Batch NFS

D.J. Bernstein, T. Lange

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageAcademicpeer review

9 Citaten (Scopus)

Samenvatting

This paper shows, assuming standard heuristics regarding the number-field sieve, that a "batch NFS" circuit of area L^{1.181...+o(1)} factors L^{0.5+o(1)} separate B-bit RSA keys in time L^{1.022...+o(1)}. Here L=exp((log 2^B)^{1/3}(log log 2^B)^{2/3}). The circuit's area-time product (price-performance ratio) is just L^{1.704...+o(1)} per key. For comparison, the best area-time product known for a single key is L^{1.976...+o(1)}. This paper also introduces new "early-abort" heuristics implying that "early-abort ECM" improves the performance of batch NFS by a superpolynomial factor, specifically exp((c+o(1))(log 2^B)^{1/6}(log log 2^B)^{5/6}) where c is a positive constant. Keywords: integer factorization, number-field sieve, price-performance ratio, batching, smooth numbers, elliptic curves, early aborts
Originele taal-2Engels
TitelSelected Areas in Cryptography -- SAC 2014: 21st International Conference, Montreal, QC, Canada, August 14-15, 2014, Revised Selected Papers
RedacteurenA. Joux, A. Youssef
UitgeverijSpringer
Pagina's38-58
ISBN van geprinte versie978-3-319-13050-7
DOI's
StatusGepubliceerd - 2014
Evenement21st International Conference on Selected Areas in Cryptography (SAC 2014) - Sackville, Canada
Duur: 14 aug. 201415 aug. 2014
Congresnummer: 21

Publicatie series

NaamLecture Notes in Computer Science
Volume8781
ISSN van geprinte versie0302-9743

Congres

Congres21st International Conference on Selected Areas in Cryptography (SAC 2014)
Verkorte titelSAC 2014
Land/RegioCanada
StadSackville
Periode14/08/1415/08/14
Ander21st International Conference on Selected Areas in Cryptography

Vingerafdruk

Duik in de onderzoeksthema's van 'Batch NFS'. Samen vormen ze een unieke vingerafdruk.

Citeer dit