Elliptic Curve Cryptosystems Immune to Any Reduction into the Discrete Logarithm Problem

Atsuko Miyaji · Institutional Repositories DataBase (IRDB) · 1993

In 1990, Menezes, Okamoto and Vanstone proposed a method that reduces EDLP to DLP, which gave an impact on the security of cryptosystems based on EDLP. But this reducing is valid only when Weil pairing can be defined over the m-torsion group which includes the base point of EDLP. If an elliptic curve is ordinary, there exists EDLP to which we cannot apply the reducing. In this paper, we investigate the condition for which this reducing is invalid. key words: Public-key, Discrete logarithms, Elliptic curves. 1

Read the paper · More papers on PaperTik