3 ms·
> if it's not embarrassingly parallelizable, first, tell me why It's a cryptographic assumption that repeated squaring in an RSA group is "inherently sequentia
by justindrake 7y ago
> if it's not embarrassingly parallelizable, first, tell me why
It's a cryptographic assumption that repeated squaring in an RSA group is "inherently sequential". This assumption was first made in 1996 by Rivest, Shamir and Wagner for timelock puzzles. See https://people.csail.mit.edu/rivest/pubs/RSW96.pdf https://people.csail.mit.edu/rivest/pubs/RSW96.pdf
> what's all this business about optimizing the algorithm
To link sequential computation with physical time we need the general public to evaluate the VDF at roughly the same speed as an attacker. By "roughly the same speed" we mean that the attacker (even with a huge budget) cannot build hardware that runs, say, 10x or 100x faster than a publicly available ASIC.