English

Comparing the difficulty of factorization and discrete logarithm: a 240-digit experiment

Cryptography and Security 2020-06-12 v1

Abstract

We report on two new records: the factorization of RSA-240, a 795-bit number, and a discrete logarithm computation over a 795-bit prime field. Previous records were the factorization of RSA-768 in 2009 and a 768-bit discrete logarithm computation in 2016. Our two computations at the 795-bit level were done using the same hardware and software, and show that computing a discrete logarithm is not much harder than a factorization of the same size. Moreover, thanks to algorithmic variants and well-chosen parameters, our computations were significantly less expensive than anticipated based on previous records.The last page of this paper also reports on the factorization of RSA-250.

Cite

@article{arxiv.2006.06197,
  title  = {Comparing the difficulty of factorization and discrete logarithm: a 240-digit experiment},
  author = {Fabrice Boudot and Pierrick Gaudry and Aurore Guillevic and Nadia Heninger and Emmanuel Thomé and Paul Zimmermann},
  journal= {arXiv preprint arXiv:2006.06197},
  year   = {2020}
}
R2 v1 2026-06-23T16:13:34.524Z