Cryptanalysis of RSA with private key d less than N0.292

  • Authors:
  • D. Boneh;G. Durfee

  • Affiliations:
  • Dept. of Comput. Sci., Stanford Univ., CA;-

  • Venue:
  • IEEE Transactions on Information Theory
  • Year:
  • 2006

Quantified Score

Hi-index 754.84

Visualization

Abstract

We show that if the private exponent d used in the RSA (Rivest-Shamir-Adleman (1978)) public-key cryptosystem is less than N 0.292 then the system is insecure. This is the first improvement over an old result of Wiener (1990) showing that when d is less than N0.25 the RSA system is insecure. We hope our approach can be used to eventually improve the bound to d less than N 0.5