## Further Attacks on Server-Aided RSA Cryptosystems (1998)

by James Mckee , Richard Pinch Citations: 6 - 1 self### BibTeX

. Lim and Lee [5] describe protocols for server-aided RSA digital signatures involving moduli N with special structure: N = pq where p and q are both of order N 1=2 , and p \Gamma 1 and q \Gamma 1 have a large common factor fi. We describe a method to factor such numbers in time O \Gamma N 1=4 =fi \Delta and show that this renders the proposed system insecure. 1. Introduction Lim and Lee [5] describe protocols for server-aided RSA digital signatures involving moduli N with special structure: N = pq where p \Gamma 1 and q \Gamma 1 have a large common factor fi. As usual, p and q are both of order N 1=2 . The authors claim that "there exists no known algorithm for factoring N (for jN j 512) with knowledge of fi of size 64 80." We shall show that this claim is incorrect: we describe a method to factor such numbers in time O \Gamma N 1=4 =fi \Delta which renders the proposed system insecure. 2. The proposed cryptosystem Lim and Lee [5] discuss server-aided RSA signat...

