Sciweavers

PKC
2005
Springer

A New Related Message Attack on RSA

13 years 10 months ago
A New Related Message Attack on RSA
Coppersmith, Franklin, Patarin, and Reiter show that given two RSA cryptograms xe mod N and (ax + b)e mod N for known constants a, b ∈ ZN , one can compute x in O(e log2 e) ZN -operations with some positive error probability. We show that given e cryptograms ci ≡ (aix + bi)e mod N, i = 0, 1, ...e − 1, for any known constants ai, bi ∈ ZN , one can deterministically compute x in O(e) ZN -operations that depend on the cryptograms, after a pre-processing that depends only on the constants. The complexity of the pre-processing is O(e log2 e) ZN operations, and can be amortized over many instances. We also consider a special case where the overall cost of the attack is O(e) ZN -operations. Our tools are borrowed from numerical-analysis and adapted to handle formal polynomials over finite-rings. To the best of our knowledge their use in cryptanalysis is novel.
Oded Yacobi, Yacov Yacobi
Added 28 Jun 2010
Updated 28 Jun 2010
Type Conference
Year 2005
Where PKC
Authors Oded Yacobi, Yacov Yacobi
Comments (0)