> Our computations show that trapdoored primes are entirely feasible with current computing technology.
Can anyone explain to me what is the risk with such trapdoored primes? Thanks!
Can anyone explain to me what is the risk with such trapdoored primes? Thanks!
I welcome correction.
EDIT: Time squeezed per tptacek, computation space reference removed per schoen.
I think kilobit refers to the prime field of 1024 bit. If you look at last page of the paper there is a table with the details of the cluster they used. Roughly 28 nodes with 512 GiB, 48 nodes with 64 GiB and a few bits and pieces.
The apparent difficulty of factorization underlies some public-key systems (like RSA), while the apparent difficulty of extracting discrete logarithms underlies others (like Diffie-Hellman key exchange and DSA). This research is about the second problem.