{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T17:33:06Z","timestamp":1743096786576,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":50,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642329272"},{"type":"electronic","value":"9783642329289"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-32928-9_17","type":"book-chapter","created":{"date-parts":[[2012,8,30]],"date-time":"2012-08-30T06:38:30Z","timestamp":1346308710000},"page":"302-325","source":"Crossref","is-referenced-by-count":8,"title":["On the Strength Comparison of the ECDLP and the IFP"],"prefix":"10.1007","author":[{"given":"Masaya","family":"Yasuda","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takeshi","family":"Shimoyama","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Kogure","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tetsuya","family":"Izu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"17_CR1","unstructured":"ANSI X9.62, Public Key Cryptography for the Financial Services Industry: The Elliptic Curve Digital Signature Algorithm (ECDSA) (1999)"},{"key":"17_CR2","unstructured":"Bailey, D., Baldwin, B., Batina, L., Bernstein, D., Birkner, P., Bos, J., van Damme, G., de Meulenaer, G., Fan, J., G\u00fcneysu, T., Gurkaynak, F., Kleinjung, T., Lange, T., Mentens, N., Paar, C., Regazzoni, F., Schwabe, P., Uhsadel, L.: The Certicom Challenges ECC2-X, IACR ePrint Archive, 2009\/466 (2009), \n                      http:\/\/eprint.iacr.org\/2009\/466"},{"key":"17_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11745853_14","volume-title":"Public Key Cryptography - PKC 2006","author":"D.J. Bernstein","year":"2006","unstructured":"Bernstein, D.J.: Curve25519: New Diffie-Hellman Speed Records. In: Yung, M., Dodis, Y., Kiayias, A., Malkin, T. (eds.) PKC 2006. LNCS, vol.\u00a03958, pp. 207\u2013228. Springer, Heidelberg (2006)"},{"key":"17_CR4","unstructured":"Bernstein, D.J.: Speed Reports for Elliptic-Curve Cryptography (2010), \n                      http:\/\/cr.yp.to\/ecdh\/reports.html"},{"key":"17_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"328","DOI":"10.1007\/978-3-642-17401-8_23","volume-title":"Progress in Cryptology - INDOCRYPT 2010","author":"D.J. Bernstein","year":"2010","unstructured":"Bernstein, D.J., Chen, H.-C., Cheng, C.-M., Lange, T., Niederhagen, R., Schwabe, P., Yang, B.-Y.: ECC2K-130 on NVIDIA GPUs. In: Gong, G., Gupta, K.C. (eds.) INDOCRYPT 2010. LNCS, vol.\u00a06498, pp. 328\u2013346. Springer, Heidelberg (2010)"},{"key":"17_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1007\/978-3-642-19379-8_8","volume-title":"Public Key Cryptography \u2013 PKC 2011","author":"D.J. Bernstein","year":"2011","unstructured":"Bernstein, D.J., Lange, T., Schwabe, P.: On the Correct Use of the Negation Map in the Pollard rho Method. In: Catalano, D., Fazio, N., Gennaro, R., Nicolosi, A. (eds.) PKC 2011. LNCS, vol.\u00a06571, pp. 128\u2013146. Springer, Heidelberg (2011)"},{"key":"17_CR7","unstructured":"Breaking ECC2K-130, IACR ePrint Achive, 2009\/541, \n                      http:\/\/eprint.iacr.org\/2009\/541.pdf"},{"key":"17_CR8","doi-asserted-by":"publisher","first-page":"627","DOI":"10.1090\/S0025-5718-1981-0606520-5","volume":"36","author":"R. Brent","year":"1981","unstructured":"Brent, R., Pollard, J.: Factorization of the eighth Fermat number. Mathematics of Computation\u00a036, 627\u2013630 (1981)","journal-title":"Mathematics of Computation"},{"key":"17_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/0022-314X(83)90002-1","volume":"17","author":"E.R. Canfield","year":"1983","unstructured":"Canfield, E.R., Erdos, P., Pomerance, C.: On a problem of Oppenheim concerning Factorisatio Numerorum. J. Number Theory\u00a017, 1\u201328 (1983)","journal-title":"J. Number Theory"},{"key":"17_CR10","unstructured":"CRYPTREC, CRYPTREC Report 2006 (2006), \n                      http:\/\/www.cryptrec.go.jp\/report\/c06_wat_final.pdf"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"Blake, I., Seroussi, G., Smart, N.: Elliptic Curves in Cryptography. Cambridge University Press (1999)","DOI":"10.1017\/CBO9781107360211"},{"key":"17_CR12","unstructured":"Certicom, Certicom ECC Challenge (1997), \n                      http:\/\/www.certicom.jp\/images\/pdfs\/cert_ecc_challenge.pdf"},{"key":"17_CR13","unstructured":"Certicom, Curves List (1997), \n                      http:\/\/www.certicom.jp\/index.php\/curves-list"},{"key":"17_CR14","unstructured":"ECRYPT II, ECRYPT II Report on Key Sizes (2011), \n                      http:\/\/www.keylength.com\/en\/3\/"},{"key":"17_CR15","unstructured":"EPFL IC LACAL, PlayStation 3 computing breaks 260 barrier 112-bit prime ECDLP solved (2009), \n                      http:\/\/lacal.epfl.ch\/112bit_prime"},{"key":"17_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-642-13013-7_22","volume-title":"Public Key Cryptography \u2013 PKC 2010","author":"S.D. Galbraith","year":"2010","unstructured":"Galbraith, S.D., Ruprai, R.S.: Using Equivalence Classes to Accelerate Solving the Discrete Logarithm Problem in a Short Interval. In: Nguyen, P.Q., Pointcheval, D. (eds.) PKC 2010. LNCS, vol.\u00a06056, pp. 368\u2013383. Springer, Heidelberg (2010)"},{"key":"17_CR17","doi-asserted-by":"publisher","first-page":"1699","DOI":"10.1090\/S0025-5718-99-01119-9","volume":"69","author":"R. Gallant","year":"2000","unstructured":"Gallant, R., Lambert, R., Vanstone, S.: Improving the Parallelized Pollard Lambda Search on Binary Anomalous Curves. Mathematics of Computation\u00a069, 1699\u20131705 (2000)","journal-title":"Mathematics of Computation"},{"key":"17_CR18","doi-asserted-by":"publisher","first-page":"1498","DOI":"10.1109\/TC.2008.80","volume":"57","author":"T. G\u00fcneysu","year":"2008","unstructured":"G\u00fcneysu, T., Kasper, T., Novotn\u00fd, M., Paar, C., Rupp, A.: Cryptanalysis with COPACOBANA. Transactions on Computers\u00a057, 1498\u20131513 (2008)","journal-title":"Transactions on Computers"},{"key":"17_CR19","unstructured":"Granlund, T.: Instruction latencies and throughput for AMD and Intel x86 processors (February 13, 2012 version), \n                      http:\/\/gmplib.org\/~tege\/x86-timing.pdf"},{"key":"17_CR20","unstructured":"Hankerson, D., Menezes, A., Vanstone, S.: Guide to Elliptic Curve Cryptography. Springer Professional Computing (2004)"},{"key":"17_CR21","unstructured":"Harley, R.: Elliptic curve discrete logarithms project, \n                      http:\/\/pauillac.inria.fr\/~harley\/ecdl\/"},{"key":"17_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1007\/978-3-540-74735-2_25","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2007","author":"T. Izu","year":"2007","unstructured":"Izu, T., Kogure, J., Shimoyama, T.: CAIRN 2: An FPGA Implementation of the Sieving Step in the Number Field Sieve Method. In: Paillier, P., Verbauwhede, I. (eds.) CHES 2007. LNCS, vol.\u00a04727, pp. 364\u2013377. Springer, Heidelberg (2007)"},{"key":"17_CR23","unstructured":"Kleinjung, T.: Estimates for factoring 1024-bit integers. In: Securing Cyberspace: Applications and Foundations of Cryptography and Computer Security, Workshop IV: Special Purpose Hardware for Cryptography: Attacks and Applications, Slides (2006), \n                      http:\/\/www.ipam.ucla.edu\/schedule.aspx?pc=scws4"},{"key":"17_CR24","unstructured":"Kleinjung, T.: Evaluation of Complexity of Mathematical Algorithms. CRYPTREC technical report No.0601 in FY 2006 (2007), \n                      http:\/\/www.cryptrec.jp\/estimation.html"},{"key":"17_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"333","DOI":"10.1007\/978-3-642-14623-7_18","volume-title":"Advances in Cryptology \u2013 CRYPTO 2010","author":"T. Kleinjung","year":"2010","unstructured":"Kleinjung, T., Aoki, K., Franke, J., Lenstra, A.K., Thom\u00e9, E., Bos, J.W., Gaudry, P., Kruppa, A., Montgomery, P.L., Osvik, D.A., te Riele, H., Timofeev, A., Zimmermann, P.: Factorization of a 768-Bit RSA Modulus. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol.