Balasubramanian-Koblitz Theorem
We show that the Weil and Tate pairing are interchangeable for elliptic curves for embedding degrees greater than 1.
Theorem: Let be an elliptic curve defined over and suppose is a prime dividing , and that does not divide . Then contains points of order if and only if divides .
Proof: It is well-known that if contains then , even without assuming divides or does not divide .
Let denote the Frobenius map. Consider the subgroup of consisting of all points of trace zero, that is
The group may be explicitly constructed using the map . Now we have , and also is not contained in since we are assuming .
Hence is an eigenspace of , but not the -eigenspace. Since the eigenvalues of are and , we see that must be the -eigenspace of and hence
since . Thus , like is fixed under , and since these groups are linearly independent they generate all of , implying that all of is fixed under . Hence
Example
Here is a curve where the Tate pairing can be used but the Weil pairing cannot. Let . Let over be given by . We may use the Tate pairing since contains the cube roots of unity. However, the group of points of is a cyclic group of order 18, so the Weil pairing cannot be used. It turns out that we must go to to get all of .