3 ms·
> you want p and q to differ in length by a few digits Not exactly; a uniformly random (admissible) p,q pair will suffice with very high probability, but in th
by CaptainNegative 5y ago
> you want p and q to differ in length by a few digits
Not exactly; a uniformly random (admissible) p,q pair will suffice with very high probability, but in those cases p and q will likely have the same number of digits. One can avoid the bad case for Fermat's method by explicitly forcing p and q to be a couple orders of magnitude off, but the probability this helps is so low that you're only just reducing your security in aggregate: the bits of entropy you're shaving off by restricting the sample space are more impactful than the resilience gained by avoiding a (very, very) tail event.
Assuming, of course, your parameters and (P)RNG are decent. See further discussion here on the history of that recommendation https://crypto.stackexchange.com/questions/35087/should-rsa-primes-p-and-q-differ-in-length-by-a-few-digits https://crypto.stackexchange.com/questions/35087/should-rsa-... .