We compare the method of Weil descent for solving the ECDLP, over extensions fields of composite degree in characteristic two, against the standard method of parallelised Pollard rho. We give details of a theoretical and practical comparison and then use this to analyse the difficulty of actually solving the ECDLP for curves of the size needed in practical cryptographic systems. We show that composite degree extensions of degree divisible by four should be avoided. We also examine the elliptic curves proposed in the Oakley key determination protocol and show that with current technology they remain secure.
|Translated title of the contribution
|How secure are elliptic curves over composite extension fields?
|Title of host publication
|Advances in Cryptology - EUROCRYPT2001
|Springer Berlin Heidelberg
|30 - 39
|Number of pages
|Published - May 2001