4 ms·
The end of DLP (over any field) is the end of ECC.
by MrXOR 6y ago
The end of DLP (over any field) is the end of ECC.
- BlackFingolfin 6y agoWhy? Is there a reduction from EC DLP to FF DLP?
- MrXOR 6y agoThere are some attacks like MOV attack [1] and Frey-Rück attack [2]. [1] http://www.dima.unige.it/~morafe/MaterialeCTC/p80-menezes.pdf http://www.dima.unige.it/~morafe/MaterialeCTC/p80-menezes.pd... [2] https://pdfs.semanticscholar.org/8823/54510ddc955c8d7e13c529ad53002f2b0966.pdf https://pdfs.semanticscholar.org/8823/54510ddc955c8d7e13c529... [3] https://eprint.iacr.org/2015/1022.pdf https://eprint.iacr.org/2015/1022.pdf PS. I am a beginner in cryptography.
- thu2111 6y agoNo it isn't. The curves used in all real systems are based on prime fields. The results against binary fields don't seem to generalise to curves deployed in the wild.
- MrXOR 6y agoBinary fields are weaker than prime fields, but "I think" there are always shortcuts. Finding these shortcuts are hard and some good topics for future research in cryptography.
- MrXOR 6y agoHypothetical roadmap for next 10 years: Binary FF DLP --> Prime FF DLP --> EC in prime FF --> RSA? --> ElGamal? --> ...