I'm trying to get into pairing-based cryptography and I don't see why the group order of the group G in the pairing function
e:G*G-> G_t
has to be a prime number.
I don't find an argument why groups of order p^k for a prime number p and some entire number k cannot be used?