Paper 2026/1357
A refined cryptanalytic attack against a generalized cubic Pell RSA scheme
Abstract
In 2022, Cotan and Te{\c{s}}eleanu proposed an alternative RSA construction in which the modulus takes the form $N = pq$ and the exponents $(e,d)$ are linked through $ ed -1\equiv 0 \pmod{\psi_n(N)},\ n \geq 2, $ where $ \psi_n(N) = \frac{(p^n-1)(q^n-1)}{(p-1)(q-1)}. $ Their scheme was subsequently examined by Nitaj et al. at Africacrypt 2024, who demonstrated that the system becomes vulnerable when the secret exponent $d$ is less than $N^{0.292(n-1)}$. In the present work, we extend this line of cryptanalysis by developing a lattice-based technique targeting the same key congruence. Our approach succeeds in recovering the private parameters even for secret exponents greater than $N^{0.292(n-1)}$, thereby surpassing the previously known boundary. The factorization of $N$ is achieved in polynomial time, provided that its divisors $p$ and $q$ share a suitably portion of their least significant bits.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published elsewhere. Minor revision. Minor revision. Discrete mathematics
- Keywords
- RSAGeneralized cubic Pell RSA variantInteger factorizationCoppersmith's methodLLL reduction algorithm
- Contact author(s)
-
brahim chnioune d24 @ ump ac ma
mohammed rahmani @ ump ac ma
abderrahmane nitaj @ unicaen fr
m ziane @ ump ac ma - History
- 2026-07-06: approved
- 2026-07-02: received
- See all versions
- Short URL
- https://ia.cr/2026/1357
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1357,
author = {Brahim Chnioune and Mohammed Rahmani and Abderrahmane Nitaj and Mhammed Ziane},
title = {A refined cryptanalytic attack against a generalized cubic Pell {RSA} scheme},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1357},
year = {2026},
url = {https://eprint.iacr.org/2026/1357}
}