The best concrete bit-security one can achieve for a dlog-based construction on a 256 bit algebraic group is 128 bits, right?
Well, usually yes, but sometimes, somewhat surprisingly, better concrete security is possible:
add a skeleton here at some point
about 1 month ago