| 250 | 250 | 14596 | 482 |
+-------------+-----------+--------------+--------------+
5.1. TWIRL Correction
If the TWIRL machine becomes a reality, and if there are advances in
parallelism for row reduction in factoring, then conservative
estimates would subtract about 11 bits from the system security
column of the table. Thus, in order to get 89 bits of security, one
would need an RSA modulus of about 1900 bits.
6. Security Considerations
The equations and values given in this document are meant to be as
accurate as possible, based on the state of the art in general
purpose computers at the time that this document is being written.
No predictions can be completely accurate, and the formulas given
here are not meant to be definitive statements of fact about
cryptographic strengths. For example, some of the empirical results
used in calibrating the formulas in this document are probably not
completely accurate, and this inaccuracy affects the estimates. It
is the authors’ hope that the numbers presented here vary from real
world experience as little as possible.
7. References
7.1. Informational References
[DL] Dodson, B. and A. K. Lenstra, NFS with four large primes:
an explosive experiment, Proceedings Crypto 95, Lecture
Notes in Comput. Sci. 963, (1995) 372-385.
[ECS] Eastlake, D., Crocker, S. and J. Schiller, "Randomness
Recommendations for Security", RFC 1750, December 1994.
[GIL98] Cracking DES: Secrets of Encryption Research, Wiretap
Politics & Chip Design , Electronic Frontier Foundation,
John Gilmore (Ed.), 272 pages, May 1998, O’Reilly &
Associates; ISBN: 1565925203
[GOR93] Gordon, D., "Discrete logarithms in GF(p) using the
number field sieve", SIAM Journal on Discrete
Mathematics, 6 (1993), 124-138.
[LEN93] Lenstra, A. K. and H. W. Lenstra, Jr. (eds), The
development of the number field sieve, Lecture Notes in
Math, 1554, Springer Verlag, Berlin, 1993.
[MH81] Merkle, R.C., and Hellman, M., "On the Security of
Multiple Encryption", Communications of the ACM, v. 24 n.
7, 1981, pp. 465-467.
[ODL95] RSA Labs Cryptobytes, Volume 1, No. 2 - Summer 1995; The
Future of Integer Factorization, A. M. Odlyzko
[ODL99] A. M. Odlyzko, Discrete logarithms: The past and the
future, Designs, Codes, and Cryptography (1999).
[POL78] J. Pollard, "Monte Carlo methods for index computation
mod p", Mathematics of Computation, 32 (1978), 918-924.
[RFC2409] Harkins, D. and D. Carrel, "The Internet Key Exchange
(IKE)", RFC 2409, November 1998.
[SCH95] R. Schroeppel, et al., Fast Key Exchange With Elliptic
Curve Systems, In Don Coppersmith, editor, Advances in
Cryptology -- CRYPTO 31 August 1995. Springer-Verlag
[SHAMIR03] Shamir, Adi and Eran Tromer, "Factoring Large Numbers
with the TWIRL Device", Advances in Cryptology - CRYPTO
2003, Springer, Lecture Notes in Computer Science 2729.
[SIL00] R. D. Silverman, RSA Laboratories Bulletin, Number 13 -
April 2000, A Cost-Based Security Analysis of Symmetric
and Asymmetric Key Lengths
[SILIEEE99] R. D. Silverman, "The Mythical MIPS Year", IEEE Computer,
August 1999.
8. Authors’ Addresses
Hilarie Orman
Purple Streak Development
500 S. Maple Dr.
Salem, UT 84653
EMail: hilarie@purplestreak.com and ho@alum.mit.edu
Paul Hoffman
VPN Consortium
127 Segre Place
Santa Cruz, CA 95060 USA
EMail: paul.hoffman@vpnc.org
9. Full Copyright Statement
Copyright (C) The Internet Society (2004). This document is subject
to the rights, licenses and restrictions contained in BCP 78, and
except as set forth therein, the authors retain all their rights.
This document and the information contained herein are provided on an
"AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE
REPRESENTS OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE
INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF
THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
Intellectual Property
The IETF takes no position regarding the validity or scope of any
Intellectual Property Rights or other rights that might be claimed
to pertain to the implementation or use of the technology
described in this document or the extent to which any license
under such rights might or might not be available; nor does it
represent that it has made any independent effort to identify any
such rights. Information on the procedures with respect to
rights in RFC documents can be found in BCP 78 and BCP 79.
Copies of IPR disclosures made to the IETF Secretariat and any
assurances of licenses to be made available, or the result of an
attempt made to obtain a general license or permission for the use
of such proprietary rights by implementers or users of this
specification can be obtained from the IETF on-line IPR repository
at http://www.ietf.org/ipr.
The IETF invites any interested party to bring to its attention
any copyrights, patents or patent applications, or other
proprietary rights that may cover technology that may be required
to implement this standard. Please address the information to the
IETF at ietf-ipr@ietf.org.
Acknowledgement
Funding for the RFC Editor function is currently provided by the
Internet Society.