Comparing the Difficulty of Factorization and Discrete Logarithm: A 240-Digit Experiment
Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé, Paul Zimmermann
Abstract
We report on two new records: the factorization of RSA-240, a 795-bit number, and a discrete logarithm computation over a 795-bit prime field. Previous records were the factorization of RSA-768 in 2009 and a 768-bit discrete logarithm computation in 2016. Our two computations at the 795-bit level were done using the same hardware and software, and show that computing a discrete logarithm is not much harder than a factorization of the same size. Moreover, thanks to algorithmic variants and well-chosen parameters, our computations were significantly less expensive than anticipated based on previous records. The last page of this paper also reports on the factorization of RSA-250.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Reducing the Number of Qubits in Quantum FactoringClémence Chevignard, Pierre-Alain Fouque, André SchrottenloherCRYPTO 2025 · 8 citations
- New Results on the φ-Hiding Assumption and Factoring Related RSA ModuliJun Xu, Jun Song, Lei HuCRYPTO 2025
- The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA ModuliMatús Nemec, Marek Sýs, Petr Svenda, Dusan Klinec et al.CCS 2017 · 147 citations
- Improved Distributed RSA Key Generation Using the Miller-Rabin TestJakob Burkhardt, Ivan Damgård, Tore Kasper Frederiksen, Satrajit Ghosh et al.CCS 2023 · 10 citations
- Generically Speeding-Up Repeated Squaring Is Equivalent to Factoring: Sharp Thresholds for All Generic-Ring Delay FunctionsLior Rotem, Gil SegevCRYPTO 2020 · 22 citations
