Paper 2026/2131

Forging 1024-bit RSA signatures in nearly SNFS time

Laura Shea, UC San Diego
Miro Haller, UC San Diego
Adam Suhl, UC San Diego
Nadia Heninger, UC San Diego
Emmanuel Thomé, INRIA Nancy
Abstract

The security of RSA is generally understood to be based on the complexity of factoring, and key size parameters are extrapolated from the general number field sieve (GNFS). However, this may not accurately represent RSA security in practical scenarios. An under-appreciated 2007 algorithm of Joux, Naccache, and Thomé allows an attacker to forge RSA signatures after temporary access to a raw RSA signing/decryption oracle in time close to the *special* number field sieve (SNFS) without factoring the key. We implement and run this algorithm for 1024-bit RSA. In total, the attack took 1380 CPU core-years over five calendar months, and made $2^{32}$ oracle queries. Most of this time is precomputation; after the precomputation the attacker can forge any signature of choice, offline, in 180 core-years. We carried out our attack using a hardware security module (HSM) as the signing oracle, thus demonstrating the ability to impersonate the HSM through black-box API interactions, without exfiltrating the key. Blind RSA schemes also provide such a signing oracle. Extrapolating our empirical running times to larger key sizes, we conclude that the concrete security of RSA with a signing oracle should be 15 to 30 bits lower than the factoring-based security estimates for the 1024-bit to 4096-bit RSA parameters that are common in practice. Even 4096-bit RSA does not appear to meet a 128-bit security level in this attack model. This highlights a gap in current RSA-type security assumptions, and gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
RSAnumber field sieve1024blind RSAhardware security module
Contact author(s)
lmshea @ ucsd edu
mhaller @ ucsd edu
asuhl @ ucsd edu
nadiah @ ucsd edu
emmanuel thome @ inria fr
History
2026-09-22: approved
2026-09-20: received
See all versions
Short URL
https://ia.cr/2026/2131
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2131,
      author = {Laura Shea and Miro Haller and Adam Suhl and Nadia Heninger and Emmanuel Thomé},
      title = {Forging 1024-bit {RSA} signatures in nearly {SNFS} time},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2131},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2131}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.