Re: [Uta] updated I-Ds

Daniel Kahn Gillmor <dkg@fifthhorseman.net> Tue, 25 February 2014 20:55 UTC

Return-Path: <dkg@fifthhorseman.net>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF38C1A018C for <uta@ietfa.amsl.com>; Tue, 25 Feb 2014 12:55:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.8
X-Spam-Level:
X-Spam-Status: No, score=0.8 tagged_above=-999 required=5 tests=[BAYES_50=0.8] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w9ONg_lb2z7R for <uta@ietfa.amsl.com>; Tue, 25 Feb 2014 12:55:14 -0800 (PST)
Received: from che.mayfirst.org (che.mayfirst.org [209.234.253.108]) by ietfa.amsl.com (Postfix) with ESMTP id 682F11A01F3 for <uta@ietf.org>; Tue, 25 Feb 2014 12:55:14 -0800 (PST)
Received: from [10.70.10.98] (unknown [38.109.115.130]) by che.mayfirst.org (Postfix) with ESMTPSA id 36EE2F984; Tue, 25 Feb 2014 15:55:12 -0500 (EST)
Message-ID: <530D0323.7020509@fifthhorseman.net>
Date: Tue, 25 Feb 2014 15:54:59 -0500
From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Icedove/24.2.0
MIME-Version: 1.0
To: Watson Ladd <watsonbladd@gmail.com>
References: <52FD1424.4080400@stpeter.im> <CACsn0ckkJqx7EmNR3iwDCKw089LePHWguMmCvYpLz4dgYhUSzQ@mail.gmail.com>
In-Reply-To: <CACsn0ckkJqx7EmNR3iwDCKw089LePHWguMmCvYpLz4dgYhUSzQ@mail.gmail.com>
X-Enigmail-Version: 1.6
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="SA9xGqlqXwTnNvH1SA7ITCcTx7Psf0mXp"
Archived-At: http://mailarchive.ietf.org/arch/msg/uta/PFm2Fg-pNMuKQgOASbPfiWetPkI
Cc: "uta@ietf.org" <uta@ietf.org>
Subject: Re: [Uta] updated I-Ds
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Feb 2014 20:55:19 -0000

On 02/13/2014 02:51 PM, Watson Ladd wrote:
> Currently a 530 bit prime can be done effectively with 3 core years of sieving.

do you mean "a 530 bit composite can be factored…" here?

the CADO-NFS team reports roughly 6 core-years for RSA-155, a 512-bit
number:

 http://cado-nfs.gforge.inria.fr/#feat

so that's in the same ballpark.  But:

> This implies that a 1024 bit prime will take approximately 10.5 core years, 
> and 2048 bits 15 core years. 

These are alarmingly short estimates, given the parallelizability of GNFS.

Recent work (also with CADO-NFS):

  http://maths-people.anu.edu.au/~bai/paper/rsa704.pdf

suggests 12 core years for polynomial selection for RSA-704, and 500 CPU
years for sieving.

Can you explain your estimate of 10.5 core years for RSA-1024 or 15 core
years for RSA-2048?

Regards,

	--dkg