Forensic Construction-Family Signatures in Solved RSA Challenge Moduli: High-Bit Conditioning, Residue Constraints, and Factor-Balance Patterns

Anthony Overmars, Sitalakshmi Venkatraman · Information · 2026

RSA moduli may retain arithmetic evidence of prime-selection constraints. We analyse 22 solved formal RSA Challenge moduli (44 factors), excluding RSA-129 and treating 18 original decimal-labelled entries separately from four later bit-labelled entries. Exact arithmetic and matched Monte Carlo controls show that all 44 factors begin with the binary prefix 11. This high-bit condition forces b(N) = b(p) + b(q) and, with balanced factor-bit allocation, explains equal factor-bit lengths for even-bit moduli and adjacent factor-bit lengths for odd-bit moduli. All 18 original pairs also satisfy p ≡ q ≡ 2 (mod 3), recovering a documented public exponent compatibility rule. The analysis used 620,000 accepted control pairs and 100,000 pseudo-datasets per comparison. The observed all-11 pair count was 22, compared with a size-and-label model median of 8 (Holm-adjusted p = 3.00 × 10−5); the residue-pair count was 18, compared with a high-bit model median of 4 (adjusted p = 3.00 × 10−5). For the eight adjacent-bit moduli, the frozen lower-tail comparison did not reject the documented-residue model (p = 0.1007). An independently seeded rerun reproduced the pseudo-dataset inference from the archived pools, but independent regeneration of the full control pools remains pending. The evidence supports broad high-bit conditioning and recovery of documented metadata but not a separate factor-balance signature, implementation attribution, weak-key detection, or reduced factoring resistance.

Read the paper · More papers on PaperTik