\u00a06223, pp. 333\u2013350. Springer, Heidelberg (2010)"},{"issue":"1","key":"17_CR26","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/s10586-010-0149-0","volume":"15","author":"T. Kleinjung","year":"2012","unstructured":"Kleinjung, T., Bos, J.W., Lenstra, A.K., Osvik, D.A., Aoki, K., Contini, S., Franke, J., Thom\u00e9, E., Jermini, P., Thi\u00e9mard, M., Leyland, P., Montgomery, P., Timofeev, A., Stockinger, H.: A heterogeneous computing environment to solve the 768-bit RSA. Cluster Computing\u00a015(1), 53\u201368 (2012)","journal-title":"Cluster Computing"},{"key":"17_CR27","volume-title":"The art of computer programming, Seminumerical Algorithms","author":"D. Knuth","year":"1969","unstructured":"Knuth, D.: The art of computer programming, Seminumerical Algorithms, vol.\u00a0II. Addison-Wesley, Reading (1969)"},{"key":"17_CR28","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1090\/S0025-5718-1987-0866109-5","volume":"48","author":"N. Koblitz","year":"1987","unstructured":"Koblitz, N.: Elliptic curve cryptosystems. Mathematics of Computation\u00a048, 203\u2013209 (1987)","journal-title":"Mathematics of Computation"},{"key":"17_CR29","doi-asserted-by":"crossref","unstructured":"Lenstra, A., Lenstra, H., Manasse, M., Pollard, J.: The Number Field Sieve. In: Symposium on Theory of Computing - STOC 1990, pp. 564\u2013572. ACM (1990)","DOI":"10.1145\/100216.100295"},{"issue":"4","key":"17_CR30","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1007\/s00145-001-0009-4","volume":"14","author":"A. Lenstra","year":"2001","unstructured":"Lenstra, A., Verheul, E.: Selecting Cryptographic Key Sizes. Journal of Cryptology\u00a014(4), 255\u2013293 (2001)","journal-title":"Journal of Cryptology"},{"key":"17_CR31","doi-asserted-by":"publisher","first-page":"1639","DOI":"10.1109\/18.259647","volume":"39","author":"A. Menezes","year":"1993","unstructured":"Menezes, A., Okamoto, T., Vanstone, S.: Reducing elliptic curve logarithms to logarithms in a finite field. IEEE Transactions on Information Theory\u00a039, 1639\u20131646 (1993)","journal-title":"IEEE Transactions on Information Theory"},{"key":"17_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"417","DOI":"10.1007\/3-540-39799-X_31","volume-title":"Advances in Cryptology","author":"V.S. Miller","year":"1986","unstructured":"Miller, V.S.: Use of Elliptic Curves in Cryptography. In: Williams, H.C. (ed.) CRYPTO 1985. LNCS, vol.\u00a0218, pp. 417\u2013426. Springer, Heidelberg (1986)"},{"key":"17_CR33","unstructured":"NESSIE, NESSIE Security Report (Feburary 2003)"},{"key":"17_CR34","unstructured":"NIST Special Publication 800-57, \n                      http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-57\/sp800-57-Part1-revised2_Mar08-2007.pdf"},{"key":"17_CR35","doi-asserted-by":"crossref","unstructured":"Orman, H., Hoffman, P.: Determining Strengths for Public Keys Used for Exchanging Symmetric Keys. IETF RFC 3766\/BCP 86 (April 2004)","DOI":"10.17487\/rfc3766"},{"key":"17_CR36","first-page":"918","volume":"32","author":"J. Pollard","year":"1978","unstructured":"Pollard, J.: Monte Carlo methods for index computation mod p. Mathematics of Computation\u00a032, 918\u2013924 (1978)","journal-title":"Mathematics of Computation"},{"key":"17_CR37","doi-asserted-by":"crossref","unstructured":"Pomerance, C.: The Number Field Sieve. In: Proceedings of Symposia in Applied Mathematics, vol.\u00a048, pp. 465\u2013480 (1994)","DOI":"10.1090\/psapm\/048\/1314884"},{"key":"17_CR38","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1145\/359340.359342","volume":"21","author":"R. Rivest","year":"1978","unstructured":"Rivest, R., Shamir, A., Adelman, L.: A method for obtaining digital signatures and public-key cyrptosystems. Communications of the ACM\u00a021, 120\u2013126 (1978)","journal-title":"Communications of the ACM"},{"key":"17_CR39","unstructured":"RSA Labs. A Cost-Based Security Analysis of Symmetric and Asymmetric Key Lengths, RSA Labs Bulletin (13) (April 2000) (revised November 2001)"},{"key":"17_CR40","first-page":"81","volume":"47","author":"T. Satoh","year":"1998","unstructured":"Satoh, T., Araki, K.: Fermat quotients and the polynomial time discrete log algorithm for anomalous elliptic curves. Commentarii Mathematici