MOV attack in various subgroups on elliptic curves

We estimate the probabilities that the Menezes-OkamotoVanstone reduction of the discrete logarithm problem on an elliptic curve E to the discrete logarithm problem in a certain finite field succeeds for various groups on points on E. Our bounds imply that in all interesting cases these probabilities are exponentially small. This extends results of Balasubramanian and Koblitz who have treated the instance in which the order of the group of points on E is prime.