Minkowski sum based lattice construction for solving simultaneous modular equations and applications to RSA

نویسنده

  • Yoshinori Aono
چکیده

We investigate a lattice construction method for the Coppersmith technique for finding small solu-tions of a modular equation. We consider its variant for simultaneous equations and propose a methodto construct a lattice by combining lattices for solving single equations. As applications, we consider(i) a new RSA cryptanalysis for multiple short secret exponents, (ii) its partial key exposure situation,and (iii) investigating the hardness of finding a certain amount of LSBs of the RSA secret exponent.More precisely, our algorithm can factor an RSA modulus from l ≥ 2 pairs of RSA public exponentswith the common modulus corresponding to secret exponents smaller than N (9l−5)/(12l+4), which im-proves on the previously best known result N (3l−1)/(4l+4) by Sarkar and Maitra [41, 42]. For partialkey exposure situation, we also can factor the modulus if β − δ/2 + 1/4 < (3l − 1)(3l + 1), whereβ and δ are bit-lengths /n of the secret exponent and its exposed LSBs, respectively. Particularly,letting β = 1, which means that the secret exponent is full-sized, the necessary amount of exposedbits is [5/2− 2(3l− 1)/(3l+ 1)]n, which is less than n for l ≥ 3. Suppose we have an algorithm thatrecovers the above amount of d from e and N satisfying e ≈ N . We showed that N can be factored inpolynomial time in logN under a heuristic assumption that the Coppersmith technique works. Whenl becomes large, the necessary amount becomes 0.5n bits. Hence, we conclude that recovering thelower half of LSBs of d is polynomial time equivalent to the factoring under the heuristic assumption.From the last result, we propose a half-amount conjecture that roughly, factoring RSA modulus ispolynomial-time equivalent to any continued bits of secret information such as p, q, d, p + q and p − q(or dp and dq for RSA-CRT). It is supported from several results, e.g., Coppersmith [12] shows thatrecovering the upper half of p is equivalent to factoring.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Minkowski Sum Based Lattice Construction for Multivariate Simultaneous Coppersmith's Technique and Applications to RSA

We investigate a lattice construction method for the Coppersmith technique for finding small solutions of a modular equation. We consider its variant for simultaneous equations and propose a method to construct a lattice by combining lattices for solving single equations. As applications, we consider a new RSA cryptanalyses. Our algorithm can factor an RSA modulus from l ≥ 2 pairs of RSA public...

متن کامل

QTRU: quaternionic version of the NTRU public-key cryptosystems

In this paper we will construct a lattice-based public-key cryptosystem using non-commutative quaternion algebra, and since its lattice does not fully fit within Circular and Convolutional Modular Lattice (CCML), we prove it is arguably more secure than the existing lattice-based cryptosystems such as NTRU. As in NTRU, the proposed public-key cryptosystem relies for its inherent securi...

متن کامل

Solving Linear Equations Modulo Unknown Divisors: Revisited

We revisit the problem of finding small solutions to a collection of linear equations modulo an unknown divisor p for a known composite integer N . In CaLC 2001, Howgrave-Graham introduced an efficient algorithm for solving univariate linear equations; since then, two forms of multivariate generalizations have been considered in the context of cryptanalysis: modular multivariate linear equation...

متن کامل

Short review of lattice basis reduction types and his applications. (Russian)

This article presets a review of lattice lattice basis reduction types. Paper contains the main five types of lattice basis reduction: size reduced (weak Hermit), c-reduced, Lovasz condition, Hermit-Korkin-Zolotarev, Minkowski reduced. The article provides references to applications in: information theory (decoding of coding group in MIMO), calculus (minimize of the positive quadratic form), co...

متن کامل

Finding Small Solutions of a Class of Simultaneous Modular Equations and Applications to Modular Inversion Hidden Number Problem and Inversive Congruential Generator

In this paper we revisit the modular inversion hidden number problem and the inversive congruential pseudo random number generator and consider how to more efficiently attack them in terms of fewer samples or outputs. We reduce the attacking problem to finding small solutions of systems of modular polynomial equations of the form ai+bix0+cixi+x0xi = 0 (mod p), and present two strategies to cons...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2012  شماره 

صفحات  -

تاریخ انتشار 2012