Really Secure Algorithm

Wiener's attack on RSA

Problem

I like my e's like I like my trucks: big and obnoxious

Author: trashcanna

Solution

Recall that e is chosen such that

ed=1(modlcm(p1,q1))ed=1\pmod{\text{lcm}(p-1, q-1)}

In this case, e is really large (only one order of magnitude smaller than n). This suggests that d might be small. When d is small, Wiener's attack would work.

Last updated

Was this helpful?