Cryptography - PKC 2006, LNCS 3958, Springer, Berlin, Heidelberg, pp. 207\u2013228 (2006)","DOI":"10.1007\/11745853_14"},{"key":"296_CR4","unstructured":"Hamburg, M.: Ed448-Goldilocks, a new elliptic curve https:\/\/eprint.iacr.org\/2015\/625 (2015)"},{"key":"296_CR5","doi-asserted-by":"crossref","unstructured":"Galbraith, S.D.: Mathematics of public key cryptography New York Cambridge University Press (2012)","DOI":"10.1017\/CBO9781139012843"},{"key":"296_CR6","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Chuengsatiansup, C., Kohel, D., Lange, T.: Twisted Hessian curves Progress in Cryptology \u2013 LATINCRYPT 2015 Lauter K., Rodr\u00edguez-Henr\u00edquez F. LNCS 9230 Springer, Cham pp. 269\u2013294 (2015)","DOI":"10.1007\/978-3-319-22174-8_15"},{"key":"296_CR7","doi-asserted-by":"crossref","unstructured":"Renes, J., Costello, C., Batina, L., Complete addition formulas for prime order elliptic curves. In: Fischlin M., Coron J.-S. (Eds.) Advances in Cryptology - EUROCRYPT 2016, LNCS 9665, Springer, Berlin, Heidelberg, pp. 403\u2013428 (2016)","DOI":"10.1007\/978-3-662-49890-3_16"},{"key":"296_CR8","doi-asserted-by":"crossref","unstructured":"Schwabe, P., Sprenkels, D.: The complete cost of cofactor $$h=1$$ Hao F., Ruj S., Sen Gupta S. Progress in Cryptology \u2013 INDOCRYPT 2019. Springer, Cham, LNCS 11898, pp. 375\u2013397 (2019)","DOI":"10.1007\/978-3-030-35423-7_19"},{"key":"296_CR9","doi-asserted-by":"crossref","unstructured":"Biehl, I., Meyer, B., M\u00fcller, V.: Differential fault attacks on elliptic curve cryptosystems Bellare M. Advances in Cryptology - CRYPTO 2000, LNCS 1880, Springer, Berlin, Heidelberg, pp. 131\u2013146 (2000)","DOI":"10.1007\/3-540-44598-6_8"},{"key":"296_CR10","doi-asserted-by":"crossref","unstructured":"Antipa, A., Brown, D., Menezes, A., Struik, R., Vanstone, S.: Validation of elliptic curve public keys Desmedt Y. G. Public Key Cryptography - PKC 2003, LNCS 2567, Springer, Berlin, Heidelberg, pp. 211\u2013223 (2003)","DOI":"10.1007\/3-540-36288-6_16"},{"key":"296_CR11","doi-asserted-by":"crossref","unstructured":"Lim, C.H., Lee, P.J.: A key recovery attack on discrete log-based schemes using a prime order subgroup Kaliski B. S. Advances in Cryptology - CRYPTO 1997, LNCS 1294, Springer, Berlin, Heidelberg, pp. 249\u2013263 (1997)","DOI":"10.1007\/BFb0052240"},{"key":"296_CR12","unstructured":"luigi1111, Spagni, R.: \u201cfluffypony\u201d https:\/\/www.getmonero.org\/2017\/05\/17\/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html (2017)"},{"key":"296_CR13","doi-asserted-by":"crossref","unstructured":"Miret, J., Moreno, R., Rio, A., Valls, M.: Determining the $$2$$-Sylow subgroup of an elliptic curve over a finite field. Math. Comput., 74(249) 411\u2013427 (2005)","DOI":"10.1090\/S0025-5718-04-01640-0"},{"key":"296_CR14","doi-asserted-by":"crossref","unstructured":"Miret, J., Moreno, R., Rio, A., Valls, M.: Computing the $$\\ell $$-power torsion of an elliptic curve over a finite field. Math. Comput. 