W Meier, O Staffelbach - Annual International Cryptology Conference, 1992 - Springer
… As already observed in [2], the elliptic curves used in the first construction are supersingular,
… The second construction applies to arbitrary elliptic curves over F, for any odd prime number …