Can someone explain how the Gallant-Lambert-Vanstone method works (or which literature explains it)?
It is also unclear to me how the Frobenius endomorphism can be used in some cases for a speedup.
Also: how does it make sure that an attack remains infeasible (by using this method)?
(I am especially interested because of the sec256k1 curve which uses the method)