Factoring Estimates for a 1024-Bit RSA Modulus

  • Arjen Lenstra
  • Eran Tromer
  • Adi Shamir
  • Wil Kortsmit
  • Bruce Dodson
  • James Hughes
  • Paul Leyland
Part of the Lecture Notes in Computer Science book series (LNCS, volume 2894)


We estimate the yield of the number field sieve factoring algorithm when applied to the 1024-bit composite integer RSA-1024 and the parameters as proposed in the draft version [17] of the TWIRL hardware factoring device [18]. We present the details behind the resulting improved parameter choices from [18].


1024-bit RSA factorization number field sieve TWIRL 


Copyright information

© Springer-Verlag Berlin Heidelberg 2003

Authors and Affiliations

  • Arjen Lenstra
    • 1
  • Eran Tromer
    • 2
  • Adi Shamir
    • 2
  • Wil Kortsmit
    • 3
  • Bruce Dodson
    • 4
  • James Hughes
    • 5
  • Paul Leyland
    • 6
  1. 1.Citibank, N.A. and Technische Universiteit EindhovenMendhamUSA
  2. 2.Department of Computer Science and Applied MathematicsWeizmann Institute of ScienceRehovotIsrael
  3. 3.Technische Universiteit EindhovenEindhovenThe Netherlands
  4. 4.Lehigh UniversityBethlehemUSA
  5. 5.Storage Technology CorporationMinneapolisUSA
  6. 6.Microsoft Research LtdCambridgeUK