78(267) 1767\u20131786 (2009)","DOI":"10.1090\/S0025-5718-08-02201-1"},{"key":"296_CR15","doi-asserted-by":"crossref","unstructured":"Hamburg, M., Decaf: Eliminating cofactors through point compression Gennaro R., Robshaw M. Advances in Cryptology - CRYPTO 2015, LNCS 9215 Springer. Berlin, Heidelberg, pp. 705\u2013723 (2015)","DOI":"10.1007\/978-3-662-47989-6_34"},{"key":"296_CR16","unstructured":"Hamburg, M., de Valence, H., Lovecruft, I., Arcieri, T.: Ristretto. https:\/\/ristretto.group\/ristretto.html"},{"key":"296_CR17","unstructured":"de Valence, H., Grigg, J., Tankersley, G., Valsorda, F., Lovecruft, I., Hamburg, M.: The ristretto255 and decaf448 groups (2021). https:\/\/datatracker.ietf.org\/doc\/draft-irtf-cfrg-ristretto255-decaf448"},{"key":"296_CR18","unstructured":"Pornin, T.: X25519 implementation for ARM Cortex-M0\/M0+ (2020). https:\/\/github.com\/pornin\/x25519-cm0"},{"key":"296_CR19","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Yang, B.-Y.: Fast constant-time gcd computation and modular inversion. IACR Trans. Cryptograph. Hardware and Embedded Syst. 2019(3), 340\u2013398 (2019)","DOI":"10.46586\/tches.v2019.i3.340-398"},{"key":"296_CR20","doi-asserted-by":"crossref","unstructured":"Barreto, P.S.L.M., Costello, C., Misoczki, R., Naehrig, M., Pereira, G.C.C.F., Zanon, G.: Subgroup security in pairing-based cryptography Lauter K., Rodr\u00edguez-Henr\u00edquez F. Progress in Cryptology \u2013 LATINCRYPT 2015, LNCS 9230. Springer Cham, pp. 245\u2013265 (2015)","DOI":"10.1007\/978-3-319-22174-8_14"},{"key":"296_CR21","unstructured":"Bowe, S.: Faster subgroup checks for BLS12-381 (2019). https:\/\/eprint.iacr.org\/2019\/814"},{"key":"296_CR22","unstructured":"Scott M.: A note on group membership tests for $$\\mathbb{G}_1$$, $$\\mathbb{G}_2$$, and $$\\mathbb{G}_T$$ on BLS pairing-friendly curves https:\/\/eprint.iacr.org\/2021\/1130 (2021)"},{"issue":"1","key":"296_CR23","first-page":"211","volume":"61","author":"A Enge","year":"2016","unstructured":"Enge, A.: Bilinear pairings on elliptic curves Enseignement. Math\u00e9matique 61(1), 211\u2013243 (2016)","journal-title":"Math\u00e9matique"},{"issue":"1","key":"296_CR24","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1515\/jmc-2020-0077","volume":"15","author":"M Joye","year":"2021","unstructured":"Joye, M., Lapiha, O., Nguyen, K., Naccache, D.: The eleventh power residue symbol. J. Math. Cryptol. 15(1), 111\u2013122 (2021)","journal-title":"J. Math. Cryptol."},{"key":"296_CR25","unstructured":"Hamburg, M.: Computing the Jacobi symbol using Bernstein\u2013Yang (2021). https:\/\/eprint.iacr.org\/2021\/1271"},{"issue":"1","key":"296_CR26","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1016\/S0022-314X(02)92783-6","volume":"96","author":"A Weilert","year":"2002","unstructured":"Weilert, A.: Fast computation of the biquadratic residue symbol. J. Number Theory 96(1), 133\u2013151 (2002)","journal-title":"J. Number Theory"},{"issue":"6","key":"296_CR27","doi-asserted-by":"publisher","first-page":"643","DOI":"10.1016\/j.jsc.2004.02.006","volume":"39","author":"IB Damg\u00e5rd","year":"2005","unstructured":"Damg\u00e5rd, I.B., Frandsen, G.S.: Efficient algorithms for the gcd and cubic residuosity in the ring of Eisenstein integers. J. Symbolic Comput. 39(6), 643\u2013652 (2005)","journal-title":"J. Symbolic Comput."