Security Analysis of a Shared Modular Inversion Protocol for RSA Cryptosystem
Fanyu Kong, Jia Yu · 2009
D. Catalano, R. Gennaro and S. Halevi had proposed a modular inversion protocol for computing a shared RSA private exponent. In this paper, we propose the security analysis of this shared modular inversion protocol. Firstly, we prove that Catalano-Gennaro-Halevi protocol is insecure when the public exponent is larger than a specific integer. Secondly, it is shown that a fraction of the private exponent d is leaked and only a few bits ofdsuffice to break the protocol, which is more fragile when smaller parameters are applied.