How are elliptic curves selected?
Unlike DLOG on
, there can be
many elliptic curves having the same order.
Elliptic curves over finite fields can be
“supersingular”: have subexponential attacks.
“ordinary”: so far, no subexponential attacks.*
) to be prime, or at least have a
large prime factor. E(
should be a cyclic
Essentially: known pitfalls are avoided, with limited understanding.
Are any other factors important?