Question: There is a powerful attack (the MOV attack) that works best when the elliptic curve cryptosystem employs a point P whose order divides p^ k
There is a powerful attack (the MOV attack) that works best when the elliptic curve cryptosystem employs a point P whose order divides p^ k 1 for some k much smaller than p (it actually turns ECDLP in E(Zp) into DLP in the multiplicative group of the field with p k elements). Explain why this implies that an elliptic curve cryptosystem that uses E : y^ 2 = x^ 3 x defined over Zp with p (mod 4) = 3 is a poor idea.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
