The Elliptic Curve Method for integer factorization (ECM) was invented by H. W. Lenstra, Jr., in 1985 [14]. In the past 20 years, many improvements of ECM were proposed on the mathematical, algorithmic, and implementation sides. This paper summarizes the current state-of-the-art, as implemented in the GMP-ECM software.
We report on algorithmic aspects of the problem of explicitly computing the rate of growth of the field of N k -th division points on an n-dimensional simple Abelian variety with Complex Multiplication. Two new examples are discussed.
We estimate the yield of the number field sieve factoring algorithm when applied to the 1024-bit composite integer RSA-1024 and the parameters as proposed in the draft version [17] of the TWIRL hardware factoring device [18]. We present the details behind the resulting improved parameter choices from [18].
We report the factorization of a 135-digit integer by the triple-large-prime variation of the multiple polynomial quadratic sieve. Previous workers [6][10] had suggested that using more than two large primes would be counterproductive, because of the greatly increased number of false reports from the sievers. We provide evidence that, for this number and our implementation, using three large primes is approximately 1.7 times as fast as using only two. The gain in efficiency comes from a sudden growth in the number of cycles arising from relations which contain three large primes. This effect, which more than compensates for the false reports, was not anticipated by the authors of [6] [10] but has become quite familiar from factorizations obtained using the number field sieve. We characterize the various types of cycles present, and give a semi-quantitative description of their rather mysterious behaviour.
The purpose of this paper is to report the unexpected results that we obtained while experimenting with the multi-large prime variation of the general number field sieve integer factoring algorithm (NFS, cf. [8]). For traditional factoring algorithms that make use of at most two large primes, the completion time can quite accurately be predicted by extrapolating an almost quartic and entirely 'smooth' function that counts the number of useful combinations among the large primes [1]. For NFS such extrapolations seem to be impossible--the number of useful combinations suddenly 'explodes' in an as yet unpredictable way, that we have not yet been able to understand completely. The consequence of this explosion is that NFS is substantially faster than expected, which implies that factoring is somewhat easier than we thought.
We present data concerning the factorization of the 120-digit number RSA-120, which we factored on July 9, 1993, using the quadratic sieve method. The factorization took approximately 825 MIPS years and was completed within three months real time. At the time of writing RSA-120 is the largest integer ever factored by a general purpose factoring algorithm. We also present some conservative extrapolations to estimate the difficulty of factoring even larger numbers, using either the quadratic sieve method or the number field sieve, and discuss the issue of the crossover point between these two methods.
This paper reports on the factorization of the 512-bit number RSA-155 by the Number Field Sieve factoring method (NFS) and discusses the implications for RSA.
On February 2, 1999, we completed the factorization of the 140-digit number RSA-140 with the help of the Number Field Sieve factoring method (NFS). This is a new general factoring record. The previous record was established on April 10, 1996 by the factorization of the 130-digit number RSA-130, also with the help of NFS. The amount of computing time spent on RSA-140 was roughly twice that needed for RSA-130, about half of what could be expected from a straightforward extrapolation of the computing time spent on factoring RSA-130. The speed-up can be attributed to a new polynomial selection method for NFS which will be sketched in this paper. The implications of the new polynomial selection method for factoring a 512-bit RSA modulus are discussed and it is concluded that 512-bit (= 155-digit) RSA moduli are easily and realistically within reach of factoring efforts similar to the one presented here.
On February 2, 1999, we completed the factorization of the 140-digit number RSA-140 with the help of the Number Field Sieve factoring method (NFS). This is a new general factoring record. The previous record was established on April 10, 1996 by the factorization of the 130-digit number RSA-130, also with the help of NFS. The amount of computing time spent on RSA-140 was roughly twice that needed for RSA-130, about half of what could be expected from a straightforward extrapolation of the computing time spent on factoring RSA-130. The speed-up can be attributed to a new polynomial selection method for NFS which will be sketched in this paper.
We present data concerning the factorization of the 130-digit number RSA130 which we factored on April 10, 1996, using the Number Field Sieve factoring method. This factorization beats the 129-digit record that was set on April 2, 1994, by the Quadratic Sieve method. The amount of computer time spent on our new record factorization is only a fraction of what was spent on the previous record. We also discuss a World Wide Web interface to our sieving program that we have developed to facilitate contributing to the sieving stage of future large scale factoring efforts. These developments have a serious impact on the security of RSA public key cryptosystems with small moduli. We present a conservative extrapolation to estimate the difficulty of factoring 512-bit numbers.
Let (K, @) be a primitive CM-type with [K: O] = 2n (for definitions and previous results see Section 1.1). Fix n, and consider the collection s(n) = {Rank(@)}, where Rank(@) counts the number of independent translates of Qi under the Galois action and (K, @) ranges over all primitive types. The smallest element of S(n), denoted by B(n), is referred to as the sharp lower bound for the rank in dimension n. As was brought to the author’s attention by Ribet, bounds on B(n) of the form p + 1, for p a prime dividing n, follow directly from the proof of Ribet’s Nondegeneracy Theorem [21]. This is recorded as Theorem 1.4. Ribet’s method also gives bounds of the form 2q for q a prime with q2 dividing n, as is observed in Theorem 1.12. When combined with the author’s constructions of Abelian varieties in [S, 91, we obtain the precise value of B(n) for many values of n (Corollaries 1.5 to 1.8 and 1.13). We recall that these constructions use the analytic method of Weil and Shimura, together with new results on the reflex field from an investigation suggested to the author by Shim’ura. The interest of the rank comes from the theory of complex multiplication. If A is an Abelian variety of CM-type (K, @), then the Kubota Rank of A is Rank (@), and controls properties of the classfields constructed from A as in Kubota [ 161 and Ribet [20]. This is connected with the fact that the rank of @ is also the dimension of the Mumford-Tate group of A, and with the relation of this group to the I-adic representations of A, as in Serre [24, 251. The main body of the paper contains results that provide information on S(n). The main result, Theorem 2.5, asserts that when n is odd there is a computable subset S,‘,,,(n) of S(n) that accounts for the ranks of many CM-types on most CM-fields. More precisely, let K, be the maximal totally real subfield of K, and Kg be the Galois closure of K,. We consider the per-
A C M CM -field K K defines a triple ( G , H , ρ ) (G,H,\rho ) , where G G is the Galois group of the Galois closure of K K , H H is the subgroup of G G fixing K K , and ρ ∈ G \rho \in G is induced by complex conjugation. A " ρ \rho -structure" identifies C M CM -fields when their triples are identified under the action of the group of automorphisms of G G . A classification of the ρ \rho -structures is given, and a general formula for the degree of the reflex field is obtained. Complete lists of ρ \rho -structues and reflex fields are provided for [ K : Q ] = 2 n [K:\mathbb {Q}] = 2n , with n = 3 , 4 , 5 n = 3,4,5 and 7 7 . In addition, simple degenerate Abelian varieties of C M CM -type are constructed in every composite dimension. The collection of reflex fields is also determined for the dihedral group G = D 2 n G = {D_{2n}} , with n n odd and H H of order 2 2 , and a relative class number formula is found.
Herman Te Riele合作论文数ERCOM (European Research Centres of Mathematics)
Het Koninklijk Wiskundig Genootschap4
François Morain合作论文数LIX Laboratoire d'Informatique de l' ?0?7cole Polytechnique ?0?7quipe Cryptologie1