Partial Key Exposure Attacks on RSA with Multiple Exponent Pairs
Partial Key Exposure Attacks on RSA with Multiple Exponent Pairs
复制标题
DOI:
10.1007/978-3-319-40367-0_15
复制
发表时间:
2016-07
期刊:
影响因子:
--
通讯作者:
Atsushi Takayasu;N. Kunihiro
中科院分区:
文献类型:
--
作者:
Atsushi Takayasu;N. Kunihiro
So far, several papers have analyzed attacks on RSA when attackers know the least significant bits of a secret exponentdas well as a public modulusNand a public exponente, the so-called partial key exposure attacks. Aono (ACISP 2013), and Takayasu and Kunihiro (ACISP 2014) generalized the attacks when there are multiple pairs of a public/secret exponentfor the same public modulusN. The standard RSA is a special case of the generalization, i.e.,. They revealed that RSA becomes more vulnerable when there are more exponent pairs. However, their results havetwo obvious drawbacks. First, partial key exposure situations which they considered are restrictive. They have proposed the attacks only for small secret exponents, although attacks for large secret exponents have also been analyzed for the standard RSA. Second, they could not generalize the attacks perfectly. More concretely, their attacks fordo not correspond to the currently known best attacks on the standard RSA.In this paper, we propose improved partial key exposure attacks on RSA with multiple exponent pairs. Our results completely solve the above drawbacks. Our attacks are the first results for large exponents, and our attacks forcorrespond to the currently known best attacks on the standard RSA. Our results for small secret exponents are superior to previous results whenand 2, and whenand.