Academic
Publications
A TimingResistant Elliptic Curve Backdoor in RSA
A TimingResistant Elliptic Curve Backdoor in RSA,10.1007/9783540794998_33,Adam L. Young,Moti Yung
A TimingResistant Elliptic Curve Backdoor in RSA
Citations: 1
Citations: 1
Adam L. Young
,
Moti Yung
We present a
fast algorithm
for finding pairs of backdoor RSA primes (p,q) given a security parameter. Such pairs posses an asymmetric backdoor that gives the designer the exclusive ability to factor n = pq, even when the key generation algorithm is public. Our algorithm uses a pair of twisted curves over GF(2257) and we present the first incremental
search method
to generate such primes. The search causes the \frac12\frac{1}{2} log(n)+O(log(log(n))) least significant bits of n to be modified during key generation after p is selected and before q is determined. However, we show that this is tolerable by using point compression and ECDH. We also present the first rigorous experimental benchmarks of an RSA asymmetric backdoor and show that our OpenSSLbased implementation outperforms OpenSSL RSA key generation. Our application is highly efficient key recovery. Of independent interest, we motivate the need to find large binary twists. We present the twist we generated and how we found it.
Conference:
Conference on Information Security and Cryptology  Inscrypt
, pp. 427441, 2007
DOI:
10.1007/9783540794998_33
Simple Backdoors on RSA Modulus by Using RSA Vulnerability
(
Citations: 1
)
HungMin Sun
,
MuEn Wu
,
ChengTa Yang
Journal:
Ieice Transactions  IEICE
, vol. 92A, no. 9, pp. 23262332, 2009