On the uniformity of distribution of the decryption exponent in fixed encryption exponent RSA

被引:1
作者
Shparlinski, IE [1 ]
机构
[1] Macquarie Univ, Dept Comp, Sydney, NSW 2109, Australia
关键词
RSA; fixed encryption exponent; decryption exponent; boneh; Durfee and Frankel attack; safety/security in digital systems;
D O I
10.1016/j.ipl.2004.07.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Let us fix a security parameter n and a sufficiently large encryption exponent e. We show that for a random choice of the RSA modulus m = pq, where p and q are n-bit primes, the decryption exponent d, defined by ed equivalent to 1 (mod phi(m)) is uniformly distributed modulo phi(m). It is known, due to recent work of Boneh, Durfee and Frankel, that additional information about some bits of d may turn out to be dramatic for the security of the whole cryptosystem. Our uniformity of distribution result implies that sufficiently long strings of the most and the least significant bits of d, which are vulnerable to such attacks, behave as random binary vectors. (C) 2004 Elsevier B.V. All rights reserved.
引用
收藏
页码:143 / 147
页数:5
相关论文
共 15 条
[1]  
Blömer J, 2001, LECT NOTES COMPUT SC, V2146, P4
[2]  
Boneh D, 1998, LECT NOTES COMPUT SC, V1514, P25
[3]   Cryptanalysis of RSA with private key d less than N0.292 [J].
Boneh, D ;
Durfee, G .
IEEE TRANSACTIONS ON INFORMATION THEORY, 2000, 46 (04) :1339-1349
[4]  
BONEH D, 1999, NOT AM MATH SOC, V46, P203
[5]  
Drmota M., 1997, SEQUENCES DISCREPANC
[6]  
Durfee G, 2000, LECT NOTES COMPUT SC, V1976, P14
[7]  
Hardy G. H., 2008, INTRO THEORY NUMBERS, Vsixth
[8]  
HOWGRAVEGRAHAM N, 1999, LECT NOTES COMP SCI, V1740, P153
[9]  
Kuipers L, 1974, UNIFORM DISTRIBUTION
[10]  
May A, 2002, LECT NOTES COMPUT SC, V2442, P242