by C a r l WMERANCE*
Department of Mathematics U n i v e r s i t y of Georgia Athens, Georgia 30602 USA
The q u a d r a t i c sieve a l g o r i t h m i s c u r r e n t l y t h e method of choice t o f a c t o r very l a r g e composite numbers w i t h no small f a c t o r s . I n t h e hands of t h e Sandia N a t i o n a l Laboratories team o f James Davis and Diane Holdridge, it has held t h e r e c o r d f o r t h e l a r g e s t hard number f a c t o r e d s i n c e mid-1983. As of t h i s w r i t i n g , t h e l a r g e s t number it has cracked i s t h e 71 d i g i t number 9.5 hours on the C r a y XMP computer a t L os Alamos, New Mexico. I n t h i s paper I s h a l l g i v e some o f t h e h i s t o r y of t h i s a l g o r i t h m and a l s o d e s c r i b e some o f t h e improvements that have been
suggested f o r it.
- 1 ) / 9 , taking
KRAITCHIK'S SCHXME
There i s a l a r g e c l a s s o f f a c t o r i n g a l g o r i t h m s t h a t share a common strategy.
If N
U Z V mod N, where
algorithm) have b e e n o b t a i n e d f o r
X2 EY2 mod N. Then one s t a n d s a good chance t h a t t h e g r e a t e s t common f a c t o r (X-Y, N), found by E u c l i d ' s a l g o r i t h m , i s a n o n - t r i v i a l f a c t o r o f
then another combination o f congruences can be t r i e d . Thus t h e s e algorithms have s e v e r a l p a r t s :
i s t h e number t o b e f a c t o r e d , t h e n t h e i d e a is t o multiply congruences U #V and complete o r p a r t i a l f a c t o r i z a t i o n s (depending on t h e
U and V , so as t o produce a s p e c i a l congruence
N . If it i s n o t ,
( 1 Generation of t h e congruences U i V mod N ,
( 2 ) Determination o f t h e complete o r p a r t i a l f a c t o r i z a t i o n s of U and V f o r some of t h e congraences,
( 3 ) Determination o f a s u b s e t o f t h e f a c t o r e d congruences which can b e X2 _Y2 mod N ,
m u l t i p l i e d t o produce a s p e c i a l congruence ( 4 ) Computeticn of (X-Y, N )
* supported in p a r t by a g r a n t from t h e National Science Foundation.
T. Beth, N. Cot, and I. Ingemarsson (Eds.): Advances in Cryptology - EUROCRYPT '84, LNCS 209, pp. 169-182, 1985.
0 Springer-Verlag Berlin Heidelberg 1985
For example, s a y w e try t o f a c t o r N =91 and we n o t i c e that 81 E-10, 90 % - I , 75 z-16, and 64 Z - 2 7 . Factoring t h e s e numbers completely w e have
34 E-2-5, 2-32.5 :-I, 3-52 1-2: and 26 Z-33.
Multiplying t h e l a s t two congruences , we have
26.3.52 -24.33 ,
o r c a n c e l l i n g common f a c t o r s ,
22.52 ~ 3 2 . This g i v e s
two congruences, g e t t i n g
l o 2 :32 mod 91 and 7 = ( 10-3,91). Or we might have m u l t i p l i e d t h e first
2.36.5 22.5 ->36 5 1 , so 2T2 Z12mod 91 and 13 =(27-1,91).
This g e n e r a l scheme f o r f a c t o r i n g w a s published by Kraitchik C41 i n 1926. The numbers
t h e congruences one i s l i k e l y t o g e n e r a t e w i l l not s u c c e s s f u l l y f a c t o r i n S t e p (21, one's chances a r e enhanced i f one o f i s arranged t o be a square and t h e o t h e r has a l a r g e square f a c t o r . I n [51, pp. 26-27, Kraitchik explains how t h i s should be done. He l e t s U =x2 where x i s c a r e f u l l y chosen so that V =-N+x2 has a l a r g e f a c t o r y2. He can f o r c e y2 t o a p p e a r by choosing x as a s o l u t i o n of t h e quadra-
t i c congruence V/y2 need not be s m a l l and so e a s i l y facto-
r a b l e . This method h a s i t s problems.
