The set of such points over Y, together with a point at infinity, denoted O, form the elliptic curve E(K). ... Then, E(K) is finite and, by Hassea#39;s theorem, its cardinality is bounded by q + 1 a 2, /.7 5 |E(K)| 5 q + 1 + 2\/if. The security of the cryptosystem is based on the difficulty of the elliptic curve discrete logarithm problem (ECDLP): Given a rational point P ... fact that, whereas sub-exponential algorithms of complexity O(exp(c(log q)1/ 3(log log q)2/ 3)) exist that solve the DLP over F, (see , e.g., anbsp;...

Title | : | 1999 IEEE International Symposium on Information Theory |

Author | : | |

Publisher | : | IEEE - 1999-01-01 |

