Does anyone know if the discrete log problem of these small prime fields: Goldilocks, Babybear, Mersenne31, has been solved?
If not, is there a small prime field in which the discrete log of any element can be computed in poly-logarithmic time of the order of the field?
Quote from https://blog.icme.io/small-fields-for-zero-knowledge/
- Polygon's 'Plonky2' uses a field defined as $p = 2^{64} - 2^{32} + 1$, which is called the Goldilocks field.
- The zkVM Risc0 uses a smaller field called BabyBear defined as: $p = 15 \cdot 2^{27} + 1$.
- Plonky3: utilizes one even smaller Mersenne31: $p = 2^{31} - 1 .$ (1772, Leonhard Euler)