<p>In this paper, we focus on the common prime RSA variant and introduce a novel investigation into the partial key exposure attack targeting it for the first time. We explore the vulnerability of this RSA variant, which employs two primes <i>p</i> and <i>q</i> defined as <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_383_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="87" /> </InlineMediaObject> <EquationSource Format="TEX">\(p=2ga+1\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>p</mi> <mo>=</mo> <mn>2</mn> <mi>g</mi> <mi>a</mi> <mo>+</mo> <mn>1</mn> </mrow> </math></EquationSource> </InlineEquation> and <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_383_Article_IEq2.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="84" /> </InlineMediaObject> <EquationSource Format="TEX">\(q=2gb+1\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>q</mi> <mo>=</mo> <mn>2</mn> <mi>g</mi> <mi>b</mi> <mo>+</mo> <mn>1</mn> </mrow> </math></EquationSource> </InlineEquation> for a large common prime <i>g</i>. Previous cryptanalysis of common prime RSA has primarily concentrated on the small private key attack. In contrast, we delve deeper into the partial key exposure attacks by categorizing them into three distinct cases. We are able to identify weak private keys that are susceptible to partial key exposure by using the lattice-based method for solving simultaneous modular univariate linear equations. Moreover, we conduct numerical experimental evaluations and demonstrate the validity of the proposed partial key exposure attacks on common prime RSA.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

New lattice-based partial key exposure attacks on common prime RSA

  • Mengce Zheng

摘要

In this paper, we focus on the common prime RSA variant and introduce a novel investigation into the partial key exposure attack targeting it for the first time. We explore the vulnerability of this RSA variant, which employs two primes p and q defined as \(p=2ga+1\) p = 2 g a + 1 and \(q=2gb+1\) q = 2 g b + 1 for a large common prime g. Previous cryptanalysis of common prime RSA has primarily concentrated on the small private key attack. In contrast, we delve deeper into the partial key exposure attacks by categorizing them into three distinct cases. We are able to identify weak private keys that are susceptible to partial key exposure by using the lattice-based method for solving simultaneous modular univariate linear equations. Moreover, we conduct numerical experimental evaluations and demonstrate the validity of the proposed partial key exposure attacks on common prime RSA.