{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T20:34:02Z","timestamp":1786826042057,"version":"3.56.0"},"reference-count":46,"publisher":"International Association for Cryptologic Research","issue":"2","license":[{"start":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T00:00:00Z","timestamp":1744070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,6,2]]},"abstract":"<jats:p>We show that Montgomery ladders compute pairings as a by-product,     and explain how a small adjustment to the ladder results     in simple and efficient algorithms for the Weil and Tate pairing on     elliptic curves using cubical arithmetic.     We demonstrate the efficiency of the resulting cubical pairings     in several applications from isogeny-based cryptography.     Cubical pairings are simpler and more performant     than pairings computed using Miller's algorithm:     we get a speed-up of over 40 per cent for use-cases in SQIsign,     and a speed-up of about 7 per cent for use-cases in CSIDH.     While these results arise from a deep connection to     biextensions and cubical arithmetic, in this article we keep things     as concrete (and digestible) as possible.     We provide a concise and complete introduction to cubical arithmetic as an appendix.<\/jats:p>","DOI":"10.62056\/ah2i893y6","type":"journal-article","created":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T17:09:09Z","timestamp":1751908149000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":6,"title":["Simpler and Faster Pairings from the Montgomery Ladder"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-0394-3650","authenticated-orcid":false,"given":"Giacomo","family":"Pope","sequence":"first","affiliation":[{"name":"NCC Group","place":["United Kingdom"]},{"id":[{"id":"https:\/\/ror.org\/0524sp257","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Bristol","place":["United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8015-399X","authenticated-orcid":false,"given":"Krijn","family":"Reijnders","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4378-4274","authenticated-orcid":false,"given":"Damien","family":"Robert","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03tjcj052","id-type":"ROR","asserted-by":"publisher"}],"name":"Inria Bordeaux, Institut de Math\u00e9matiques de Bordeaux","place":["France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7968-0570","authenticated-orcid":false,"given":"Alessandro","family":"Sferlazza","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02kkvpp62","id-type":"ROR","asserted-by":"publisher"}],"name":"Technical University of Munich","place":["Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6701-1420","authenticated-orcid":false,"given":"Benjamin","family":"Smith","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02kvxyf05","id-type":"ROR","asserted-by":"publisher"}],"name":"Inria","place":["France"]},{"id":[{"id":"https:\/\/ror.org\/04afed728","id-type":"ROR","asserted-by":"publisher"}],"name":"LIX, CNRS, \u00c9cole polytechnique, Institut Polytechnique de Paris","place":["France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"ref1:AC:CLMPR18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","article-title":"CSIDH: An Efficient Post-Quantum Commutative Group\n  Action","volume":"11274","author":"Wouter Castryck","year":"2018"},{"key":"ref2:EC:MMPPW23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"448","DOI":"10.1007\/978-3-031-30589-4_16","article-title":"A Direct Key Recovery Attack on SIDH","volume":"14008","author":"Luciano Maino","year":"2023"},{"key":"ref3:CaiLinZha24","doi-asserted-by":"publisher","first-page":"9631360","DOI":"10.1049\/2024\/9631360","article-title":"Pairing Optimizations for Isogeny-Based Cryptosystems","volume":"2024","author":"Shiping Cai","year":"2024","journal-title":"IET Information Security"},{"key":"ref4:EC:Robert23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1007\/978-3-031-30589-4_17","article-title":"Breaking SIDH in Polynomial Time","volume":"14008","author":"Damien Robert","year":"2023"},{"key":"ref5:AC:NaeRen19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1007\/978-3-030-34621-8_9","article-title":"Dual Isogenies and Their Application to Public-Key\n  Compression for Isogeny-Based Cryptography","volume":"11922","author":"Michael Naehrig","year":"2019"},{"key":"ref6:C:CHMMBV23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1007\/978-3-031-38548-3_25","article-title":"Weak Instances of Class Group Action Based Cryptography via\n  Self-pairings","volume":"14083","author":"Wouter Castryck","year":"2023"},{"key":"ref7:cryptoeprint:2020\/972","volume-title":"Optimized Binary GCD for Modular Inversion","author":"Thomas Pornin","year":"2020"},{"key":"ref8:doliskani","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1007\/s00200-018-0349-z","article-title":"On division polynomial PIT and supersingularity","volume":"29","author":"Javad Doliskani","year":"2018","journal-title":"Applicable Algebra in Engineering, Communication and\n  Computing"},{"key":"ref9:2023\/Aranha--El-Housni--Guillevic","doi-asserted-by":"publisher","first-page":"3333","DOI":"10.1007\/S10623-022-01135-Y","article-title":"A survey of elliptic curves for proof systems","volume":"91","author":"Diego F. Aranha","year":"2023","journal-title":"Des. Codes Cryptogr."