4 ms·
DJB says following about all non-prime fields [1]: > Is ECDLP broken for non-prime fields? No. However, the security story for non-prime fields (e.g.,
by SaveTheRbtz 12y ago
DJB says following about all non-prime fields [1]:
> Is ECDLP broken for non-prime fields?
No. However, the security story for non-prime fields
(e.g., binary extension fields) is more complicated and
less stable than the security story for prime fields, as
illustrated by 1998 Frey, 2002 Gaudry–Hess–Smart, 2009
Gaudry, and 2012 Petit–Quisquater.
2006 Bernstein stated that prime fields "have the virtue
of minimizing the number of security concerns for
elliptic-curve cryptography". Similarly, the Brainpool
standard and NSA's Suite B standards require prime fields.
There is general agreement that prime fields are the safe,
conservative choice for ECC.
[1] http://safecurves.cr.yp.to/field.html http://safecurves.cr.yp.to/field.html