Zeeka saysA pairing maps two curve points into a third group while preserving multiplication in the exponents — the trick behind BLS signatures and KZG commitments.
A pairing is a bilinear map e(aP, bQ) = e(P, Q)^(ab). The point is that secrets sitting in the exponents can be multiplied and checked without ever being revealed — a verifier can confirm a relationship between hidden scalars. This is the engine under BLS signature aggregation, KZG polynomial commitments, and many SNARK verifiers.
Pairings only exist efficiently on special pairing-friendly curves like bn254 and bls12-381, and computing one is the expensive step in verification. Real pairings need extension fields and a Miller loop — too much for a sandbox — so the demo below models the bilinear identity on toy exponents. It is illustrative, not secure crypto, but it shows exactly the property pairings give you.
Power-ups you unlock
A bilinear map: e(aP, bQ) = e(P, Q)^(ab)
Linear in both arguments — exponents factor out
Needs pairing-friendly curves (bn254, bls12-381)
Lets a verifier check products of hidden secrets
Powers BLS aggregation, KZG openings, and many SNARKs
The Collision attacks — common mistakes
Thinking any curve supports an efficient pairing (most do not)
Confusing the two source groups with the target group
Assuming pairings are cheap — they are the costly verification step
Treating a toy exponent demo as a real, secure pairing
Boss battleUsing a toy exponent group, verify the bilinear identity e(g^(a+c), g^b) = e(g^a, g^b) · e(g^c, g^b).
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// ILLUSTRATIVE pairing (toy): real pairings need extension fields + a Miller loop.
// We model the bilinear IDENTITY on exponents to show the property correctly.
const P = 2003; // toy target-group prime
const gt = 5; // target generator
const pw = (a,e,m)=>{ let r=1; a%=m; while(e>0){ if(e&1) r=(r*a)%m; a=(a*a)%m; e>>=1; } return r; };
const pair = (a,b)=> pw(gt, a*b, P); // e(g^a, g^b) := gt^(a·b)
const a=6, b=7, c=4;
document.getElementById('o').textContent = [
'e(g^a, g^b) := gt^(a·b) [illustrative — not a real pairing]',
'e(g^6, g^7) = ' + pair(6,7),
'e(g,g)^(6·7) = ' + pw(pair(1,1), 6*7, P) + ' ← same value',
'bilinear: e(g^(6+4),g^7) == e(g^6,g^7)·e(g^4,g^7) ?',
' ' + ( pair(a+c,b) === (pair(a,b)*pair(c,b)) % P )
].join('\n');
</script></body></html>