[curves] The genus 3 setting

Samuel Neves sneves at dei.uc.pt
Thu Apr 3 13:17:32 PDT 2014

On 03-04-2014 20:00, Trevor Perrin wrote:
> On Wed, Apr 2, 2014 at 8:04 PM, Watson Ladd <watsonbladd at gmail.com> wrote:
>> Anyway, bottom line is genus 1 and 2 are where things are interesting.
>> In genus 1 thanks to Edwards curves we have very nice arithmetic:
>> genus 2 isn't so nice.
> Hi Watson,
> So in your estimation, the best structure for discrete-log crypto
> remains elliptic curves (in particular Edwards curves), and not
> hyper-elliptic (or other genus>2) curves?

Genus 1 and 2 curves have been the only ones without better-than-rho attacks for around a decade
now [1]. As the genus grows, index calculus attacks only get better [2].

[1] http://link.springer.com/chapter/10.1007%2F978-3-540-40061-5_5
[2] https://www.sciencedirect.com/science/article/pii/S0304397599000614

