Factoring estimates for a 1024-bit RSA modulus
Arjen K. Lenstra, Eran Tromer, Adi Shamir, Wil Kortsmit, Bruce Dodson, James P. Hughes, Paul C. Leyland · 2003
Abstract. We estimate the yield of the number field sieve factoring al-gorithm when applied to the 1024-bit composite integer RSA-1024 and the parameters as proposed in the draft version [17] of the TWIRL hard-ware factoring device [18]. We present the details behind the resulting improved parameter choices from [18].