Beruflich Dokumente
Kultur Dokumente
Curve Cryptography
CT-RSA 2004
ECDLP
Given E,
P ∈ E(Fq), such that r =ord(P) a large prime,
and Q ∈ <P>,
find s ∈ [0,r-1] such that:
Q = sP .
All fields:
F2N
with
N ∈ [185,600]
and
N ≡ 0 (mod 5)
are weak.
TrF2210/F2(a) = 0 ,
and yields genus 15 or 16 curve only if
TrF2210/F2(b) = 0 .
Cost to find E’ :
≈ 260 operations in F2210 .
Cost to compute explicit isogeny E → E’ :
const x 253 bit operations .
N = 210 = nl
Recall:
n=6 data only apply when #E(F2210) ≡ 0 mod 8,
that is, to ≈ 1/4 of all E(F2210).
Summary: Weakness of F2210 (cont)
Remark 1:
For almost* all E(F2210), the ECDLP in E(F2210) can be
reduced to a DLP in the Jacobian variety of a curve
of genus ≤ 14.
Subexponential algorithms for solving this DLP apply.
(F. Hess: The GHS attack revisited, Eurocrypt 2003).
Remark 2:
Results analogous to the above apply to all finite fields
F2N with N=6l.