 , an 
elliptic curve
, an 
elliptic curve  over
 over 
 , and a point
, and a point 
 .
.
 and sends
 and sends  .
.
 and sends
 and sends  .
.
 , which both Michael and
Nikita can compute.
, which both Michael and
Nikita can compute. 
 without solving the discrete logarithm 
problem
(see Problem 3.1.2 and Section 6.4.3 below) 
in
 without solving the discrete logarithm 
problem
(see Problem 3.1.2 and Section 6.4.3 below) 
in 
 .   For well-chosen
.   For well-chosen  ,
,  , and
, and  experience suggests
that the discrete logarithm problem
in
 experience suggests
that the discrete logarithm problem
in 
 is much more difficult than the discrete
logarithm problem in
 is much more difficult than the discrete
logarithm problem in 
 (see Section 6.4.3 for more on the elliptic
curve discrete log problem).
(see Section 6.4.3 for more on the elliptic
curve discrete log problem).
William 2007-06-01