Attacks on RSA

Finding out someone's private d is probably as hard as factoring n.  But sometimes we can find out a particular message without breaking the general code.  Usually this is because e is too small --- small e makes the encrypting faster, but can weaken security.

Small message attack

[Graphics:Images/rsaA_gr_1.gif]
[Graphics:Images/rsaA_gr_2.gif]
[Graphics:Images/rsaA_gr_3.gif]
[Graphics:Images/rsaA_gr_4.gif]
[Graphics:Images/rsaA_gr_5.gif]
[Graphics:Images/rsaA_gr_6.gif]
[Graphics:Images/rsaA_gr_7.gif]
[Graphics:Images/rsaA_gr_8.gif]
[Graphics:Images/rsaA_gr_9.gif]
[Graphics:Images/rsaA_gr_10.gif]
[Graphics:Images/rsaA_gr_11.gif]
[Graphics:Images/rsaA_gr_12.gif]
[Graphics:Images/rsaA_gr_13.gif]
[Graphics:Images/rsaA_gr_14.gif]
[Graphics:Images/rsaA_gr_15.gif]
[Graphics:Images/rsaA_gr_16.gif]
[Graphics:Images/rsaA_gr_17.gif]
[Graphics:Images/rsaA_gr_18.gif]
[Graphics:Images/rsaA_gr_19.gif]
[Graphics:Images/rsaA_gr_20.gif]
[Graphics:Images/rsaA_gr_21.gif]
[Graphics:Images/rsaA_gr_22.gif]
[Graphics:Images/rsaA_gr_23.gif]
[Graphics:Images/rsaA_gr_24.gif]

Next Section


Converted by Mathematica      February 7, 2001