Wiener attack and weak keys of the RSA cryptosystem
Andrey E. Trishin · Discrete Mathematics and Applications · 2025
Abstract It is proved that the generalized Wiener attack on the RSA cryptosystem allows one to find not only small, but also some large secret exponents d , and the fraction of exponents d which are weak against this attack is heuristically estimated as O ( N −1/2 ).