Computation of a 768-bit prime field discrete logarithm

Thorsten Kleinjung and Claus Diem and Arjen K. Lenstra and Christine Priplata and Colin Stahlke

Abstract: This paper reports on the number field sieve computation of a 768-bit prime field discrete logarithm, describes the different parameter optimizations and resulting algorithmic changes compared to the factorization of a 768-bit RSA modulus, and briefly discusses the cryptologic relevance of the result.

Category / Keywords: public-key cryptography / Discrete logarithm, DSA, ElGamal, number field sieve

