3 ms·
In Schneider's 1995 book he estimated factoring a 512-bit number would take roughly 30,000 MIPS-years (a one-million-instruction-per-second computer running for
by Maxious 25d ago
In Schneider's 1995 book he estimated factoring a 512-bit number would take roughly 30,000 MIPS-years (a one-million-instruction-per-second computer running for one year).
When a research team actually factored RSA-155 in August 1999, it took 8,400 MIPS-years due to efficiencies discovered. It still took 35 CPU-years spread across a cluster of 300 fast SGI/SUN workstations and Pentium II PCs (400-500 MIPS each), crunching in parallel for seven months. https://cs.ccsu.edu/~pelletie/local/risks/cryptography/Factoring-a-512-bit-number.html https://cs.ccsu.edu/~pelletie/local/risks/cryptography/Facto...
Robert Silverman, a senior research scientist at RSA Laboratories, published an analysis projecting these new hardware requirements against Moore's Law. His expectation was that within 10 years (roughly 2009–2010), common desktop machines would possess the speed and memory necessary to handle a 512-bit factorization entirely on their own. https://cr.yp.to/bib/2000/silverman.pdf https://cr.yp.to/bib/2000/silverman.pdf
- mcpherrinm 24d agoI don't know how fast my CPU cores are in MIPS, but it's 4.5 Ghz and some random googling indicates that might be about 10 MIPS per Mhz, so 45,000 Dhrystone MIPS. And assuming about ((32x32 core-hours) / 8766 (hours/year)) x 45,000 = 5256 MIPS-years. So within the order of magnitude of the 1999 factoring! Of course, the MIPS number is kinda made up, so
- rurban 24d agoOnly lunatics would do it on CPU's though. They'd use their GPU cluster, with custom SW (not yet online). RSA-1024 would cost about a week then.
- TorKlingberg 24d agoGPUs may have existed in the 90's but they were very specialized to graphics and couldn't do general purpose computation like factoring integers.