- Integer factorization records
= Numbers of a general form =
The first very large distributed factorisation was RSA129, a challenge number described in the Scientific American article of 1977 which first popularised the RSA cryptosystem. It was factorised between September 1993 and April 1994, using MPQS, with relations contributed by about 600 people from all over the Internet, and the final stages of the calculation performed on a
MasPar supercomputer at Bell Labs.Between January and August 1999,
RSA-155 , a challenge number prepared by the RSA company, was factorised using GNFS with relations again contributed by a large group, and the final stages of the calculation performed in just over nine days on theCray C916 supercomputer at the SARA Amsterdam Academic Computer Center.In January 2002, Franke et al announced the factorisation of a 158-digit cofactor of 2953+1, using a couple of months on about 25 PCs at the
University of Bonn , with the final stages done using a cluster of six Pentium-III PCs.In April 2003, the same team factored
RSA-160 using about a hundred CPUs at BSI, with the final stages of the calculation done using 25 processors of anSGI Origin supercomputer.The 174-digit
RSA-576 was factored by Franke, Kleinjung and members of theNFSNET collaboration in December 2003, using resources at BSI and theUniversity of Bonn ; soon afterwards, Aoki, Kida, Shimoyama, Sonoda and Ueda announced that they had factored a 164-digit cofactor of 21826+1.A 176-digit cofactor of 11281+1 was factored by Aoki, Kida, Shimoyama and Ueda between February and May 2005 using machines at
NTT andRikkyo University in Japan. [cite web |url=http://www.loria.fr/~zimmerma/records/11_281+ |accessdate=2007-05-23 |title=Factorization of 176-digit number|author=K. Aoki, Y. Kida, T. Shimoyama, H. Ueda]The
RSA-200 challenge number was factored by Franke, Kleinjung et al between December 2003 and May 2005, using a cluster of 80 Opteron processors at BSI in Germany; the announcement was made on 9 May 2005. [cite web |url=http://www.loria.fr/~zimmerma/records/rsa200|accessdate=2007-05-23 |title=RSA200|author=F. Bahr, M. Boehm, J. Franke, T. Kleinjung] They later (November 2005) factored the slightly smallerRSA-640 challenge number.Numbers of a special form
12151−1, of 542 bits (163 digits), was factored between April and July 1993 by a team at
CWI andOregon State University . [cite web|url=http://krum.rz.uni-mannheim.de/cabench/sieve-record.html|accessdate=2007-11-23|title=Record Number Field Sieve Factorisations|author=P. L. Montgomery ]2773+1, of 774 bits (233 digits), was factored between April and November 2000 by 'The Cabal', with the matrix step done over 250 hours on the Cray also used for RSA-155. [cite web | url=http://ftp.cwi.nl/herman/SNFSrecords/SNFS-233|accessdate=2007-11-23|title=233-digit SNFS factorization|author='The Cabal' ]
2809-1, of 809 bits (244 digits), had its factorisation announced at the start of January 2003. Sieving was done at the CWI, at the Scientific Computing Institute and the Pure Mathematics Department at Bonn University, and using private resources of J. Franke, T. Kleinjung and the family of F. Bahr. The linear algebra step was done by P. Montgomery at SARA in Amsterdam. [cite web | url=http://ftp.cwi.nl/herman/SNFSrecords/SNFS-244|accessdate=2007-11-23|title=M809|author=J. Franke]
6353−1, of 911 bits (275 digits), was factored by Aoki, Kida, Shimoyama and Ueda between September 2005 and January 2006 using SNFS. [cite web |url=http://www.loria.fr/~zimmerma/records/6353|accessdate=2007-05-23 |title=SNFS274|author=K. Aoki, Y. Kida, T. Shimoyama, H. Ueda]
21039−1, of 1039 bits (313 digits) (though a factor of 23 bits was already known) was factored between September 2006 and May 2007 by a group including K. Aoki, J. Franke, T. Kleinjung,
A. K. Lenstra and D. A. Osvik, using computers at NTT, EPFL and theUniversity of Bonn . [cite web | url=http://listserv.nodak.edu/cgi-bin/wa.exe?A2=ind0705&L=nmbrthry&T=0&P=1019 |accessdate=2007-05-23| title=Factorization of the 1039th Mersenne number|author=K. Aoki, J. Franke, T. Kleinjung, A. K. Lenstra, D. A. Osvik] [cite web | url=http://eprint.iacr.org/2007/205 | author= Kazumaro Aoki and Jens Franke and Thorsten Kleinjung and Arjen Lenstra and Dag Arne Osvik |accessdate=2007-12-19 | title=A kilobit special number field sieve factorization]How do these compare to what can be done by individuals?
As of the end of 2007, thanks to the constant decline in memory prices, the ready availability of multi-core 64-bit computers, and the availability of the Bonn group's efficient sieving code via [http://sourceforge.net/project/showfiles.php?group_id=140917 ggnfs] and robust open-source software such as [http://www.boo.net/~jasonp/qs.html msieve] for the finishing stages, special-form numbers of up to 750 bits and general-form numbers of up to about 520 bits can be factored in a few months on a few PCs by a single person without any special mathematical experience (see [http://www.mersenneforum.org/showpost.php?p=124079&postcount=97] for a 518-bit example). These bounds would increase to about 850 and 570 if it were possible to secure the collaboration of a few dozen PCs; the limit is the amount of memory in a single machine.
References
Wikimedia Foundation. 2010.