February 26, 2002
Practical Aspects of Modern Cryptography
46
Why not use Elliptic Curves?
nEC discrete logarithms have been studied far less than integer discrete logarithms.
nResults have shown that a fundamental break in integer discrete logs would also yield a fundamental break in EC discrete logs, although the reverse may not be true.
nBasic EC operations are more cumbersome than integer operations, so EC is only faster if the keys are much smaller.