On 03-04-2014 20:00, Trevor Perrin wrote: > On Wed, Apr 2, 2014 at 8:04 PM, Watson Ladd <[email protected]> wrote: >> Anyway, bottom line is genus 1 and 2 are where things are interesting. >> In genus 1 thanks to Edwards curves we have very nice arithmetic: >> genus 2 isn't so nice. > Hi Watson, > > So in your estimation, the best structure for discrete-log crypto > remains elliptic curves (in particular Edwards curves), and not > hyper-elliptic (or other genus>2) curves?
Genus 1 and 2 curves have been the only ones without better-than-rho attacks for around a decade now [1]. As the genus grows, index calculus attacks only get better [2]. [1] http://link.springer.com/chapter/10.1007%2F978-3-540-40061-5_5 [2] https://www.sciencedirect.com/science/article/pii/S0304397599000614 _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