U,V a r e f a c t o r e d i n t o primes except f o r squared f a c t o r s . Since most of
U,V
x2 Z B mod y2. However,
K r a i t c h i k o p p o r t u n i s t i c a l l y used o t h e r congruences U ZVmod T4 t h a t w e r e suggested by t h e s p e c i a l form o f N i n question . These congruences would n o t b e a v a i l a b l e f o r a "random"
were used t o assist i n f i n d i n g
s t r a t e g y t h a t goes back t o Fermat. I t h i n k Kraitchik preferred t h i s method f o r two reasons. F i r s t , f e w e r congruences U Z V mod N with m u l t i p l i c a t i v e information about U and V a r e used. Second, when X , Y a r e found w i t h X2-Y2 =N, one could b e a s s u r e d of a n o n - t r i v i a l f a c t o r i z a t i o n of
may produce a t r i v i a l f a c t o r i z a t i o n . L i t t l e d i d Kraitchik know that h i s l a r g e l y abandoned method of Froducing "cycles" ( t h e combination o f congruences i n s t e p ( 3 ) ) would be t h e b a s i s o f most modern f a c t o r i n g algorithms !
N. I n h i s l a t e r work c51, t h e congruences U E V mod B X and Y with X2-Y2 =N. This i s an o l d f a c t o r i n g
N, u n l i k e with t h e o t h e r method where s t e p ( 4 )
THE CONTINUED FRACTION ALGORITHM
I n s t e a d o f f i n d i n g U S V mod N with one o f U,V a square and t h e o t h e r d i v i - s i b l e by a l a r g e s q u a r e factor, a n o t h e r s t r a t e g y might be t o choose one a s q u a r e and t h e o t h e r smazz i n a b s o l u t e value. It t h u s would more l i k e l y f a c t o r i n s t e p (2).
I n 1931, Lehmer and Powers 161 suggested t h e use of tiie continued f r a c t i o n expansion o f fi t o g e n e r a t e t h e congruences U Z V mod N i n Kraitchik's scheme. This i s done by a simple r e c u r s i v e procedure t h a t c r e a t e s p a i r s 8 , An where
Q 1 A2 mod N
n n
and
f r a c t i o n expansion o f fi, b u t h i s aim w a s t o use t h e congruences ( 1 ) t o f i n d i n f o r - mation on the q u a d r a z i c c h a r a c t e r mod Q n of prime f a c t o r s p of N. Then a d i r e c t
search, such as t r i a l d i v i s i o n , could be g r e a t l y speeded up because many p o t e n t i a l d i v i s o r s would n o t have the proper c h a r a c t e r . I n c o n t r a s t , Lehmer and Powers advo- c a t e d
l Q n l <2&. An o l d method o f Legendre a l s o suggested t h e use o f t h e c o n t i n u e d
m u l t i p l y i n g several congruences of t h e form ( 1 ) t o produce congruent squares.
Morrison and B r i l l h a r t El01 were t h e f i r s t t o t r y t h e continued f r a c t i o n algo- rithm on a modern computer. I n t h e implementation they made s e v e r a l major improve- ments and refinements t h a t would be o f use i n any of t h e combination o f congruences family o f a l g o r i t h m s . F i r s t , t h e y used a ''factor base", o r all of t h e primes t o some p o i n t F, t o dermine which o f t h e congruences ( 1 ) were useful. When a congruence ( 1 w a s generated, t h e number (Ln w a s s u b j e c t e d t o trial d i v i s i o n by t h e primes p SF.
If a complete f a c t o r i z a t i o n c o u l d be obtained, t h e congruence was kept f o r l a t e r use -if not, it w a s d i s c a r d e d .
S t e p ( 3 ) of t h e a l g o r i t h m , t h e a c t u a l combination of congruences w a s e f f e c t e d by a Gaussian e l i m i n a t i o n i n a v e r y l a r g e matrix over
f a c t o r base c o n s i s t s o f t h e primes pl,...,pf, and i f
Z/2Zm S p e c i f i c a l l y , if t h e
a f a . Qn = ( - 1 ) n pi1
i = l 0
where t h e a . are non-negative i n t e g e r s , t h e n w e look a t t h e vector +. v ( n ) = ( a 0 ,a1 ,..., a,) mod 2 .
I f we have enough v e c t o r s + dependency
d n ) , t h e n Gaussian elimination w i l l produce a l i n e a r
-t -+ +
v ( n l ) +.. .+ v ( n ) = 0, k
so t h a t Qn ..* 9- i s a s q u a r e , say X2. If we compute X mod N and Y = A
o q eA mod 3, t h e n X2 3Y2 mod N and we a r e ready f o r s t e p ( 4 ) .
L I