An Attack on RSA Given a Small Fraction of the Private Key Bits
1998; Springer Science+Business Media; Linguagem: Inglês
10.1007/3-540-49649-1_3
ISSN1611-3349
AutoresDan Boneh, Glenn Durfee, Yair Frankel,
Tópico(s)Cryptographic Implementations and Security
ResumoWe show that for low public exponent rsa, given a quarter of the bits of the private key an adversary can recover the entire private key. Similar results (though not as strong) are obtained for larger values of e. For instance, when e is a prime in the range [N1/4, N1/2], half the bits of the private key suffice to reconstruct the entire private key. Our results point out the danger of partial key exposure in the rsa public key system.
Referência(s)