We show that if the private exponent d used in the RSA (Rivest-Shamir-Adleman (1978)) public-key cryptosystem is less than N 0.292 then the system is insecure. This is the first improvement over an old result of Wiener (1990) showing that when d is less than N0.25 the RSA system is insecure. We hope our approach can be used to eventually improve the bound to d less than N 0.5
Published in:
Information Theory, IEEE Transactions on
(Volume:46
,
Issue:
4
)
Date of Publication: Jul 2000