RESULT The solution to Certicom's ECCp-97 problem is the residue class of 1 6C86AA7C ACF69F1D D28B3E2F modulo 1 6EA1595E D21AE98F B6CCA20D The calculation was carried out in 53 days by a group of 588 people and 1288 machines in more than 16 countries. It was found after 186,364 Distinguished Points. At an expected 2^30 iterations per Point, we estimate it took 200 trillion (200 E12)iterations. We sustained an average rate of 5 trillion (5 E12) iterations per day, for the past two weeks. We achieved 440K 97bit Elliptic Curve iterations per second on an Alpha 600MHz or 494K on an Alpha 400MHz 21264 prototype. We got 125K iterations/sec from a Pentium II 300 and 39K iterations/sec from a PowerPC 604/120. The method we used was a "birthday paradox" algorithm iterating from random initial points (distributed over all machines) with a pseudo-random function (the same on all machines) until a collision was detected at 23:38 GMT on Monday 16th of March 1998. The two Points were coincidentally both found by Greg Thomas of BT on two different AlphaServer 8200s, each with four 440MHz 21164A Alpha CPUs. This effort was organised by the BT Labs team, led by Adrian Escott, John Sager, Alex Selkirk & Dimitris Tsapakidis and by the Linux Alpha group, led by Robert Harley at INRIA. Our proposed prize distribution is indicated on our web page at http://www.labs.bt.com/projects/security/crackers/p97/ If we have won the prize, then we will discuss the mechanics of this separately. CREDITS Robert Harley(INRIA): Original 64bit Alpha code & client, p97 code optimisation, user support, ECC background. John Sager(BT Labs): 64bit Alpha code conversion to p97, Pentium assembler, VMS & 32bit Unix clients, proxies, ECC background. Adrian Escott(BT Labs): ECC background, 64->32bit core code conversion. Alex Selkirk(BT Labs): Windows clients, keyserver. Dimitris Tsapakidis(BT Labs): Live stats & user support. Dave Parkinson(BT Labs): Pentium assembler. Jake Hill(BT Labs): Mac client & PowerPC assembler. CONTRIBUTORS 222 Alpha machines produced 103,000 Points or 55.3%, 753 Pentium machines produced 73,691 Points or 39.5% the rest were produced by Sparcs, Macs, HPs and others. The groups & people involved follow. Figures denote Points found and total contribution. BT Labs 131163, 70.38% [484 email addresses] digital 14794, 7.94% simons@zk3.dec.com gorton@amt.tay1.dec.com schloss@zk3.dec.com reeves@zk3.dec.com frank@zk3.dec.com gorton@400mhz_proto@amt.tay1.dec.com inria 14472, 7.77% robert.harley@inria.fr guillaume.pierre@inria.fr legion project 4961, 2.66% lindahl@cs.virginia.edu tu wien 3153, 1.69% andi@complang.tuwien.ac.at nino@complang.tuwien.ac.at university of tromsoe 2308, 1.24% frodef@acm.org tobias@td.org.uit.no alvin.brattli@phys.uit.no duke university - demographics 2032, 1.09% ggw@cds.duke.edu barbarian brothers 1065, 0.57% gorton@thetick.antix.com csmith 1006, 0.54% csmith@stoneboro.uucp.cirr.com lut 920, 0.49% bande@lut.fi alcar group 839, 0.45% edlee@chinet.chinet.com digital unix internet security 712, 0.38% spider@leggy.zk3.dec.com hist institutt for databehandling 703, 0.38% einarfd@tihlde.hist.no vuw:school of earth sciences 699, 0.38% bill@geo.vuw.ac.nz de boulevard 691, 0.37% bjv@de-boulevard.nl robijn@robijn.de-boulevard.nl stf at large 642, 0.34% spock@abraxas.adelphi.edu