On the uniformity of distribution of the decryption exponent in fixed encryption exponent RSA

Igor E. Shparlinski*

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

1 Citation (Scopus)

Abstract

Let us fix a security parameter n and a sufficiently large encryption exponent e. We show that for a random choice of the RSA modulus m = pq, where p and q are n-bit primes, the decryption exponent d, defined by ed ≡ 1 (mod φ(m)) is uniformly distributed modulo φ(m). It is known, due to recent work of Boneh, Durfee and Frankel, that additional information about some bits of d may turn out to be dramatic for the security of the whole cryptosystem. Our uniformity of distribution result implies that sufficiently long strings of the most and the least significant bits of d, which are vulnerable to such attacks, behave as random binary vectors.

Original languageEnglish
Pages (from-to)143-147
Number of pages5
JournalInformation Processing Letters
Volume92
Issue number3
DOIs
Publication statusPublished - 15 Nov 2004

Fingerprint

Dive into the research topics of 'On the uniformity of distribution of the decryption exponent in fixed encryption exponent RSA'. Together they form a unique fingerprint.

Cite this