# Journal of Mathematical Cryptology

Volume 11, Issue 2 (Jun 2017)

# Cryptanalysis of an RSA variant with moduli N=prql

Yao Lu
/ Liqiang Peng
/ Santanu Sarkar
Published Online: 2017-05-16 | DOI: https://doi.org/10.1515/jmc-2016-0025

## Abstract

In this paper we study an RSA variant with moduli of the form $N={p}^{r}{q}^{l}$ ($r>l\ge 2$). This variant was mentioned by Boneh, Durfee and Howgrave-Graham [2]. Later Lim, Kim, Yie and Lee [11] showed that this variant is much faster than the standard RSA moduli in the step of decryption procedure. There are two proposals of RSA variants when $N={p}^{r}{q}^{l}$. In the first proposal, the encryption exponent e and the decryption exponent d satisfy $ed\equiv 1mod{p}^{r-1}{q}^{l-1}\left(p-1\right)\left(q-1\right)$, whereas in the second proposal $ed\equiv 1mod\left(p-1\right)\left(q-1\right)$. We prove that for the first case if $d<{N}^{1-\left(3r+l\right){\left(r+l\right)}^{-2}}$, one can factor N in polynomial time. We also show that polynomial time factorization is possible if $d<{N}^{\left(7-2\sqrt{7}\right)/\left(3\left(r+l\right)\right)}$ for the second case. Finally, we study the case when few bits of one prime are known to the attacker for this variant of RSA. We show that given $\mathrm{min}\left(\frac{l}{r+l},\frac{2\left(r-l\right)}{r+l}\right){\mathrm{log}}_{2}p$ least significant bits of one prime, one can factor N in polynomial time.

Keywords: Coppersmith’s method; lattices; RSA; RSA variants

MSC 2010: 94A60

Revised: 2017-01-18

Accepted: 2017-04-23

Published Online: 2017-05-16

Published in Print: 2017-06-01

Funding Source: National Natural Science Foundation of China

Award identifier / Grant number: 61472417

Yao Lu is supported by Project CREST, JST and Liqiang Peng is supported by the National Key Basic Research Program of China (Grant 2013CB834203) and the National Natural Science Foundation of China (Grant 61472417).

Citation Information: Journal of Mathematical Cryptology, ISSN (Online) 1862-2984, ISSN (Print) 1862-2976,

© 2017 Walter de Gruyter GmbH, Berlin/Boston.