Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1h ago ·

Researchers Forge 1024-Bit RSA Signatures Without Factoring the Key

The result says RSA's security can sit below the cost estimates drawn from general number field sieving when an attacker has raw signing access, which puts hardware security modules that return unpadded signatures inside the threat model rather than outside it.

Reporting from 1 source: GIGAZINE.

Researchers Forge 1024-Bit RSA Signatures Without Factoring the Key

A University of California, San Diego and Inria team ran a large-scale experiment using an algorithm called sqrt-e NFS, a Number Field Sieve variant proposed in 2007 and implemented publicly here. Targetting 1024-bit RSA, the attack never factors the public key. It needs an oracle that returns raw RSA operations. Precomputation took about 1,200 CPU core-years, plus 2^32 oracle queries; total cost was roughly 1,380 CPU core-years over about five months.

The attack does not recover the private key. It acquires the ability to produce arbitrary signatures offline and keeps it after oracle access ends. That is the part worth sitting with: the private key stays inside the hardware security module the whole time, and the signatures still come out forged. What the method exploits is the module's willingness to hand back raw, unpadded RSA results on request. The algorithm is still sub-exponential, so key size still buys real distance. It is just a shorter distance than a general number field sieve estimate implies.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources