A comparison of MNT curves and supersingular curvesDan Page, Nigel Smart, Fre Vercauteren, A comparison of MNT curves and supersingular curves. Applicable Algebra in Engineering, Communication and Computing, 17(5), pp. 379–392. October 2006. No electronic version available.
We compare both the security and performance issues related to the choice of MNT curves against supersingular curves in characteristic three, for pairing based systems. We pay particular attention to equating the relevant security levels and comparing not only computational performance and bandwidth performance. The paper focuses on the BLS signature scheme and the Boneh--Franklin encryption scheme, but a similar analysis can be applied to many other pairing based schemes.