首页> 外文会议>International Symposium on Information Theory and its Applications >Small secret exponent attacks on RSA with unbalanced prime factors
【24h】

Small secret exponent attacks on RSA with unbalanced prime factors

机译:具有不平衡主因子的RSA的小型秘密指数攻击

获取原文

摘要

Boneh and Durfee (Eurocrypt 1999) proposed two polynomial time attacks on small secret exponent RSA. The first attack works when d <; N0.284 whereas the second attack works when d <; N0.292. Both attacks are based on lattice based Coppersmith's method to solve modular equations. Durfee and Nguyen (Asiacrypt 2000) extended the attack to a variant of RSA where prime factors are not the same sizes. However, the attack extended only the first attack of the Boneh-Durfee. Hence, an open problem remains, i.e., if the Boneh-Durfee second attack can be extended to unbalanced RSA. In this paper, we propose a desired attack that extended the Boneh-Durfee second attack. Our proposed attack fully improves the Durfee-Nguyen attack for all size of prime factors. The improvement stems from our technical lattice construction. Although Durfee and Nguyen only analyzed lattices whose basis matrices are triangular, we analyze broader classes of lattices that contain non-triangular basis matrices. The analysis can be performed by using the unravelled linearization proposed by Herrmann and May (Asiacrypt 2009) and the transformation on the Boneh-Durfee lattices proposed by Takayasu and Kunihiro (PKC 2016). As a result, we can exploit useful algebraic structure compared with the Durfee-Nguyen.
机译:Boneh和Durfee(Eurocrypt 1999)提出了对小秘密指数RSA的两次多项式时间攻击。 d <;时,第一次攻击有效。 N0.284,而第二次攻击在d <;时起作用。 N0.292。两种攻击都基于基于网格的Coppersmith方法来求解模块化方程式。 Durfee和Nguyen(Asiacrypt 2000)将攻击范围扩展到了主要因子大小不相同的RSA变体。但是,这次袭击只扩大了Boneh-Durfee的第一次进攻。因此,仍然存在公开问题,即,如果可以将Boneh-Durfee的第二次攻击扩展到不平衡的RSA。在本文中,我们提出了一种期望的攻击,该攻击扩展了Boneh-Durfee的第二次攻击。我们建议的攻击方法可以针对所有大小的主要因素完全改善Durfee-Nguyen攻击。改进源于我们的技术架构。尽管Durfee和Nguyen仅分析了基矩阵为三角形的晶格,但我们分析了包含非三角形基矩阵的更大范围的晶格。可以通过使用Herrmann和May(Asiacrypt 2009)提出的解散线性化以及Takayasu和Kunihiro(PKC 2016)提出的Boneh-Durfee晶格变换来进行分析。结果,与Durfee-Nguyen相比,我们可以利用有用的代数结构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号