<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>2008 Reports</title>
    <link>http://eprint.iacr.org/forum/list.php?8</link>
    <description><![CDATA[Discussion forum for Cryptology ePrint Archive reports posted in 2008.
Please put the report number in the subject.

]]></description>
    <language>EN</language>
    <pubDate>Wed, 30 Jul 2008 18:08:48 -0600</pubDate>
    <lastBuildDate>Wed, 30 Jul 2008 18:08:48 -0600</lastBuildDate>
    <category>2008 Reports</category>
    <generator>Phorum 5.1.22</generator>
    <ttl>600</ttl>
    <item>
      <title>about  2008/296</title>
      <link>http://eprint.iacr.org/forum/read.php?8,58,58#msg-58</link>
      <author>zhaoyaodong</author>
      <description><![CDATA[The authors studied the small private-key attacks of LSBS-RSA in the paper. They suspected there are some errors in the Zhao-Qi attack reported in [25]. 

But the error they pointed in the paper does not exist in the Zhao-Qi attack. In fact, in the Zhao-Qi attack, that they ignored the factor &quot;a&quot; will not lead to error.

Because in [25], they assumed that the publice key e was an odd number, so a^{-1} existed. Let u_{i} be a positive number that satisfied a^{-i}*a-u_{i}*e^m=1. They use the coeffient vectors of the ploynomial a^(-i)f(xX,yY,zZ)-u_{i}*e^m*I/(a^t) to build the lattice in order to eliminate the factor &quot;a&quot; in the terms in the diagonal of the matrix, where I is the term in the diagonal of the matrix of the polynomial f(xX, yY, zZ). It is obvious that a^(-i)f(x_0,y_0,z_0)-u_{i}*e^m*I/(a^t) mod e^m =0, where (x_0, y_0, z_0) is the small root they want to get. So using LLL-algorithm to the Zhao-Qi's lattice, the polynomials they get h1(x, y, z), h2(x, y, z) will still satisfy h1(x_0, y_0, z_0)= h2(x_0, y_0, z_0)=0 mod e^m. This technique decreases the det(L) which leads to a larger bound of the attack. I think this technique is very simple, so it is ignored in Zhao's work.]]></description>
      <category>2008 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?8,58,58#msg-58</guid>
      <pubDate>Wed, 30 Jul 2008 18:08:48 -0600</pubDate>
    </item>
  </channel>
</rss>