},{"key":"ref10:C:BonFra01","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/3-540-44647-8_13","article-title":"Identity-Based Encryption from the Weil Pairing","volume":"2139","author":"Dan Boneh","year":"2001"},{"key":"ref11:theta-pairings-dim2","volume-title":"Hyperelliptic biextension pairings","author":"Alessandro Sferlazza","year":"2024"},{"key":"ref12:2006\/Hess--Smart--Vercauteren","doi-asserted-by":"publisher","first-page":"4595","DOI":"10.1109\/TIT.2006.881709","article-title":"The Eta Pairing Revisited","volume":"52","author":"Florian Hess","year":"2006","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref13:miller","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/s00145-004-0315-8","article-title":"The Weil pairing, and its efficient calculation","volume":"17","author":"Victor S Miller","year":"2004","journal-title":"Journal of cryptology"},{"key":"ref14:stangephd","volume-title":"Elliptic nets and elliptic curves","author":"Katherine Stange","year":"2008"},{"key":"ref15:SQIsignNIST2","volume-title":"SQIsign","author":"Marius A. Aardal","year":"2025"},{"key":"ref16:JC:BonLynSha04","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1007\/s00145-004-0314-9","article-title":"Short Signatures from the Weil Pairing","volume":"17","author":"Dan Boneh","year":"2004","journal-title":"Journal of Cryptology"},{"key":"ref17:2002\/Izu--Takagi","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/3-540-45664-3_20","article-title":"A Fast Parallel Elliptic Curve Multiplication Resistant\n  against Side Channel Attacks","volume":"2274","author":"Tetsuya Izu","year":"2002"},{"key":"ref18:lichtenbaum","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/BF01389795","article-title":"Duality theorems for curves over $p$-adic fields","volume":"7","author":"Stephen Lichtenbaum","year":"1969","journal-title":"Inventiones mathematicae"},{"key":"ref19:cryptoeprint:2025\/670","volume-title":"Biextensions in pairing-based cryptography","author":"Jianming Lin","year":"2025"},{"key":"ref20:weil","first-page":"592","article-title":"Sur les fonctions alg\u00e9briques \u00e0 corps de constantes\n  fini","volume":"210","author":"Andr\u00e9 Weil","year":"1940","journal-title":"CR Acad. Sci. Paris"},{"key":"ref21:rotk","volume-title":"Return of the Kummer: a Toolbox for Genus-2 Cryptography","author":"Maria Corte-Real Santos","year":"2024"},{"key":"ref22:BGS22","first-page":"21","article-title":"Efficient supersingularity testing over $\\mathbb{F}_p$ and\n  CSIDH key validation","volume":"2","author":"Gustavo Banegas","year":"2022","journal-title":"Mathematical Cryptology"},{"key":"ref23:Montgomery87","doi-asserted-by":"publisher","first-page":"243","DOI":"10.2307\/2007888","article-title":"Speeding the Pollard and elliptic curve methods of\n  factorization","volume":"48","author":"Peter L Montgomery","year":"1987","journal-title":"Mathematics of computation"},{"key":"ref24:freyruck","doi-asserted-by":"publisher","first-page":"865","DOI":"10.2307\/2153546","article-title":"A remark concerning $m$-divisibility and the discrete\n  logarithm in the divisor class group of curves","volume":"62","author":"Gerhard Frey","year":"1994","journal-title":"Mathematics of computation"},{"key":"ref25:maculastange","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/978-981-96-0891-1_12","volume-title":"International Conference on the Theory and Application of\n  Cryptology and Information Security","author":"Joseph Macula","year":"2024"},{"key":"ref26:EC:CJLNRU17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"679","DOI":"10.1007\/978-3-319-56620-7_24","article-title":"Efficient Compression of SIDH Public Keys","volume":"10210","author":"Craig Costello","year":"2017"},{"key":"ref27:dCTIDH","doi-asserted-by":"publisher","first-page":"516","DOI":"10.46586\/tches.v2025.i3.516-541","article-title":"dCTIDH: Fast and Deterministic CTIDH","volume":"2025","author":"Fabio