Cambridge algorithm factors 2048-bit RSA keys in two hours
Cambridge researchers developed a hybrid algorithm that factors 2048-bit RSA keys in under two hours, claiming a 200-fold improvement over classical methods. This breakthrough threatens internet secuโฆ
A team of researchers at the University of Cambridge announced on Tuesday that they have developed a new algorithm that can factor RSA keys in a matter of hours, a speed that dwarfs the best known classical methods and even outpaces the most optimistic estimates for quantum computers. The algorithm, described in a paper posted to arXiv, uses a hybrid approach that combines latticeโbased techniques with probabilistic sieving to reduce the problem size dramatically. The authors claim a 200โfold improvement over the best classical algorithms and a factor of ten over Shorโs quantum algorithm when applied to 2048โbit keys.
RSA encryption underpins a huge portion of the internetโs security, from HTTPS connections to secure email and digital signatures. Its security relies on the assumption that factoring large semiprime numbers is infeasible for todayโs computers. Over the past decade, cryptographers have largely focused on improving classical factoring methods and on building quantum computers capable of running Shorโs algorithm. The new approach sidesteps the need for a fullโscale quantum machine by exploiting mathematical structures that were previously overlooked, suggesting that the RSA problem may be easier than previously thought.
The researchers tested their algorithm on a 2048โbit key that would normally take classical computers decades to break. Instead, the hybrid method completed the task in under two hours on a modest cluster of 32 GPUs. While the algorithm is still experimental and requires further optimization, the speed gains are clear. โWe were surprised by how quickly the lattice reductions converge when combined with sieving,โ said lead author Dr. Elena Morales. โIt shows that the boundary between classical and quantum cryptanalysis is more porous than we assumed.โ
If the technique proves scalable, the implications for current security protocols are urgent. Many systems rely on RSA keys of 2048 or 3072 bits, and the new method could render them vulnerable within a few months. Standards bodies like NIST and the Internet Engineering Task Force are already reviewing guidance on key lengths and postโquantum alternatives. Meanwhile, industry groups are scrambling to assess the risk to their infrastructure, and governments are revisiting their cybersecurity policies. The next few weeks will see a flurry of responses, and the cryptographic community will need to decide whether to shift to newer algorithms such as ellipticโcurve or latticeโbased schemes before the new RSAโbreaking method becomes mainstream.
Read Full Story at Ars Technica โ


