Lenstra elliptic-curve factorization: Difference between revisions

Content deleted Content added
Fgrieu (talk | contribs)
Lenstra's elliptic-curve factorization: Fix parenthesis and brackets in the formula
Line 122:
 
==Quantum version (GEECM)==
Bernstein, Heninger, Lou, & Valenta<ref>Bernstein D.J., [[Nadia Heninger|Heninger N.]], Lou P., Valenta L. (2017) [https://eprint.iacr.org/2017/351 Post-quantum RSA]. In: Lange T., Takagi T. (eds), ''Post-Quantum Cryptography''. PQCrypto 2017. Lecture Notes in Computer Science, vol 10346. Springer, Cham</ref> suggest GEECM, a quantum version of ECM with Edwards curves. It uses [[Grover's algorithm]] to roughly double the size of the primes found compared to standard EECM, assuming a quantum computer with sufficiently many qubits and of comparable speed to the classical computer running EECM.
 
==See also==