Another Generalization of Weak Keys in RSA with Prime Sharing LSBs
Navaneet Ojha, Sahadeo Padhye · 2012
In this paper we revisit Meng et.al [9] method to find new weakness in RSA. Let N = pq be an LSBS-RSA modulus where p and q have same bit length. Let p and ρq share the m least significant bits, where ρ(1 ≤ ρ ≤ 2) is known to the attacker. In this paper, under some assumption, we show that the number of weak keys e is at least N 3 4 +θ−� ,