A polynomial-time algorithm for breaking the basic Merkle - Hellman cryptosystem
Adi Shamir · IEEE Transactions on Information Theory · 1984
The Merkle-Hellman cryptosystem is one of the two major public-key cryptosystems proposed so far. It is shown that the basic variant of this cryptosystem, in which the elements of the public key are modular multiples of a superincreasing sequence, is breakable in polynomial time.