The Tower Number Field Sieve is only applicable to pairing-based ECC though, right? It doesn't impact the security of the curves used in most mainstream crypto (Curve25519, NIST P-256 etc).
> The number field sieve algorithm is still far from being fully understood, in particular for extension fields that are so important for pairing-based cryptography.
I won't say I understand it either. But it indeed seems to only be applicable in towers of extension fields which are only used for pairing-based cryptography.
> The number field sieve algorithm is still far from being fully understood, in particular for extension fields that are so important for pairing-based cryptography.
I won't say I understand it either. But it indeed seems to only be applicable in towers of extension fields which are only used for pairing-based cryptography.