# Integer factorization

We will see three algorithms for integer factorization: the Pollard $p-1$ algorithm, the Pollard $\rho$ algorithm, and Dixon's random squares algorithm.

In [1]:
from algorithms.factorization import pollardP1, pollardRho, totalFactorization

## Pollard $p-1$ algorithm

Let us try to determine the bound $B$ needed to factor $262063$ and $9420457$.

In [5]:
pollardP1(262063, 13)

521

In [13]:
pollardP1(9420457, 47)

2351

## Pollard $\rho$ algorithm

Let us try to factor $221$ using the function $f(x) = (x^2 + 1) \bmod{221}$.

In [16]:
n = 221
f = lambda x: (x^2 + 1) % n
pollardRho(n, f, trace=True)

x = 109
f(x) = 169
gcd(x-f(x), n) = 1
f^1(x) = 169
f^3(x) = 158
gcd(f^1(x)-f^3(x), n) = 1
f^2(x) = 53
f^5(x) = 65
gcd(f^2(x)-f^5(x), n) = 1
f^3(x) = 158
f^7(x) = 67
gcd(f^3(x)-f^7(x), n) = 13


13

In [15]:
209 % 13

1

## Dixon's random squares algorithm

We will factorize $n = 15770708441$ using the random integers $14056852462$, $9004436975$, $5286195500$, $11335959904$ and $7052612564$. Let us factorize the squares of the random integers modulo $n$. We notice that they can be expressed as products of powers of the smallest seven primes.

In [17]:
n = 15770708441
r = [14056852462, 9004436975, 5286195500, 11335959904, 7052612564]
b = [2, 3, 5, 7, 11, 13, 17]
fac = [totalFactorization(x^2 % n, a=1, x=2) for x in r]
fac

[{2: 1, 3: 3, 13: 3, 17: 2},
 {3: 2, 5: 3, 7: 8},
 {2: 2, 3: 3, 7: 3, 13: 2},
 {2: 4, 5: 4, 11: 1, 17: 4},
 {3: 8, 5: 1, 11: 1, 13: 2}]

Let us gather the exponents into a matrix.

In [18]:
M = Matrix([[l.get(p, 0) for p in b] for l in fac])
M

[1 3 0 0 0 3 2]
[0 2 3 8 0 0 0]
[2 3 0 3 0 2 0]
[4 0 4 0 1 0 4]
[0 8 1 0 1 2 0]

We notice that summing the second and the last two rows gives a vector consisting entirely of even numbers.

In [19]:
rows = (1, 3, 4)
[sum(M[rows, i]) % 2 for i in range(len(b))]

[(0), (0), (0), (0), (0), (0), (0)]

We can use this to find a factor of $n$.

In [20]:
pr = prod(r[i] for i in rows) % n
pb = prod(p^e for p, (e, ) in zip(b, (sum(M[rows, i])/2 for i in range(len(b))))) % n
g = gcd(abs(pr - pb), n)
(g, n/g)

(135979, 115979)