...
首页> 外文期刊>Theoretical computer science >Generalized cryptanalysis of small CRT-exponent RSA
【24h】

Generalized cryptanalysis of small CRT-exponent RSA

机译:小型CRT-exconent RSA的广义密码分析

获取原文
获取原文并翻译 | 示例
           

摘要

There have been several works for studying the security of CRT-RSA with small CRT exponents d(p) and d(q) by using lattice-based Coppersmith's method. Thus far, two attack scenarios have been mainly studied: (1) d(q) is small with unbalanced prime factors p q. (2) Both d(p) and d(q) are small for balanced p approximate to q. The best attacks for the both scenarios were proposed by Takayasu-Lu-Peng (Eurocrypt'17. Journal of Cryptology'19) and the attack conditions are much better than the other known attacks. Although the attacks have been very useful for studying the security of CRT-RSA, the structures of their proposed lattices are not well understood. In this paper, to further study the security of CRT-RSA, we first define a generalized attack scenario to unify the previous ones. Specifically, all p, q, d(p), and d(q) can be of arbitrary sizes. Furthermore, we propose improved attacks in this paper when d(p) and/or p is sufficiently small. Technically, we construct a lattice whose basis vectors are chosen flexibly depending on the sizes of p, q, d(p), and d(q). Since the attack scenarios (1) and (2) are simpler than our general scenario, the previous Takayasu-Lu-Peng's lattices are simple special cases of ours. We are able to achieve the flexible lattice constructions by exploiting implicit but essential structures of Takayasu-Lu-Peng's lattices. We check the validity of our proposed attacks by computer experiments. We believe that the deeper understanding of the lattice structures will be useful for studying the security of CRT-RSA even in other scenarios. (C) 2019 Elsevier B.V. All rights reserved.
机译:通过使用基于格子的COPPERSMITH的方法,已经有几种用于研究CRT-RSA的安全性的CRT-RSA的安全性。到目前为止,主要研究了两种攻击情景:(1)D(Q)小,具有不平衡的主要因素P q。 (2)D(P)和D(Q)小于Q的平衡P近似。 Takayasu-Lu-Peng(Eurocrypt'17)提出了这两种情况的最佳攻击。“Cryptology'19杂志”),攻击条件比其他已知攻击要好得多。虽然攻击对于研究CRT-RSA的安全性非常有用,但其所提出的格子的结构并不符合很好的理解。在本文中,为了进一步研究CRT-RSA的安全性,我们首先定义一个泛化攻击方案来统一以前的攻击方案。具体地,所有p,q,d(p)和d(q)可以是任意尺寸。此外,当D(P)和/或P足够小时,我们提出了本文中的改进攻击。从技术上讲,我们构造一个晶格,其基础向量选择灵活地根据P,Q,D(P)和D(Q)的尺寸。由于攻击情景(1)和(2)比我们的一般情景更简单,因此之前的高山鲁鹏的格子是我们简单的特殊情况。我们能够通过利用Takayasu-Lu-Lu-Peng的格子的隐含而是实现灵活的格子结构。我们通过计算机实验检查我们提出攻击的有效性。我们认为,即使在其他情况下,对晶格结构的更深入了解CRT-RSA的安全性。 (c)2019 Elsevier B.v.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号