Short secret exponent attack on LSBS-RSA.
Ravva Santosh, Narasimham Challa, Pallam Shetty · The International Arab Journal of Information Technology · 2015
LSBS-RSA is a variation of RSA cryptosystem with modulus primes p, q, sharing a large number of least significant bits. As original RSA, LSBS-RSA is also vulnerable to the short secret exponent attack. Sun et al. [15] studied this problem and they provided the bound for secret exponent as: 2 2 5 4 3 1 6 1 3 6 3 2 2 6 γ β α α γ α − < + − + − − . Their bound does not reduce to the optimal bound 0.292 for original RSA, which is provided by Boneh-Durfee. In this paper, we achieve the bound 1 2 2 γ β αγ < − − which reduces to the Boneh-Durfee optimal bound. Keyword: Lattice reduction, unravelled linearization, LSBS-RSA. Received March 7, 2013; accepted June 9, 2014; published online August 9, 2015