Solving the Diffie Hellman problem on pairing friendly elliptic curves used commercially in in polynomial time. But does it includes bn and Bls curves?

The aim is through pairing inversion. In the case of Groth16, it still require a first proof

(as it would require to alter it)

Информационные технологии159-168.pdf (238.7 KB)

Meanwhile I now have a universal Miller inversion algorithm that work for any curve (provided the input finite field element is in the right coset and the embeding degree is 12). Some peoples suggested me I might be able to use it for Weil pairing inversion, but I completely fail to see how.