Logo image
Cryptanalysis of exhaustive search on attacking RSA
Conference paper   Peer reviewed

Cryptanalysis of exhaustive search on attacking RSA

Mu-En Wu, Raylin Tso and Hung-Min Sun
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), Vol.7645 LNCS, pp.373-379
2012

Abstract

lattice basis reduction LLL algorithm partial key exposure (PKE) attack RSA
In RSA equation: ed = k·φ(N) + 1, we may guess on partial bits of d or p + q by doing an exhaustive search to further extend the security boundary of d. In this paper, we discuss the following question: Does guessing on p + q bring more benefit than guessing on d? We provide the detailed analysis on this problem by using the lattice reduction technique. Our analysis shows that leaking partial most significant bits (MSBs) of p + q in RSA risks more than leaking partial MSBs of d. This result inspires us to further extend the boundary of the Boneh-Durfee attack to N <sup>0.284+Δ</sup> , where "Δ" is contributed by the capability of exhaustive search. Assume that doing an exhaustive search for 64 bits is feasible in the current computational environment, the boundary of the Boneh-Durfee attack should be raised to d < N <sup>0.328</sup> for an 1024-bit RSA modulus. This is a 37 bits improvement over Boneh and Durfee's boundary. © 2012 Springer-Verlag.

Metrics

1 Record Views

Details

Logo image