On the uniformity of distribution of the decryption exponent in fixed encryption exponent RSA

被引:1
作者
Shparlinski, IE [1 ]
机构
[1] Macquarie Univ, Dept Comp, Sydney, NSW 2109, Australia
关键词
RSA; fixed encryption exponent; decryption exponent; boneh; Durfee and Frankel attack; safety/security in digital systems;
D O I
10.1016/j.ipl.2004.07.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Let us fix a security parameter n and a sufficiently large encryption exponent e. We show that for a random choice of the RSA modulus m = pq, where p and q are n-bit primes, the decryption exponent d, defined by ed equivalent to 1 (mod phi(m)) is uniformly distributed modulo phi(m). It is known, due to recent work of Boneh, Durfee and Frankel, that additional information about some bits of d may turn out to be dramatic for the security of the whole cryptosystem. Our uniformity of distribution result implies that sufficiently long strings of the most and the least significant bits of d, which are vulnerable to such attacks, behave as random binary vectors. (C) 2004 Elsevier B.V. All rights reserved.
引用
收藏
页码:143 / 147
页数:5
相关论文
共 42 条
  • [41] Securing RSA against power analysis attacks through non-uniform exponent partitioning with randomisation
    Mahanta, Hridoy Jyoti
    Khan, Ajoy Kumar
    IET INFORMATION SECURITY, 2018, 12 (01) : 25 - 33
  • [42] Generalized cryptanalysis of RSA with small public exponent针对公钥e小于等于N的0.5次幂的RSA算法的广义密码分析
    Mengce Zheng
    Honggang Hu
    Zilong Wang
    Science China Information Sciences, 2016, 59