International Association for Cryptologic Research (IACR)
Abstract
Here we consider a method for quickly testing for group membership in the groups \G_1, \G_2 and \G_T (all of prime order r) as they arise on a type-3 pairing-friendly curve. As is well known endomorphisms exist for each of these groups which allows for faster point multiplication for elements of order r. The endomorphism applies if an element is of
order r. Here we show that, under relatively mild conditions, the endomorphism applies {\bf if and only if} an element is of order r. This results in a faster method of confirming group membership. In particular we show that the conditions are met for the popular BLS family of curves