pitney bowes 585, 0.31% romansbr@pb.com lessing research 542, 0.29% leonl@icon.co.za olive@ilink.nis.za rui@ilink.nis.za bucknell university 496, 0.27% jwilkins@bucknell.edu systems@bucknell.edu weber@bucknell.edu penn state university 457, 0.25% duvernoi@psu.edu daydreamers 341, 0.18% christopher.endsley@interimtechnology.com sunquest information systems 338, 0.18% terry@venus.sunquest.com digital equipment corporation 324, 0.17% woodburn@zk3.dec.com gelinas@zk3.dec.com center for water research 310, 0.17% dichro-ecdl@eris.rcpt.to centrale_lille 221, 0.12% mainaud@ec-lille.fr masson@ec-lille.fr girolami@ec-lille.fr lenzotti@ec-lille.fr vanhouv9@cti.ecp.fr je@eclia5.ec-lille.fr rezoleo@eclia5.ec-lille.fr gallico@ec-lille.fr cornet@ec-lille.fr solnet 191, 0.10% fli@trekkers.org fli@solnet.sollentuna.se unb 187, 0.10% jeffg@nbnet.nb.ca danimal 167, 0.09% danimal@pobox.com rupture dot net 157, 0.08% jon@blading.com fermi national accelerator lab 150, 0.08% baisley@fnal.gov none 148, 0.08% sysadmin@wolf.hip.berkely.edu gevaryah@netaxs.com wieger@dublin.student.utwente.nl sysadmin@wolf.hip.berkeley.edu ethz informatik 142, 0.08% mihailes@inf.ethz.ch the obfuscation organization 120, 0.06% techs@obfuscation.org jaap 115, 0.06% schj@anna.xs4all.nl digital equipment corporation, unix support engineering group 108, 0.06% gentry@zk3.dec.com gaillon 98, 0.05% a1504d@micronet.fr art - futures testbed 83, 0.04% margarida max-planck institute for plasma physics 79, 0.04% dpc@ipp.mpg.de damicon kraa ltd. 74, 0.04% msiren@damicon.fi le free french 70, 0.04% charles@degaulle.com home 58, 0.03% metal@ton.tut.fi dso 53, 0.03% lhiankia@dso.org.sg caos/camm center 52, 0.03% verwer@caos.kun.nl macintosh 52, 0.03% lcollie@compuserve.com j-beda@pobox.com doolittl@uiuc.edu bluequark2@aol.com mattkime@usa.net seth@snet.net freeth's 50, 0.03% k.brincat@rhbnc.ac.uk aa-tech 47, 0.03% antinoja@netlife.fi duchy of wabesylvan obspauk 47, 0.03% spider@orb.nashua.nh.us systems test engineering 38, 0.02% dawson@nio.dec.com harijs 35, 0.02% harijs@parks.lv partner communications 31, 0.02% pete@partnercomm.com team incompetent 30, 0.02% dontknowman@incompetent.to noleadership@incompetent.to loser@incompetent.to ringzero systems 28, 0.02% arc@cts.com plalone@alphax.com renaissance internet services 26, 0.01% cadams@ro.com uninet 24, 0.01% barryn@pobox.com oxfrod 23, 0.01% mert0236@sable.ox.ac.uk fbs2 17, 0.01% email glen mcbride 13, 0.01% gmcbride@baynetworks.com pent 12, 0.01% alnick@mail.wplus.net delta-net 12, 0.01% daniel@delta-net.com patanjali 11, 0.01% patanjali@prodigy.net neural.net 9, 0.00% mdschmoeckel@stthomas.edu crank 6, 0.00% jdonner@erols.com tu graz 6, 0.00% harry@igi.tu-graz.ac.at spunkmunky 5, 0.00% tiensivu@pilot.msu.edu slap_yo 4, 0.00% lacuran sas 4, 0.00% sas@minofdefence.demon.co.uk ecc@computerx.com 3, 0.00% ecc@computerx.com #macwarez 2, 0.00% goffy@2-cool.com jobtrak 2, 0.00% schatt@jobtrak.com al's group 1, 0.00% livalan@tig.com.au Our source code can be downloaded from: http://pauillac.inria.fr/~harley/ecdl4/ The main project page with more info and stats is at: http://www.labs.bt.com/projects/security/crackers/p97/ We invite anyone interested in working on the next calculation to point their Web browsers at: http://pauillac.inria.fr/~harley/ecdl5/