Multiplicative Notation
- will give a result that is uniformly distributed between 1 and (p - 1), inclusive
- Given g, r and p, it is hard to deduce x
- If p is small, it is easy to find x
- If p is very large, it is hard to find x
Additive Notation
- Given is a standard elliptic curve and arbitrary nonzero
- where and (e.g. is 254-bit if is BN254 )
- is hard to find
- However, given and , one can compute in
General
- An instance of the Hidden Subgroup Problem (HSP)