3 ms·
Note that #7 is not actually true anymore, and actually hasn't been for quite a while. A paper from Mehdi Tibouchi [1] shows how to represent points on essenti
by kwantam 7y ago
Note that #7 is not actually true anymore, and actually hasn't been for quite a while.
A paper from Mehdi Tibouchi [1] shows how to represent points on essentially any curve as uniform random bitstrings.
Another paper by Aranha, Fouque, Qian, Tibouchi, and Zapalowicz [2] gives an even more efficient construction for curves over binary fields.
(As an aside, there are really good reasons not to use curves over binary fields. Discrete log has recently been getting easier much faster over GF(2^k) than over GF(p).)
[1] https://ia.cr/2014/043 https://ia.cr/2014/043
[2] https://ia.cr/2014/486 https://ia.cr/2014/486
- segfaultbuserr 7y agoThanks for the update!
- mti 7y agoThe hardness of discrete logs over fields doesn't have much to do with the hardness of elliptic curve discrete logs. At this stage, I don't think we have any evidence that curves over binary fields are less secure than over prime fields, especially for cryptographically relevant curve sizes. (The situation is different for pairing-friendly elliptic curves, of course, but that's a different kettle of fish).