Paper 2012/106
More on Correcting Errors in RSA Private Keys: Breaking CRT-RSA with Low Weight Decryption Exponents
Santanu Sarkar and Subhamoy Maitra
Abstract
Several schemes have been proposed towards the fast encryption and decryption in RSA and its variants. One popular idea is to use integers having low Hamming weight in the preparation of the decryption exponents. This is to reduce the multiplication effort in the square and multiply method in the exponentiation routine, both in encryption and decryption. In this paper we show that such schemes are insecure in CRT-RSA when the encryption exponent is small (e.g.,
Note: Presented at Indo-US workshop on "Mathematical and Statistical Aspects of Cryptography" at Indian Statistical Institute, Kolkata, January 12-14, 2012.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. Unknown where it was published
- Keywords
- CRT-RSACryptanalysisError CorrectionExponentsHamming WeightRSA.
- Contact author(s)
- subho @ isical ac in
- History
- 2012-02-29: received
- Short URL
- https://ia.cr/2012/106
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2012/106, author = {Santanu Sarkar and Subhamoy Maitra}, title = {More on Correcting Errors in {RSA} Private Keys: Breaking {CRT}-{RSA} with Low Weight Decryption Exponents}, howpublished = {Cryptology {ePrint} Archive, Paper 2012/106}, year = {2012}, url = {https://eprint.iacr.org/2012/106} }