If Algorithm 6.3.8 fails for one random elliptic curve, there is an option that is unavailable with Pollard's -method--we may repeat the above algorithm with a different elliptic curve. With Pollard's method we always work with the group , but here we can try many groups for many curves . As mentioned above, the number of points on over is of the form for some with ; Algorithm 6.3.8 thus has a chance if is -power-smooth for some with .
William 2007-06-01