A Comprehensive Study of Backdoors for RSA Key Generation

Ting-Yu Lin,Hung-Min Sun,Mu-En Wu
2006-01-01
Abstract:Young and Yung devised various backdoors for RSA key generation. However, due to their backdoor constructing method, the two MSBs of the modulus n generated by their systems have di¤erent distribution than that generated by the normal RSA. Thus, someone may observe the abnormal distribution of n to detect the existence of backdoors. Recently, Crepéau and Slakmon further suggested four simple ways to construct RSA backdoor mechanisms. Although their schemes have roughly the same running time as the normal RSA, they are still not StrongSETUPs. Hence, in this paper, we propose three RSA backdoor cryptosystems. The …rst two, RSA-SBLT and RSA-SBES, have the same advantages as Crépeau and Slakmon’s RSA-HP but provide new ways to construct the backdoors. As for our third backdoor cryptosystem, RSA-BDH, we exploit the relationship between p and q to devise a backdoor which can solve the problem occurring in Young and Yong’s methods successfully. Moreover, we prove that RSA-BDH is a real Strong-SETUP based on DH assumption.
What problem does this paper attempt to address?