Computing Discrete Logarithms [pdf]
eprint.iacr.org
eprint.iacr.org
This is a pretty neat survey and includes a lot of stuff you're not going to run into in practical, deployed, conventional systems (it'll also give you some pointers to background behind things in SafeCurves).
A choice quote:
Progress in cryptanalytic algorithms, just as in science more
generally, usually evolves by small increments but with occasional
revolutionary steps forward [54]. One example of such a step
forward could arguably be the rapid development of efficient
algorithms for solving the DLP in finite fields of fixed
characteristic, that took place from late 2012 to mid 2014, thanks
to the present authors and their collaborators. Between these
times, the fastest algorithm for solving this problem went from
having complexity L(1/3) to being quasi-polynomial, rendering such
fields entirely unsuitable for discrete logarithm-based
cryptography, including pairing-based cryptography over small
characteristic supersingular curves. These events constitute a
perfect example of Prof. Lenstra’s (perhaps jocular, but no doubt
in part quite serious) contention that no problem based on number
theory should ever be considered truly secure, even if it has
remained impenetrable for several decades.
† ie: not