Guide Twenty Years of Attacks on the RSA Cryptosystem

Twenty years of attacks on the RSA cryptosystem. Authors: D. Boneh. Abstract: Two decades of research led to a number fascinating attacks on RSA. We survey .
Modified Multi Prime RSA Cryptosystem

A simple example

No known mechanism to easily invert f k M However, not proven to be impossible. Implementation Difference between the function and the cryptosystem Cryptosystem is not semantically secure Given N, e, C it is possible to recover some information about M Example: Jacobi symbol of M over N Fixed by padding M with random bits.

Must N be factored in order to efficiently compute e th roots mod N?

  • Is breaking RSA as hard as factoring? Probably not Evidence that for small e, answer may be no There may not exist a polynomial-time reduction from factoring to breaking RSA However, not proven Negative answered probably preferred over positive answer. Trusted authority can provide user i with keys N, e i , N, d i Attacker can use own e a, d a to factor N Once N is factored, recovering d i easy Do not reuse N.

    Implementing Secure RSA Cryptosystems Using Your Own Cryptographic JCE Provider

