Journal of Cryptology

, Volume 19, Issue 4, pp 553–562

Elliptic Curves with Low Embedding Degree


DOI: 10.1007/s00145-006-0544-0

Cite this article as:
Luca, F. & Shparlinski, I. J Cryptology (2006) 19: 553. doi:10.1007/s00145-006-0544-0


Miyaji, Nakabayashi and Takano have recently suggested a construction of the so-called MNT elliptic curves with low embedding degree, which are also of importance for pairing-based cryptography. We give some heuristic arguments which suggest that there are only about z1/2+ o(1) of MNT curves with complex multiplication discriminant up to z. We also show that there are very few finite fields over which elliptic curves with small embedding degree and small complex multiplication discriminant may exist (regardless of the way they are constructed).

Copyright information

© International Association for Cryptologic Research 2006

Authors and Affiliations

  1. 1.Instituto de Matematicas, Universidad Nacional Autonoma de Mexico, C.P. 58089, MoreliaMichoacanMexico
  2. 2.Department of Computing, Macquarie UniversitySydney, NSW 2109Australia

Personalised recommendations