Thanks Paul for your analysis. I have found it is also possible to do a variation on this. Let M be a small integer. Let k vary a la Pollard Rho  f(k) = ??? modulo s where s is the square root of the number to be factored. With each iteration increment M and let k_{1} = f(k_{0}) modulo s. Let H = M^{k} modulo n. Then try a_{0}^{H} modulo n.
Last fiddled with by mgb on 20070624 at 18:04
