Lifting Discrete Logarithm Based Cryptography to Post-Quantum Cryptography
eprint.iacr.org
eprint.iacr.org
The author uses similar wording a couple times and it is a little ambiguous? Does "does not have" mean a superpolynomial quantum lower bound has been discovered for this algorithm (or is there a reduction to some other important conjectured complexity theorem)? Or is it just that a polynomial algorithm has not been discovered yet?
It's almost as bad as saying that NP stands for Non Polynomial time.