Algorithm For Ensuring p & q Sufficiently Large For n in RSA



Hi All,

What are the prevaling recommendations for choosing p, q, such that
the product is indeed, say, 512 bits, for a 512-bit modulus.

There are things that can be done to the bit-pattern of p and q during
randomization phase obviously, and I recall a while back in Coutinho's
there was a recommendation, but I wanted to explore more.

TIA,

-Le Chaud Lapin-
.