摘要: It is already known that the Weil and Tate pairings can be used to solve many decision-Diffie-Hellman (DDH) problems on elliptic curves. A natural question whether all DDH are easy supersingular To answer this it necessary have suitable distortion maps. Verheul states such maps exist, paper gives methods construct them. The therefore shows curves easy. We also discuss issue of which ordinary related contribution a discussion not isomorphisms. give explicit for with complex multiplication discriminants D = −7 −8.