IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences
Online ISSN : 1745-1337
Print ISSN : 0916-8508
Special Section on Cryptography and Information Security
Small Secret Key Attack on a Takagi's Variant of RSA
Kouichi ITOHNoboru KUNIHIROKaoru KUROSAWA
Author information
JOURNAL RESTRICTED ACCESS

2009 Volume E92.A Issue 1 Pages 33-41

Details
Abstract

For a variant of RSA with modulus N = prq and ed ≡ 1 (mod(p-1)(q-1)), we show that d is to be recovered if d < N(2-√2)/(r+1). (Note that φ(N) ≠ (p-1)(q-1).) Boneh-Durfee's result for the standard RSA is obtained as a special case for r=1. Technically, we develop a method for finding a small root of a trivariate polynomial equation f(x, y, z)=x(y-1)(z-1)+1 ≡ 0 (mod e) under the condition that yrz=N. Our result cannot be obtained from the generic method of Jochemsz-May.

Content from these authors
© 2009 The Institute of Electronics, Information and Communication Engineers
Previous article Next article
feedback
Top