Campos","year":"2025","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref28:JCEng:CosSmi18","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/s13389-017-0157-6","article-title":"Montgomery curves and their arithmetic - The case of large\n  characteristic fields","volume":"8","author":"Craig Costello","year":"2018","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref29:CiC:CCCMRR24","doi-asserted-by":"publisher","first-page":"5","DOI":"10.62056\/anjbksdja","article-title":"Optimizations and Practicality of High-Security CSIDH","volume":"1","author":"Fabio Campos","year":"2024","journal-title":"CiC"},{"key":"ref30:STOC:MenVanOka91","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1145\/103418.103434","article-title":"Reducing Elliptic Curve Logarithms to Logarithms in a Finite\n  Field","author":"Alfred Menezes","year":"1991"},{"key":"ref31:AC:BDDLMP24","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"339","DOI":"10.1007\/978-981-96-0891-1_11","article-title":"SQIsign2D-West - The Fast, the Small, and the Safer","volume":"15486","author":"Andrea Basso","year":"2024"},{"key":"ref32:grothendieck1972groupes","volume-title":"Groupes de Monodromie en G\u00e9om\u00e9trie Alg\u00e9brique:\n  SGA 7","author":"Alexandre Grothendieck","year":"1972"},{"key":"ref33:LC:Reijnders23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1007\/978-3-031-44469-2_6","article-title":"Effective Pairings in Isogeny-Based Cryptography","volume":"14168","author":"Krijn Reijnders","year":"2023"},{"key":"ref34:2000\/Joux","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1007\/10722028_23","article-title":"A One Round Protocol for Tripartite Diffie-Hellman","volume":"1838","author":"Antoine Joux","year":"2000"},{"key":"ref35:AC:DKLPW20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","article-title":"SQISign: Compact Post-quantum Signatures from Quaternions\n  and Isogenies","volume":"12491","author":"Luca De Feo","year":"2020"},{"key":"ref36:moret1985pinceaux","volume-title":"Pinceaux de vari\u00e9t\u00e9s ab\u00e9liennes","author":"L. Moret-Bailly","year":"1985"},{"key":"ref37:EC:CasDec23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-031-30589-4_15","article-title":"An Efficient Key Recovery Attack on SIDH","volume":"14008","author":"Wouter Castryck","year":"2023"},{"key":"ref38:tate","first-page":"288","article-title":"Duality theorems in Galois cohomology over number fields","author":"John Tate","year":"1962"},{"key":"ref39:NISTPQC-R4:SIKE22","volume-title":"SIKE","author":"David Jao","year":"2022"},{"key":"ref40:thesisstam","doi-asserted-by":"publisher","DOI":"10.6100\/IR564670","volume-title":"Speeding up subgroup cryptosystems","author":"Martijn Stam","year":"2003"},{"key":"ref41:breen1983fonctions","series-title":"Lecture Notes in Mathematics","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0065683","volume-title":"Fonctions th\u00eata et th\u00e9oreme du cube","volume":"980","author":"Lawrence Breen","year":"1983"},{"key":"ref42:DRcubical","volume-title":"Fast pairings via biextensions and cubical arithmetic","author":"Damien Robert","year":"2024"},{"key":"ref43:stange2007tate","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-540-73489-5_19","article-title":"The Tate pairing via elliptic nets","author":"Katherine E Stange","year":"2007"},{"key":"ref44:originalsidh","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1515\/jmc-2012-0015","article-title":"Towards quantum-resistant cryptosystems from supersingular\n  elliptic curve isogenies","volume":"8","author":"Luca De Feo","year":"2014","journal-title":"Journal of Mathematical Cryptology"},{"key":"ref45:DRarithmetic","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1016\/j.ffa.2016.01.009","article-title":"Arithmetic on Abelian and Kummer Varieties","volume":"39","author":"David Lubicz","year":"2016","journal-title":"Finite Fields and Their Applications"},{"key":"ref46:2002\/Brier--Joye","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1007\/3-540-45664-3_24","article-title":"Weierstra\u00df Elliptic Curves and Side-Channel Attacks","volume":"2274","author":"Eric Brier","year":"2002"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T17:10:14Z","timestamp":1751908214000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/2\/29"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,7]]},"references-count":46,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,7,7]]}},"URL":"https:\/\/doi.org\/10.62056\/ah2i893y6","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,7]]},"assertion":[{"value":"2025-04-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-06-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-2-75"}}