In this note, we study decomposition of the Ate pairing on certain elliptic curves defined over finite fields. As an application, we reduce a generalized pairing inversion to root findings of an element of the affine coordinate ring appearing in the decomposition. For a supersingular curve satisfying , heuristic observation suggests that a number of calls to a root finding algorithm seems to where is the maximal power of dividing $q+1

Decomposition of the Ate Pairing and its Relation to Generalized Pairing Inversion
Takakazu Satoh

