Attacks on Shamir's 'RSA for paranoids'

Henri Gilbert, Dipankar Gupta, Andrew Odlyzko, Jean Jacques Quisquater

Research output: Contribution to journalArticlepeer-review

12 Scopus citations

Abstract

In order to allow for efficient use of extremely large moduli, Adi Shamir has proposed a variant of RSA in which one of the two prime factors is much smaller than the other. This note points out that unless special precautions are taken, simple implementations of Shamir's idea are subject to protocol attacks that recover the secret keys.

Original languageEnglish (US)
Pages (from-to)197-199
Number of pages3
JournalInformation Processing Letters
Volume68
Issue number4
DOIs
StatePublished - Nov 30 1998

Keywords

  • Cryptography
  • Safety/security in digital systems

Fingerprint

Dive into the research topics of 'Attacks on Shamir's 'RSA for paranoids''. Together they form a unique fingerprint.

Cite this