{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T16:16:46Z","timestamp":1778948206492,"version":"3.51.4"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030568795","type":"print"},{"value":"9783030568801","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-56880-1_3","type":"book-chapter","created":{"date-parts":[[2020,8,12]],"date-time":"2020-08-12T15:04:50Z","timestamp":1597244690000},"page":"62-91","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":50,"title":["Comparing the Difficulty of Factorization and Discrete Logarithm: A 240-Digit Experiment"],"prefix":"10.1007","author":[{"given":"Fabrice","family":"Boudot","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pierrick","family":"Gaudry","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0824-7273","authenticated-orcid":false,"given":"Aurore","family":"Guillevic","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nadia","family":"Heninger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emmanuel","family":"Thom\u00e9","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0718-4458","authenticated-orcid":false,"given":"Paul","family":"Zimmermann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,8,10]]},"reference":[{"issue":"1","key":"3_CR1","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1145\/3292035","volume":"62","author":"D Adrian","year":"2018","unstructured":"Adrian, D., et al.: Imperfect forward secrecy: How Diffie-Hellman fails in practice. Commun. ACM 62(1), 106\u2013114 (2018). https:\/\/doi.org\/10.1145\/3292035","journal-title":"Commun. ACM"},{"key":"3_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-76900-2_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2007","author":"K Aoki","year":"2007","unstructured":"Aoki, K., Franke, J., Kleinjung, T., Lenstra, A.K., Osvik, D.A.: A kilobit special Number Field Sieve factorization. In: Kurosawa, K. (ed.) ASIACRYPT 2007. LNCS, vol. 4833, pp. 1\u201312. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-76900-2_1"},{"issue":"298","key":"3_CR3","doi-asserted-by":"publisher","first-page":"861","DOI":"10.1090\/mcom3048","volume":"85","author":"S Bai","year":"2016","unstructured":"Bai, S., Bouvier, C., Kruppa, A., Zimmermann, P.: Better polynomials for GNFS. Math. Comput. 85(298), 861\u2013873 (2016). https:\/\/doi.org\/10.1090\/mcom3048","journal-title":"Math. Comput."},{"key":"3_CR4","unstructured":"Barbulescu, R.: Algorithmes de logarithmes discrets dans les corps finis. th\u00e8se de doctorat, Universit\u00e9 de Lorraine, France (2013). https:\/\/tel.archives-ouvertes.fr\/tel-00925228"},{"issue":"3","key":"3_CR5","doi-asserted-by":"publisher","first-page":"804","DOI":"10.1137\/S0895479892230031","volume":"15","author":"B Beckerman","year":"1994","unstructured":"Beckerman, B., Labahn, G.: A uniform approach for the fast computation of matrix-type Pad\u00e9 approximants. SIAM J. Matrix Anal. Appl. 15(3), 804\u2013823 (1994). https:\/\/doi.org\/10.1137\/S0895479892230031","journal-title":"SIAM J. Matrix Anal. Appl."},{"key":"3_CR6","unstructured":"Bernstein, D.J.: How to find small factors of integers (2002). http:\/\/cr.yp.to\/papers.html#sf"},{"key":"3_CR7","unstructured":"Boudot, F.: On improving integer factorization and discrete logarithm computation using partial triangulation. Cryptology ePrint Archive, Report 2017\/758 (2017). https:\/\/eprint.iacr.org\/2017\/758"},{"key":"3_CR8","unstructured":"Bouillaguet, C., Zimmermann, P.: Parallel structured Gaussian elimination for the Number Field Sieve (2019). https:\/\/hal.inria.fr\/hal-02098114, preprint"},{"key":"3_CR9","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"483","DOI":"10.1007\/978-3-030-45388-6_17","volume-title":"PKC 2020, Part II","author":"C Bouvier","year":"2020","unstructured":"Bouvier, C., Imbert, L.: Faster cofactorization with ECM using mixed representations. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC 2020, Part II. LNCS, vol. 12111, pp. 483\u2013504. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45388-6_17"},{"key":"3_CR10","doi-asserted-by":"publisher","unstructured":"Buhler, J.P., Lenstra, H.W., Pomerance, C.: Factoring integers with the Number Field Sieve. In: Lenstra, Lenstra, Jr. [30], pp. 50\u201394. https:\/\/doi.org\/10.1007\/BFb0091534","DOI":"10.1007\/BFb0091534"},{"key":"3_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/10722028_11","volume-title":"Algorithmic Number Theory","author":"S Cavallar","year":"2000","unstructured":"Cavallar, S.: Strategies in filtering in the Number Field Sieve. In: Bosma, W. (ed.) ANTS 2000. LNCS, vol. 1838, pp. 209\u2013231. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/10722028_11"},{"key":"3_CR12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-02945-9","volume-title":"Graduate Texts in Mathematics","author":"H Cohen","year":"1993","unstructured":"Cohen, H.: A course in computational algebraic number theory. In: Axler, S., Ribet, K. (eds.) Graduate Texts in Mathematics, vol. 138. