On an Attack on RSA with Small CRT-exponents

LiDong Han,XiaoYun Wang,GuangWu Xu
DOI: https://doi.org/10.1007/s11432-010-4029-2
2010-01-01
Science China Information Sciences
Abstract:This paper concerns the RSA system with private CRT-exponents. Since Chinese remainder rep- resentation provides efficiency in computation, such system is of some practical significance. In this paper, an existing attack to small private CRT-exponents is analyzed. It is indicated that this attack makes nice use of lattice in RSA analysis, but some argument does not hold in general. Several counterexamples are constructed. Refinements and more precise statements of the attack are given.
What problem does this paper attempt to address?