},{"key":"296_CR28","unstructured":"Bach, E., Sandlund, B.: On Euclidean methods for cubic and quartic Jacobi symbols (2018). https:\/\/arxiv.org\/abs\/1807.07719"},{"key":"296_CR29","unstructured":"Wikstr\u00f6m, D.: On the $$l$$-ary gcd-algorithm and computing residue symbols (2004). https:\/\/www.csc.kth.se\/~dog\/research\/papers\/Wik04TR.pdf"},{"key":"296_CR30","doi-asserted-by":"crossref","unstructured":"Koshelev, D.: Magma code (2022). https:\/\/github.com\/dishport\/Subgroup-membership-testing-on-elliptic-curves-via-the-Tate-pairing","DOI":"10.1007\/s13389-023-00331-3"},{"key":"296_CR31","unstructured":"Husem\u00f6ller, D.: Elliptic curves Graduate Texts in Mathematics 111, Springer. New York (2004)"},{"key":"296_CR32","unstructured":"Pornin, T.: Double-odd elliptic curves (2020). https:\/\/eprint.iacr.org\/2020\/1558"},{"key":"296_CR33","unstructured":"Pornin, T., Bottinelli, P., Doussot, G., Schorn, E.: Double-odd elliptic curves. https:\/\/doubleodd.group"},{"key":"296_CR34","doi-asserted-by":"crossref","unstructured":"Costello, C., Jao, D., Longa, P., Naehrig, M., Renes, J., Urbanik, D.: Efficient compression of SIDH public keys Coron J.-S., Nielsen J. Advances in Cryptology \u2013 EUROCRYPT 2017, LNCS 10210. Springer, Cham, pp. 679\u2013706 (2017)","DOI":"10.1007\/978-3-319-56620-7_24"},{"key":"296_CR35","unstructured":"Electric Coin Company What is Jubjub? https:\/\/z.cash\/technology\/jubjub"},{"key":"296_CR36","unstructured":"Masson, S., Sanso, A., Zhang, Z.: Bandersnatch: a fast elliptic curve built over the BLS12-381 scalar field (2021). https:\/\/eprint.iacr.org\/2021\/1152"},{"key":"296_CR37","unstructured":"Bandersnatch implementation notes (2021). https:\/\/hackmd.io\/wliPP_RMT4emsucVuCqfHA?view"},{"key":"296_CR38","unstructured":"Hopwood, D.: Calculate circuit costs of prime group operations (Ristretto or ctEdwards-subgroup) (2019). https:\/\/github.com\/zcash\/zcash\/issues\/4024"}],"updated-by":[{"DOI":"10.1007\/s13389-023-00331-3","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2023,8,17]],"date-time":"2023-08-17T00:00:00Z","timestamp":1692230400000}}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-022-00296-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-022-00296-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-022-00296-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,23]],"date-time":"2023-08-23T08:19:57Z","timestamp":1692778797000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-022-00296-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,2]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,4]]}},"alternative-id":["296"],"URL":"https:\/\/doi.org\/10.1007\/s13389-022-00296-9","relation":{"correction":[{"id-type":"doi","id":"10.1007\/s13389-023-00331-3","asserted-by":"object"}]},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,2]]},"assertion":[{"value":"11 January 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 July 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 September 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 August 2023","order":4,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Correction","order":5,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"A Correction to this paper has been published:","order":6,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"https:\/\/doi.org\/10.1007\/s13389-023-00331-3","URL":"https:\/\/doi.org\/10.1007\/s13389-023-00331-3","order":7,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}}]}}