| BL OMER, J.---MAY, A.: Low secret exponent RSA revisited, Cryptography and Lattice - Proceedings of CaLC |
....) e ) e ) and 2 ) Thus, lim m 1 vol(L BD (m; t) 1 and lim m 1 e = 2 ) 0, so (4.9) cannot be satis ed for any , as m gets large. Hence, the bound on is incorrect. This oversight is unfortunate, as ignoring the contribution from 2 seems to be common [BD00, BM01, DN00]. Finding corresponding values for m and t that allow for the largest in (4.9) is a dicult problem, as (4.9) is nonlinear, and N are variables, and we require m 1 and t 0 to be integers. To estimate an upper bound for , with various xed values N and we numerically optimized (4.9) for m ....
....volume inequality (with = 1) is not satis ed. Nevertheless, since max becomes larger for smaller values of , the attacks still can be successfully mounted in speci c applications. 4.2.4. The Bl omer May Lattice. Another extension of the Boneh Durfee lattice is given by Bl omer and May [BM01]. Again, certain rows of BBD (m; t) are removed that contribute too much to the volume. But now also certain columns are removed, to ensure that the new basis has full rank and the matrix is triangular. Bl omer and May nd that max = 0:290. Unfortunately, they too ignore the term 2 , so ....
J. Blomer and A. May. Low secret exponent RSA revisited. In Cryptography and Lattices - Proceedings of CALC '01, volume 2146 of LNCS, pages 4-19. Springer-Verlag, 2001.
No context found.
BL OMER, J.---MAY, A.: Low secret exponent RSA revisited, Cryptography and Lattice - Proceedings of CaLC
No context found.
BL OMER, J.---MAY, A.: Low secret exponent RSA revisited, Cryptography and Lattice - Proceedings of CaLC
No context found.
BL OMER, J.---MAY, A.: Low secret exponent RSA revisited, Cryptography and Lattice - Proceedings of CaLC
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC