Remarks on the Bounds for Cryptanalysis of Low Private Key RSA

Haijian Zhou,Ping Luo,Daoshun Wang,Yiqi Dai
DOI: https://doi.org/10.1016/j.pnsc.2008.09.013
2009-01-01
Abstract:Boneh and Durfee have developed a cryptanalytic algorithm on low private key RSA. The algorithm is based on lattice basis reduction and breaks RSA with private key d < N-0.292. Later on, an improved version by Blomer and May enhanced the efficiency, while reaching approximately this same upper bound. Unfortunately, in both the algorithms, there is a critical error in theoretical analysis, leading to the overestimated upper bound N-0.292. In this paper we present a more precise analytical model, with which the theoretical upper bound on d is modified to approximately d < N-0.277 for ordinary RSA systems with a 1024-bit public key (N,e). (C) 2009 National Natural Science Foundation of China and Chinese Academy of Sciences. Published by Elsevier Limited and Science in China Press. All rights reserved.
What problem does this paper attempt to address?