The problem comes when a and b parameters are large, specifically for 163 bit elliptic curve parameters. I can generate random point of the elliptic curve of 163 bits. However, when I compute its order, it displays exhaust memory and then it exits and some times Jim dead message is displayed.
I could not understand the problem. Could you say something for me regarding this problem? Thank you in advance.
http://ask.sagemath.org/question/9020/order-of-randomly-generated-elliptic-curve/?comment=19696#post-id-19696Example: b = 0x423d0900aeb5645491fee539c297946cbc6a4f1f5
Z.<x>=GF(2)[]
K.<a>=GF(2^163, 'a', modulus = x^163 + x^7 + x^6 + x^3 + 1)
bb = Z(b.digits(2))
E = EllipticCurve(K,[1, 1, 0, 0, bb])
http://ask.sagemath.org/question/9020/order-of-randomly-generated-elliptic-curve/?answer=15783#post-id-15783Sage is not magic. If no-one has implemented a procedure for computing orders of curves over such large binary fields, then it will revert to using a generaic procedure, and that will not work in reasonable time.
I think that the documentation does say something about this: apart from prime fields, where Sage uses a pretty good SEA implementation from PARI, the point-counting abilities are definitely not good enough for fields of cryptographic interest.
Feel free to contribute something better!
In particular, trac tickets http://trac.sagemath.org/ticket/11448 http://trac.sagemath.org/ticket/11548 seem relevant.