[curves] Twist security and induced distributions

David Leon Gil coruus at gmail.com
Wed Nov 12 09:22:51 PST 2014


What is the distribution induced on the trace of Frobenius by choosing a
curve such that its twist has nearly prime order?

(I.e., is it any different from the distribution induced by choosing a
curve parameter at random, which -- as I understand it -- is the Sato-Tate
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/curves/attachments/20141112/b1040ea1/attachment.html>

More information about the Curves mailing list