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/978-3-662-02945-9"},{"issue":"205","key":"3_CR13","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1090\/S0025-5718-1994-1192970-7","volume":"62","author":"D Coppersmith","year":"1994","unstructured":"Coppersmith, D.: Solving linear equations over $$\\rm GF(2)$$ via block Wiedemann algorithm. Math. Comput. 62(205), 333\u2013350 (1994). https:\/\/doi.org\/10.1090\/S0025-5718-1994-1192970-7","journal-title":"Math. Comput."},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"David, N., Zimmermann, P.: A new ranking function for polynomial selection in the Number Field Sieve. Contemporary Mathematics (to appear) (2019). https:\/\/hal.inria.fr\/hal-02151093","DOI":"10.1090\/conm\/754\/15139"},{"key":"3_CR15","first-page":"103","volume-title":"CRYPTO\u201983","author":"JA Davis","year":"1983","unstructured":"Davis, J.A., Holdridge, D.B.: Factorization using the quadratic sieve algorithm. In: Chaum, D. (ed.) CRYPTO\u201983, pp. 103\u2013113. Plenum Press, New York (1983)"},{"key":"3_CR16","doi-asserted-by":"publisher","unstructured":"Dumas, J., Kaltofen, E., Thom\u00e9, E., Villard, G.: Linear time interactive certificates for the minimal polynomial and the determinant of a sparse matrix. In: Abramov, S.A., Zima, E.V., Gao, X. (eds.) ISSAC 2016, pp. 199\u2013206. ACM (2016). https:\/\/doi.org\/10.1145\/2930889.2930908","DOI":"10.1145\/2930889.2930908"},{"key":"3_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"202","DOI":"10.1007\/978-3-319-56620-7_8","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"J Fried","year":"2017","unstructured":"Fried, J., Gaudry, P., Heninger, N., Thom\u00e9, E.: A kilobit hidden SNFS discrete logarithm computation. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017, Part I. LNCS, vol. 10210, pp. 202\u2013231. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56620-7_8"},{"key":"3_CR18","doi-asserted-by":"publisher","unstructured":"Giorgi, P., Lebreton, R.: Online order basis algorithm and its impact on the block Wiedemann algorithm. In: Nabeshima, K., Nagasaka, K., Winkler, F., Sz\u00e1nt\u00f3, \u00c1. (eds.) ISSAC 2014, pp. 202\u2013209. ACM (2014). https:\/\/doi.org\/10.1145\/2608628.2608647","DOI":"10.1145\/2608628.2608647"},{"key":"3_CR19","unstructured":"Granlund, T.: the GMP development team: GNU MP: The GNU Multiple Precision Arithmetic Library, version 6.1.2 (2016). http:\/\/gmplib.org\/"},{"issue":"6","key":"3_CR20","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1007\/s00200-003-0144-2","volume":"14","author":"G Hanrot","year":"2004","unstructured":"Hanrot, G., Quercia, M., Zimmermann, P.: The middle product algorithm I. AAECC 14(6), 415\u2013438 (2004). https:\/\/doi.org\/10.1007\/s00200-003-0144-2","journal-title":"AAECC"},{"key":"3_CR21","unstructured":"ICSI certificate notary (2019). https:\/\/notary.icsi.berkeley.edu\/"},{"issue":"242","key":"3_CR22","doi-asserted-by":"publisher","first-page":"953","DOI":"10.1090\/S0025-5718-02-01482-5","volume":"72","author":"A Joux","year":"2003","unstructured":"Joux, A., Lercier, R.: Improvements to the general Number Field Sieve for discrete logarithms in prime fields: a comparison with the Gaussian integer method. Math. Comput. 72(242), 953\u2013967 (2003). https:\/\/doi.org\/10.1090\/S0025-5718-02-01482-5","journal-title":"Math. Comput."},{"issue":"210","key":"3_CR23","doi-asserted-by":"publisher","first-page":"777","DOI":"10.1090\/S0025-5718-1995-1270621-1","volume":"64","author":"E Kaltofen","year":"1995","unstructured":"Kaltofen, E.: Analysis of Coppersmith\u2019s block Wiedemann algorithm for the parallel solution of sparse linear systems. Math. Comput. 64(210), 777\u2013806 (1995). https:\/\/doi.org\/10.1090\/S0025-5718-1995-1270621-1","journal-title":"Math. Comput."},{"key":"3_CR24","unstructured":"Kleinjung, T.: Cofactorisation strategies for the Number Field Sieve and an estimate for the sieving step for factoring $$1024$$-bit integers. In: Proceedings of SHARCS 2006 (2006). http:\/\/www.hyperelliptic.org\/tanja\/SHARCS\/slides06.html"},{"issue":"256","key":"3_CR25","doi-asserted-by":"publisher","first-page":"2037","DOI":"10.1090\/S0025-5718-06-01870-9","volume":"75","author":"T Kleinjung","year":"2006","unstructured":"Kleinjung, T.: On polynomial selection for the general Number Field Sieve. Math. Comput. 75(256), 2037\u20132047 (2006). https:\/\/doi.org\/10.1090\/S0025-5718-06-01870-9","journal-title":"Math. Comput."},{"key":"3_CR26","unstructured":"Kleinjung, T.: Polynomial selection. Slides presented at the CADO workshop on integer factorization (2008). http:\/\/cado.gforge.inria.fr\/workshop\/abstracts.html"},{"key":"3_CR27","doi-asserted-by":"publisher","unstructured":"Kleinjung, T., et al.: Factorization of a 768-bit RSA modulus. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol. 6223, pp. 333\u2013350. