Low-exponent RSA with related messages

  • Authors:
  • Don Coppersmith;Matthew Franklin;Jacques Patarin;Michael Reiter

  • Affiliations:
  • IBM Research, Yorktown Heights, NY;AT&T Research, Murray Hill, NJ;CP8 Transac, Louveciennes, France;AT&T Research, Murray Hill, NJ

  • Venue:
  • EUROCRYPT'96 Proceedings of the 15th annual international conference on Theory and application of cryptographic techniques
  • Year:
  • 1996

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we present a new class of attacks against RSA with low encrypting exponent. The attacks enable the recovery of plaintext messages from their ciphertexts and a known polynomial relationship among the messages, provided that the ciphertexts were created using the same RSA public key with low encrypting exponent.