{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T14:13:58Z","timestamp":1773238438288,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":24,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540418986","type":"print"},{"value":"9783540453536","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[1999]]},"DOI":"10.1007\/3-540-45353-9_23","type":"book-chapter","created":{"date-parts":[[2007,7,16]],"date-time":"2007-07-16T15:50:02Z","timestamp":1184601002000},"page":"308-318","source":"Crossref","is-referenced-by-count":27,"title":["Analysis of the Weil Descent Attack of Gaudry, Hess and Smart"],"prefix":"10.1007","author":[{"given":"Alfred","family":"Menezes","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minghua","family":"Qu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2001,4,2]]},"reference":[{"key":"23_CR1","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1007\/3-540-58691-1_39","volume-title":"Algorithmic Number Theory","author":"L. Adleman","year":"1994","unstructured":"L. Adleman, J. DeMarrais and M. Huang, \u201cA subexponential algorithm for discrete logarithms over the rational subgroup of the jacobians of large genus hyperelliptic curves over finite fields\u201d, Algorithmic Number Theory, LNCS 877, 1994, 28\u201340."},{"key":"23_CR2","doi-asserted-by":"publisher","first-page":"95","DOI":"10.2307\/2007876","volume":"48","author":"D. Cantor","year":"1987","unstructured":"D. Cantor, \u201cComputing in the jacobian of a hyperelliptic curve\u201d, Mathematics of Computation, 48 (1987), 95\u2013101.","journal-title":"Mathematics of Computation"},{"key":"23_CR3","unstructured":"A. Enge, \u201cThe extended Euclidean algorithm on polynomials, and the efficiency of hyperelliptic cryptosystems\u201d, Designs, Codes and Cryptography, to appear."},{"key":"23_CR4","unstructured":"A. Enge and P. Gaudry, \u201cA general framework for subexponential discrete logarithm algorithms\u201d, Rapport de Recherche Lix\/RR\/00\/04, June 2000. Available from \n                    https:\/\/2.zoppoz.workers.dev:443\/http\/ultralix.polytechnique.fr\/Labo\/Pierrick.Gaudry\/papers.html"},{"key":"23_CR5","unstructured":"G. Frey, \u201cHow to disguise an elliptic curve (Weil descent) \u201d, Talk at ECC\u2019 98, Waterloo, 1998. Slides available from \n                    https:\/\/2.zoppoz.workers.dev:443\/http\/www.cacr.math.uwaterloo.ca\/conferences\/1998\/ecc98\/slides.html"},{"key":"23_CR6","unstructured":"G. Frey, \u201cApplications of arithmetical geometry to cryptographic constructions\u201d, Proceedings of the Fifth International Conference on Finite Fields and Applications, to appear. Also available from \n                    https:\/\/2.zoppoz.workers.dev:443\/http\/www.exp-math.uni-essen.de\/zahlentheorie\/preprints\/Index.html"},{"key":"23_CR7","unstructured":"G. Frey and H. R\u00fcck, \u201cA remark concerning m-divisibility and the discrete logarithm in the divisor class group of curves\u201d, Mathematics of Computation, 62 (1994), 865\u2013874."},{"key":"23_CR8","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1007\/3-540-46665-7_23","volume-title":"Codes and Cryptography","author":"S. Galbraith","year":"1999","unstructured":"S. Galbraith and N. Smart, \u201cA cryptographic application of Weil descent\u201d, Codes and Cryptography, LNCS 1746, 1999, 191\u2013200."},{"key":"23_CR9","unstructured":"R. Gallant, R. Lambert and S. Vanstone, \u201cImproving the parallelized Pollard lambda search on binary anomalous curves\u201d, to appear in Mathematics of Computation."},{"key":"23_CR10","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/3-540-45539-6_2","volume-title":"Advances in Cryptology \u2014 Eurocrypt 2000","author":"P. Gaudry","year":"2000","unstructured":"P. Gaudry, \u201cAn algorithm for solving the discrete log problem on hyperelliptic curves\u201d, Advances in Cryptology \u2014 Eurocrypt 2000, LNCS 1807, 2000, 19\u201334."},{"key":"23_CR11","unstructured":"P. Gaudry, F. Hess and N. Smart, \u201cConstructive and destructive facets of Weil descent on elliptic curves\u201d, preprint, January 2000. Available from \n                    https:\/\/2.zoppoz.workers.dev:443\/http\/ultralix.polytechnique.fr\/Labo\/Pierrick.Gaudry\/papers.html"},{"key":"23_CR12","unstructured":"Internet Engineering Task Force, The OAKLEY Key Determination Protocol, IETF RFC 2412, November 1998."},{"key":"23_CR13","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1007\/3-540-46766-1_22","volume-title":"Advances in Cryptology \u2014 Crypto\u2019 91","author":"N. Koblitz","year":"1992","unstructured":"N. Koblitz, \u201cCM-curves with good cryptographic properties\u201d, Advances in Cryptology \u2014 Crypto\u2019 91, LNCS 576, 1992, 279\u2013287."