Logo image
Cryptanalysis of short exponent RSA with primes sharing least significant bits
Conference paper   Peer reviewed

Cryptanalysis of short exponent RSA with primes sharing least significant bits

Hung-Min Sun, Mu-En Wu, Ron Steinfeld, Jian Guo and Huaxiong Wang
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), Vol.5339 LNCS, pp.49-63
2008

Abstract

Least significant bits (LSBs) LSBS-RSA Lttice reduction technique RSA Short exponent attack The boneh-durfee attack
LSBS-RSA denotes an RSA system with modulus primes, p and q, sharing a large number of least significant bits. In ISC 2007, Zhao and Qi analyzed the security of short exponent LSBS-RSA. They claimed that short exponent LSBS-RSA is much more vulnerable to the lattice attack than the standard RSA. In this paper, we further raise the security boundary of the Zhao-Qi attack by considering another polynomial. Our improvemet supports the result of analogue Fermat factoring on LSBS-RSA, which claims that p and q cannot share more than least significant bits, where n is the bit-length of pq. In conclusion, it is a trade-off between the number of sharing bits and the security level in LSBS-RSA. One should be more careful when using LSBS-RSA with short exponents. © 2008 Springer Berlin Heidelberg.

Metrics

1 Record Views

Details

Logo image