Small primitive roots and malleability of RSA moduli
classification
🧮 math.NT
keywords
conjecturemalleabilitymodulusalgorithmallowedauxiliarybelieveconcrete
read the original abstract
In a paper of P. Paillier and J. Villar a conjecture is made about the malleability of an RSA modulus. In this paper we present an explicit algorithm refuting the conjecture. Concretely we can factorize an RSA modulus n using very little information on the factorization of a concrete n' coprime to n. However, we believe the conjecture might be true, when imposing some extra conditions on the auxiliary n' allowed to be used. In particular, the paper shows how subtle the notion of malleability is.
This paper has not been read by Pith yet.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.