No Fault polynomial time Miller s inversion implemented for altbn128, but can it be made usefull against eip197?

Based on recent research results.

Is there a way to lift both G_1 and G_2/G_12 to an hyperelliptic curve cover where the final exponentiation isn t required?

Or are there some cases where the right exponentiation inversion is easy as highlighted by some papers that where using faults for performing Miller inversion (which was usefull when a secret was to be hidden).

1 Like