The security of pairing-based cryptography is based on the hardness of solving the discrete logarithm problem (DLP) over extension field GF(p) of characteristic p and degree n. Joux et al. proposed an asymptotically fastest algorithm for solving DLP over GF(p) (JLSV06-NFS) as the extension of the number field sieve over prime field GF(p) (JL03-NFS). The lattice sieve is often used for a largesc...