},{"key":"23_CR14","doi-asserted-by":"crossref","first-page":"1639","DOI":"10.1109\/18.259647","volume":"39","author":"A. Menezes","year":"1993","unstructured":"A. Menezes, T. Okamoto and S. Vanstone, \u201cReducing elliptic curve logarithms to logarithms in a finite field\u201d, tiIEEE Transactions on Information Theory, 39 (1993), 1639\u20131646.","journal-title":"tiIEEE Transactions on Information Theory"},{"key":"23_CR15","unstructured":"National Institute of Standards and Technology, Digital Signature Standard, FIPS Publication 186-2, February 2000."},{"key":"23_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/PL00003816","volume":"12","author":"P. Oorschot van","year":"1999","unstructured":"P. van Oorschot and M. Wiener, \u201cParallel collision search with cryptanalytic applications\u201d, Journal of Cryptology, 12 (1999), 1\u201328.","journal-title":"Journal of Cryptology"},{"key":"23_CR17","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"576","DOI":"10.1007\/BFb0054894","volume-title":"Algorithmic Number Theory","author":"S. Paulus","year":"1998","unstructured":"S. Paulus and A. Stein, \u201cComparing real and imaginary arithmetics for divisor class groups of hyperelliptic curves\u201d, Algorithmic Number Theory, LNCS 1423, 1998, 576\u2013591."},{"key":"23_CR18","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1109\/TIT.1978.1055817","volume":"24","author":"S. Pohlig","year":"1978","unstructured":"S. Pohlig and M. Hellman, \u201cAn improved algorithm for computing logarithms over GF(p) and its cryptographic significance\u201d, IEEE Transactions on Information Theory, 24 (1978), 106\u2013110.","journal-title":"IEEE Transactions on Information Theory"},{"key":"23_CR19","doi-asserted-by":"publisher","first-page":"918","DOI":"10.2307\/2006496","volume":"32","author":"J. Pollard","year":"1978","unstructured":"J. Pollard, \u201cMonte Carlo methods for index computation mod p\u201d, Mathematics of Computation, 32 (1978), 918\u2013924.","journal-title":"Mathematics of Computation"},{"key":"23_CR20","first-page":"81","volume":"47","author":"T. Satoh","year":"1998","unstructured":"T. Satoh and K. Araki, \u201cFermat quotients and the polynomial time discrete log algorithm for anomalous elliptic curves\u201d, Commentarii Mathematici Universitatis Sancti Pauli, 47 (1998), 81\u201392.","journal-title":"Commentarii Mathematici Universitatis Sancti Pauli"},{"key":"23_CR21","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1090\/S0025-5718-98-00887-4","volume":"67","author":"I. Semaev","year":"1998","unstructured":"I. Semaev, \u201cEvaluation of discrete logarithms in a group of p-torsion points of an elliptic curve in characteristic p\u201d, Mathematics of Computation, 67 (1998), 353\u2013356.","journal-title":"Mathematics of Computation"},{"key":"23_CR22","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/s001459900052","volume":"12","author":"N. Smart","year":"1999","unstructured":"N. Smart, \u201cThe discrete logarithm problem on elliptic curves of trace one\u201d, Journal of Cryptology, 12 (1999), 193\u2013196.","journal-title":"Journal of Cryptology"},{"key":"23_CR23","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1023\/A:1008306223194","volume":"19","author":"J. Solinas","year":"2000","unstructured":"J. Solinas, \u201cEficient arithmetic on Koblitz curves\u201d, Designs, Codes and Cryptography, 19 (2000), 195\u2013249.","journal-title":"Designs, Codes and Cryptography"},{"key":"23_CR24","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/3-540-48892-8_15","volume-title":"Selected Areas in Cryptography","author":"M. Wiener","year":"1999","unstructured":"M. Wiener and R. Zuccherato, \u201cFaster attacks on elliptic curve cryptosystems\u201d, Selected Areas in Cryptography, LNCS 1556, 1999, 190\u2013200."}],"container-title":["Lecture Notes in Computer Science","Topics in Cryptology \u2014 CT-RSA 2001"],"original-title":[],"link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/link.springer.com\/content\/pdf\/10.1007\/3-540-45353-9_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,2,17]],"date-time":"2019-02-17T23:31:58Z","timestamp":1550446318000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/link.springer.com\/10.1007\/3-540-45353-9_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1999]]},"ISBN":["9783540418986","9783540453536"],"references-count":24,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/3-540-45353-9_23","relation":{},"ISSN":["0302-9743"],"issn-type":[{"value":"0302-9743","type":"print"}],"subject":[],"published":{"date-parts":[[1999]]}}}