Partial Key Exposure Attacks on CRT-RSA: General Improvement for the Exposed Least Significant Bits
Partial Key Exposure Attacks on CRT-RSA: General Improvement for the Exposed Least Significant Bits
复制标题
DOI:
10.1007/978-3-319-45871-7_3
复制
发表时间:
2016-09
期刊:
影响因子:
--
通讯作者:
Atsushi Takayasu;N. Kunihiro
中科院分区:
文献类型:
--
作者:
Atsushi Takayasu;N. Kunihiro
Blömer and May (Crypto 2003) used Coppersmith’s lattice based method to study partial key exposure attacks on CRT-RSA, i.e., an attack on RSA with the least significant bits of a CRT exponent. The attack works for an extremely small public exponente, however, improved attacks were proposed by Lu, Zhang, and Lin (ACNS 2014), Takayasu and Kunihiro (ACNS 2015). These attack works for. For a smaller (resp. larger)e, an attack of Lu et al. (resp. Takayasu-Kunihiro’s attack) requires less partial information to attack RSA.In this paper, we propose a further improved attack. Indeed, our attack completely improves previous attacks in the sense that our attack requires less partial information than previous attacks for all. We solve the same modular equation as Takayasu-Kunihiro, however, our attack can find larger roots. From the technical point of view, although the Takayasu-Kunihiro lattice follows the Jochemsz-May strategy (Asiacrypt 2006), we carefully analyze the algebraic structure of the underlying polynomial and propose better lattice constructions.