Refined Analysis of the Asymptotic Complexity of the Number Field Sieve
Aude Le Gluher, Pierre-Jean Spaenlehauer, Emmanuel Thom\'e

TL;DR
This paper refines the asymptotic complexity analysis of the Number Field Sieve by precisely estimating the slow convergence of the heuristic function involved, questioning the practical relevance of existing complexity estimates.
Contribution
It provides exact asymptotic estimates for the parameters of NFS, revealing the slow convergence of the heuristic function and challenging previous complexity assumptions.
Findings
The heuristic function $\xi(N)$ converges very slowly, approximately as $4 ext{log} ext{log} ext{log} hinspace N / (3 ext{log} ext{log} hinspace N)$.
Practical estimates of NFS complexity are unreliable due to the slow convergence of $\xi(N)$.
Asymptotic series expansion of $\xi(N)$ indicates convergence only for extremely large N, beyond practical ranges.
Abstract
The classical heuristic complexity of the Number Field Sieve (NFS) is the solution of an optimization problem that involves an unknown function, usually noted and called throughout this paper, which tends to zero as the entry grows. The aim of this paper is to find optimal asymptotic choices of the parameters of NFS as grows, in order to minimize its heuristic asymptotic computational cost. This amounts to minimizing a function of the parameters of NFS bound together by a non-linear constraint. We provide precise asymptotic estimates of the minimizers of this optimization problem, which yield refined formulas for the asymptotic complexity of NFS. One of the main outcomes of this analysis is that has a very slow rate of convergence: We prove that it is equivalent to . Moreover, has an unpredictable…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Residue Arithmetic · Coding theory and cryptography · Cryptography and Data Security
