Tags: hyperelliptic-curves

Rating:

All divisors have order $p+1$, so we can compute Weil pairings; computing discrete logarithms in $\mathbb F_{p^2}$ gives us independent linear equations to get the numbers $e[0],e[1],e[2]$.

Original writeup (https://pwnthem0le.polito.it/2020/12/20/hxpCTF-2020-Hyper-writeup/).