Partial Key Exposure Attacks on RSA with Multiple Exponent Pairs

Partial Key Exposure Attacks on RSA with Multiple Exponent Pairs
复制标题

DOI:
10.1007/978-3-319-40367-0_15
复制
发表时间:
2016-07
期刊:
--
影响因子:
--
通讯作者:
Atsushi Takayasu;N. Kunihiro
Atsushi Takayasu;N. Kunihiro
中科院分区:
其他
文献类型:
--
作者:
Atsushi Takayasu;N. Kunihiro

文献摘要

相似文献

到目前为止,已有多篇文章分析了当攻击者知道秘密指数das以及公开模N和公开指数的最低有效位时对RSA的攻击,即所谓的部分密钥暴露攻击。Aono(ACISP 2013),Takayasu和Kunihiro(ACISP 2014)概括了当同一个公共模N有多对公共/秘密指数时的攻击。标准RSA是推广的一个特例,即,。他们发现,当有更多的指数对时,RSA变得更脆弱。然而,他们的结果有两个明显的缺点。首先,他们认为部分密钥暴露的情况是限制性的。他们提出的攻击只针对小的秘密指数,虽然攻击大的秘密指数也已经分析了标准的RSA。其次,他们不能完美地概括攻击。更具体地说,他们的攻击不对应于目前已知的最好的攻击标准RSA。本文提出了改进的部分密钥暴露攻击的RSA与多个指数对。我们的结果完全解决了上述缺点。我们的攻击是第一个结果大指数,我们的攻击对应于目前已知的最好的攻击标准RSA。对于小秘密指数,我们的结果上级优于以前的结果,当和2,和当和.
So far, several papers have analyzed attacks on RSA when attackers know the least significant bits of a secret exponentdas well as a public modulusNand a public exponente, the so-called partial key exposure attacks. Aono (ACISP 2013), and Takayasu and Kunihiro (ACISP 2014) generalized the attacks when there are multiple pairs of a public/secret exponentfor the same public modulusN. The standard RSA is a special case of the generalization, i.e.,. They revealed that RSA becomes more vulnerable when there are more exponent pairs. However, their results havetwo obvious drawbacks. First, partial key exposure situations which they considered are restrictive. They have proposed the attacks only for small secret exponents, although attacks for large secret exponents have also been analyzed for the standard RSA. Second, they could not generalize the attacks perfectly. More concretely, their attacks fordo not correspond to the currently known best attacks on the standard RSA.In this paper, we propose improved partial key exposure attacks on RSA with multiple exponent pairs. Our results completely solve the above drawbacks. Our attacks are the first results for large exponents, and our attacks forcorrespond to the currently known best attacks on the standard RSA. Our results for small secret exponents are superior to previous results whenand 2, and whenand.