Universitatis Sancti Pauli\u00a047, 81\u201392 (1998)","journal-title":"Commentarii Mathematici Universitatis Sancti Pauli"},{"key":"17_CR41","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1090\/S0025-5718-98-00887-4","volume":"67","author":"I. Semaev","year":"1998","unstructured":"Semaev, I.: Evaluation of discrete logarithms in a group of p-torsion points of an elliptic curve in characteristic p. Mathematics of Computation\u00a067, 353\u2013356 (1998)","journal-title":"Mathematics of Computation"},{"key":"17_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/3-540-48059-5_2","volume-title":"Cryptographic Hardware and Embedded Systems","author":"A. Shamir","year":"1999","unstructured":"Shamir, A.: Factoring Large Numbers with the TWINKLE Device (Extended Abstract). In: Ko\u00e7, \u00c7.K., Paar, C. (eds.) CHES 1999. LNCS, vol.\u00a01717, pp. 2\u201312. Springer, Heidelberg (1999)"},{"key":"17_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-45146-4_1","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"A. Shamir","year":"2003","unstructured":"Shamir, A., Tromer, E.: Factoring Large Numbers with the TWIRL Device. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol.\u00a02729, pp. 1\u201326. Springer, Heidelberg (2003)"},{"key":"17_CR44","first-page":"110","volume":"12","author":"N.P. Smart","year":"1999","unstructured":"Smart, N.P.: The discrete logarithm problem on elliptic curves of trace one. Journal of Cryptology\u00a012, 110\u2013125 (1999)","journal-title":"Journal of Cryptology"},{"key":"17_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"541","DOI":"10.1007\/BFb0054891","volume-title":"Algorithmic Number Theory","author":"E. Teske","year":"1998","unstructured":"Teske, E.: Speeding Up Pollard\u2019s Rho Method for Computing Discrete Logarithms. In: Buhler, J.P. (ed.) ANTS 1998. LNCS, vol.\u00a01423, pp. 541\u2013554. Springer, Heidelberg (1998)"},{"key":"17_CR46","doi-asserted-by":"publisher","first-page":"809","DOI":"10.1090\/S0025-5718-00-01213-8","volume":"70","author":"E. Teske","year":"2001","unstructured":"Teske, E.: On random walks for Pollard\u2019s rho method. Mathematics of Computation\u00a070, 809\u2013825 (2001)","journal-title":"Mathematics of Computation"},{"key":"17_CR47","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/PL00003816","volume":"12","author":"P.C. van Oorschot","year":"1999","unstructured":"van Oorschot, P.C., Wiener, M.J.: Parallel collision search with cryptanalytic applications. Journal of Cryptology\u00a012, 1\u201328 (1999)","journal-title":"Journal of Cryptology"},{"key":"17_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/3-540-48892-8_15","volume-title":"Selected Areas in Cryptography","author":"M. Wiener","year":"1999","unstructured":"Wiener, M., Zuccherato, R.J.: Faster Attacks on Elliptic Curve Cryptosystems. In: Tavares, S., Meijer, H. (eds.) SAC 1998. LNCS, vol.\u00a01556, pp. 190\u2013200. Springer, Heidelberg (1999)"},{"issue":"2011B-3","key":"17_CR49","first-page":"107","volume":"3","author":"M. Yasuda","year":"2011","unstructured":"Yasuda, M., Izu, T., Shimoyama, T., Kogure, J.: On random walks of Pollard\u2019s rho method for the ECDLP on Koblitz curves. Journal of Math-for-Industry\u00a03(2011B-3), 107\u2013112 (2011)","journal-title":"Journal of Math-for-Industry"},{"key":"17_CR50","unstructured":"Yasuda, M., Shimoyma, T., Izu, T., Kogure, J.: On the strength comparison of ECC and RSA. In: Workshop Record of SHARCS 2012, pp. 61\u201379 (2012), \n                      http:\/\/2012.sharcs.org\/"}],"container-title":["Lecture Notes in Computer Science","Security and Cryptography for Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-32928-9_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,19]],"date-time":"2023-02-19T05:36:20Z","timestamp":1676784980000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-642-32928-9_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642329272","9783642329289"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-32928-9_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2012]]}}}