How does a low hamming weight prime inflict the Miller algorithm?

132 Views Asked by At

If I look up [1] there is a third improvement for pairings given on page 10. How does a low hamming weight prime order does improve the Miller algorithm? Could someone summarize this in short or point me out a paper, where I could find the answere?

Oh..I guess I found the solution while googling for the Miller algorithm in [2]. But does anyone has some knowledge about, how the Miller algorithm is effected? How many cycles can be saved?

[1] https://www.esat.kuleuven.be/cosic/publications/talk-73.pdf

[2] http://www.craigcostello.com.au/pairings/PairingsForBeginners.pdf , Section 7.4