首页 | 官方网站   微博 | 高级检索  
     


On the Security of RSA with Primes Sharing Least-Significant Bits
Authors:Ron Steinfeld  Yuliang Zheng
Affiliation:(1) Department of Computing, Macquarie University, North Ryde, NSW, 2109, Australia;(2) Department of Software and Information Systems, University of North Carolina at Charlotte, Charlotte, NC 28223, USA
Abstract:We investigate the security of a variant of the RSA public-key cryptosystem called LSBS-RSA, in which the modulus primes share a large number of least-significant bits. We show that low public-exponent LSBS-RSA is inherently resistant to Partial Key Exposure (PKE) attacks in which least-significant bits of the secret exponent are revealed to the attacker, and in particular that the Boneh-Durfee-Frankel PKE attack 5] on low public-exponent RSA is less effective for LSBS-RSA systems than for standard RSA. On the other hand, we show that large public-exponent LSBS-RSA is more vulnerable to such attacks than standard RSA. An application to server-aided RSA signature generation is proposed.This is an extended version of an earlier paper presented at the Cryptographerrsquos Track RSA Conference (CT-RSA 2001), April 8-12 2001, San Francisco, USA 20].This work was done while the author was at the School of Network Computing, Monash University, Frankston, Australia.Acknowledgement The authors would like to thank the anonymous referees of CT-RSA 2001 for their helpful comments on a preliminary version 20] of some of the results in this paper.
Keywords:RSA Cryptosystem  Communication Security  Cryptanalysis  Partial Key Exposure  Boneh-Durfee-Frankel Attack  Coppersmith Algorithm  Least-Significant Bits  Server-Aided Signature Generation
本文献已被 SpringerLink 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号