In this article we offer guidelines for the determination of key sizes for symmetric cryptosystems, RSA, and discrete logarithm based cryptosystems both over finite fields and over groups of elliptic curves over prime fields. Our recommendations are based on a set of explicitly formulated hypotheses, combined with existing data points about the cryptosystems.
|
434
|
Algorithms for quantum computation: discrete log and factoring
– Shor
- 1994
|
|
227
|
Why cryptosystems fail
– Anderson
- 1994
|
|
158
|
A One Round Protocol for Tripartite Diffie-Hellman
– Joux
- 2000
|
|
146
|
Lower Bounds for Discrete Logarithms and Related Problems
– Shoup
- 1997
|
|
95
|
Parallel collision search with cryptanalytic applications, J. Cryptology 12
– Oorschot, Wiener
- 1999
|
|
75
|
Minimal Key Lengths for Symmetric Ciphers to Provide Adequate Commercial Security” in www.counterpane. com/keylength.html
– Blaze, Diffie, et al.
- 1996
|
|
66
|
The XTR Public Key System
– Lenstra, Verheul
|
|
55
|
Separating decision Diffie-Hellman from Diffie-Hellman in cryptographic groups
– Joux, Nguyen
|
|
54
|
Evidence that xtr is more secure than supersingular elliptic curve cryptosystems
– Verheul
- 2004
|
|
53
|
Complexity of a determinate algorithm for the discree logarithm
– Nechaev
- 1974
|
|
43
|
Faster attacks on elliptic curve cryptosystems
– Wiener, Zuccherato
- 1998
|
|
41
|
Improving the parallelized Pollard lambda search on binary anomalous curves
– Gallant, Lambert, et al.
|
|
41
|
A Fast New DES Implementation in Software
– Biham
|
|
40
|
Performance Comparison of Public-Key Cryptosystems
– Wiener
- 1998
|
|
39
|
A one round protocol for tripartite Die-Hellman
– Joux
- 2000
|
|
30
|
The future of integer factorization
– Odlyzko
- 1995
|
|
29
|
A cost-based security analysis of symmetric and asymmetric key lengths
– Silverman
|
|
27
|
Exhaustive cryptanalysis of the NBS
– Diffie, Hellman
- 1977
|
|
24
|
A Fast New DES Implementation
– Biham
- 1997
|
|
23
|
Separating Decision Die-Hellman from Die-Hellman in cryptographic groups. Cryptology ePrint Archive, Report 2001/003
– Joux, Nguyen
- 2001
|
|
14
|
Factoring integers using SIMD sieves
– Dixon, Lenstra
- 1994
|
|
14
|
RSA for Paranoids
– Shamir
- 1995
|
|
13
|
te Riele, et al., Factorization of a 512-bit RSA modulus
– Cavallar, Dodson, et al.
- 2000
|
|
11
|
Analysis and Optimization of the TWINKLE Factoring Device
– Lenstra, Shamir
- 2000
|
|
6
|
personal communication
– Kocher
- 1998
|
|
5
|
Efficient hardware and software
– Davio, Desmedt, et al.
- 1984
|
|
5
|
Efficient DES key search, manuscript
– Wiener
- 1993
|
|
5
|
personal communication
– Zimmermann
- 1999
|
|
4
|
Breaking DES, RSA Laboratories’ Cryptobytes, v
– Kocher
- 1999
|
|
4
|
Faster Hashing on the Pentium,” Rump Session of Eurocrypt ’97
– Bosselaers, “Even
- 1997
|
|
3
|
Even faster hashing on the Pentium, manuscript, Katholieke Universiteit
– Bosselaers
- 1997
|
|
3
|
Possible NSA decryption capabilities, http://jya.com/nsa-study.htm
– Brazier
|
|
3
|
personal communication
– Gallant
- 1999
|
|
3
|
personal communication
– Menezes
- 1999
|
|
3
|
letter to the editor
– Montgomery
- 1999
|
|
3
|
rump session presentation at Crypto’97
– Silverman
|
|
3
|
Exposing the Mythical MIPS
– Silverman
- 1999
|
|
2
|
Future Resiliency and High Security Systems
– Johnson, ECC
- 1999
|
|
2
|
personal communication
– Leyland
- 1999
|
|
2
|
Factoring integers using the TWINKLE device, manuscript
– Shamir
- 1999
|
|
2
|
Faster attakcs on elliptic curve cryptosystems
– Wiener, Zuccherato
- 1999
|
|
2
|
TWINKLE and the number field sieve, manuscript in preparation
– Lenstra, Shamir
- 1999
|
|
2
|
Possible NSA decryption capabilities, jya.com/nsa-study.htm
– Brazier
|
|
2
|
Exposing the Mythical Mips-Year
– Silverman
- 1999
|
|
2
|
The future of integer factorization, RSA Laboratories
– Odlyzko
- 1995
|
|
1
|
Analysis and optimization of the TWINKLE factoring device, manuscript
– Lenstra, Shamir
- 1999
|
|
1
|
te Riele, Factorization of a 512-bit RSA key using the number field sieve, manuscript
– Cavallar, Dodson, et al.
|
|
1
|
Java applet on www.cryptosavvy.com
– Puolamäki
|
|
1
|
Factoring integers using the TWINKLE device
– Shamir
- 1999
|
|
1
|
Singh’s cipher challenge, www.simonsingh.com/cipher.htm
– Simon
|