Improving the parallelized Pollard lambda search on anomalous binary curves
Robert P. Gallant, Robert Lambert, Scott A. Vanstone · Mathematics of Computation · 1999
The best algorithm known for finding logarithms on an elliptic curve ( E ) (E) is the (parallelized) Pollard lambda collision search. We show how to apply a Pollard lambda search on a set of equivalence classes derived from E E , which requires fewer iterations than the standard approach. In the case of anomalous binary curves over F 2 m F_{2^m} , the new approach speeds up the standard algorithm by a factor of 2 m \sqrt {2m} .