The LMS JCM, (7) 50-72. Published 22 Mar 2004. First received 15 Dec 2003.


The equivalence between the DHP and DLP for elliptic curves used in practical applications

A. Muzereau, N. P. Smart and F. Vercauteren



Abstract: The Weil descent construction of the GHS attack on the elliptic curve discrete logarithm problem (ECDLP) is generalised in this paper, to arbitrary Artin-Schreier extensions. A formula is given for the characteristic polynomial of Frobenius for the curves thus obtained, as well as a proof that the large cyclic factor of the input elliptic curve is not contained in the kernel of the composition of the conorm and norm maps. As an application, the number of elliptic curves that succumb to the basic GHS attack is considerably increased, thereby further weakening curves over GF2155.

Other possible extensions or variations of the GHS attack are discussed, leading to the conclusion that they are unlikely to yield further improvements.

This paper is available as PDF (172 KB).

All papers published in the LMS JCM are covered by a copyright agreement with the authors. Access to the papers is bound by this agreement; click here for details.

Go to the Volume 7 index
Return to the LMS JCM Homepage