DLOG on other
abstract groups?

•Introduced because of *subexponential *attacks on DLOG over (**Z**/n**Z**)*.

•Idea: Find an isomorphic group where the structure of the integers is not as apparent.

•Also want computation to be efficient, e.g. by polynomial operations (rules out many abstract choices).

•Elliptic Curves: the set of solutions to an equation of the form

E : y2 = x3 + a x + b

over a finite field satisfies these
criteria.