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14623-7_18","DOI":"10.1007\/978-3-642-14623-7_18"},{"key":"3_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"358","DOI":"10.1007\/978-3-662-45611-8_19","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2014","author":"T Kleinjung","year":"2014","unstructured":"Kleinjung, T., Bos, J.W., Lenstra, A.K.: Mersenne factorization factory. In: Sarkar, P., Iwata, T. (eds.) ASIACRYPT 2014. LNCS, vol. 8873, pp. 358\u2013377. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-45611-8_19"},{"key":"3_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-319-56620-7_7","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"T Kleinjung","year":"2017","unstructured":"Kleinjung, T., Diem, C., Lenstra, A.K., Priplata, C., Stahlke, C.: Computation of a 768-bit prime field discrete logarithm. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10210, pp. 185\u2013201. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56620-7_7"},{"key":"3_CR30","series-title":"Lecture Notes in Mathematics","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0091534","volume-title":"The Development of the Number Field Sieve","year":"1993","unstructured":"Lenstra, A.K., Lenstra Jr., H.W. (eds.): The Development of the Number Field Sieve. LNM, vol. 1554. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/BFb0091534"},{"key":"3_CR31","doi-asserted-by":"crossref","unstructured":"Montgomery, P.L.: Square roots of products of algebraic numbers. In: Gautschi, W. (ed.) Mathematics of Computation 1943\u20131993: a Half-Century of Computational Mathematics. Proceedings Symposium Applied Mathematics, vol. 48, p. 567\u2013571. American Mathematical Soc. Providence (1994). Complemented by two later unpublished drafts in 1995 and 1997","DOI":"10.1090\/psapm\/048\/1314892"},{"key":"3_CR32","unstructured":"Murphy, B.A.: Polynomial selection for the Number Field Sieve integer factorisation algorithm. Ph.D. thesis, Australian National University (1999). http:\/\/maths-people.anu.edu.au\/~brent\/pd\/Murphy-thesis.pdf"},{"key":"3_CR33","unstructured":"National Security Agency: Commercial national security algorithm suite (2015). https:\/\/apps.nsa.gov\/iaarchive\/programs\/iad-initiatives\/cnsa-suite.cfm"},{"key":"3_CR34","series-title":"Lecture Notes in Mathematics","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1007\/BFb0091538","volume-title":"The development of the Number Field Sieve","author":"JM Pollard","year":"1993","unstructured":"Pollard, J.M.: The lattice sieve. In: Lenstra, A.K., Lenstra, H.W. (eds.) The development of the Number Field Sieve. LNM, vol. 1554, pp. 43\u201349. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/BFb0091538"},{"issue":"1676","key":"3_CR35","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1098\/rsta.1993.0139","volume":"345","author":"O Schirokauer","year":"1993","unstructured":"Schirokauer, O.: Discrete logarithms and local units. Philos. Trans. Roy. Soc. London Ser. A 345(1676), 409\u2013423 (1993). https:\/\/doi.org\/10.1098\/rsta.1993.0139","journal-title":"Philos. Trans. Roy. Soc. London Ser. A"},{"key":"3_CR36","unstructured":"The CADO-NFS Development Team: CADO-NFS, an implementation of the Number Field Sieve algorithm (2019). http:\/\/cado-nfs.gforge.inria.fr\/. Development version"},{"issue":"5","key":"3_CR37","doi-asserted-by":"publisher","first-page":"757","DOI":"10.1006\/jsco.2002.0533","volume":"33","author":"E Thom\u00e9","year":"2002","unstructured":"Thom\u00e9, E.: Subquadratic computation of vector generating polynomials and improvement of the block Wiedemann algorithm. J. Symb. Comput. 33(5), 757\u2013775 (2002). https:\/\/doi.org\/10.1006\/jsco.2002.0533","journal-title":"J. Symb. Comput."},{"key":"3_CR38","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1007\/978-3-642-31662-3_15","volume-title":"WAIFI 2012","author":"E Thom\u00e9","year":"2012","unstructured":"Thom\u00e9, E.: Square root algorithms for the Number Field Sieve. In: \u00d6zbudak, F., Rodr\u00edguez-Henr\u00edquez, F. (eds.) WAIFI 2012. LNCS, vol. 7369, pp. 208\u2013224. Springer, Cham (2012). https:\/\/doi.org\/10.1007\/978-3-642-31662-3_15"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2020"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-56880-1_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,12]],"date-time":"2023-08-12T00:06:26Z","timestamp":1691798786000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-56880-1_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030568795","9783030568801"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-56880-1_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"10 August 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 August 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"40","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2020\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"371","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"85","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"23% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.82","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19.43","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}