Abstract
We present data concerning the factorization of the 120-digit number RSA-120, which we factored on July 9, 1993, using the quadratic sieve method. The factorization took approximately 825 MIPS years and was completed within three months real time. At the time of writing RSA-120 is the largest integer ever factored by a general purpose factoring algorithm. We also present some conservative extrapolations to estimate the difficulty of factoring even larger numbers, using either the quadratic sieve method or the number field sieve, and discuss the issue of the crossover point between these two methods.
Chapter PDF
Similar content being viewed by others
Keywords
These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
References
Bernstein, D. J., Lenstra, A. K.: A general number field sieve implementation. 103–126 in Lenstra, Jr. H. W. (eds): The development of the number field sieve. Lecture Notes in Math. 1554, Springer-Verlag, Berlin, 1993 [7]
Buhler, J. P., Lenstra, Jr., H. W., Pomerance, C: Factoring integers with the number field sieve. 50–94 in Lenstra, Jr. H. W. (eds): The development of the number field sieve. Lecture Notes in Math. 1554, Springer-Verlag, Berlin, 1993 [7]
Buchmann, J.A., Denny, T. F.: An implementation of the multiple polynomial quadratic sieve, University of Saarbrücken (to appear)
Dixon, B., Lenstra, A. K.: Factoring integers using SIMD sieves. Advances in Cryptology, Eurocrypt’ 93, Lecture Notes in Comput. Sci. (to appear)
LaMacchia, B.A., Odlyzko, A.M.: Computation of discrete logarithms in prime fields. Designs, Codes and Cryptography 1 (1991) 47–62
Lenstra, A.K.: Massively parallel computing and factoring. Proceedings Latin’92, Lecture Notes in Comput. Sci. 583 (1992) 344–355
Lenstra, A. K., Lenstra, Jr. H. W. (eds): The development of the number field sieve. Lecture Notes in Math. 1554, Springer-Verlag, Berlin, 1993
Lenstra, A.K., Lenstra, Jr., H.W., Manasse, M.S., Pollard, J.M.: The number field sieve. 11–42 in Lenstra, Jr. H. W. (eds): The development of the number field sieve. Lecture Notes in Math. 1554, Springer-Verlag, Berlin, 1993 [7]
Lenstra, A.K., Lenstra, Jr., H. W., Manasse, M. S., Pollard, J. M.: The factorization of the ninth Fermat number. Math. Comp. 61 (1993) 319–349
Lenstra, A.K., Manasse, M.S.: Factoring by electronic mail. Advances in Cryptology, Eurocrypt’ 89, Lecture Notes in Comput. Sci. 434 (1990) 355–371
Lenstra, A. K., Manasse, M. S.: Factoring with two large primes. Math. Comp. (to appear); extended abstract in: Advances in Cryptology, Eurocrypt’ 90, Lecture Notes in Comput. Sci. 473 (1991) 72–82
Pomerance, C: The quadratic sieve factoring algorithm. Lecture Notes in Comput. Sci. 209 (1985) 169–182
Pomerance, C., Smith, J. W.: Reduction of huge, sparse matrices over finite fields via created catastrophes. Experiment. Math. 1 (1992) 89–94
RSA Data Security Corporation Inc., sci.crypt, May 18, 1991; information available by sending electronic mail to challenge-rsa-list@rsa.coia
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 1994 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Denny, T., Dodson, B., Lenstra, A.K., Manasse, M.S. (1994). On the factorization of RSA-120. In: Stinson, D.R. (eds) Advances in Cryptology — CRYPTO’ 93. CRYPTO 1993. Lecture Notes in Computer Science, vol 773. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-48329-2_15
Download citation
DOI: https://doi.org/10.1007/3-540-48329-2_15
Published:
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-57766-9
Online ISBN: 978-3-540-48329-8
eBook Packages: Springer Book Archive