The better bound of private key in RSA with unbalanced primes

Hyun Soo Hong, Ho Kyu Lee, Hyang Sook Lee, Hee Jung Lee

At Asiacrypt '99, Sun, Yang and Laih proposed three different schemes of RSA cryptosystem to avoid all known attacks including Boneh-Durfee attack. One year after, Durfee and Nguyen attacked two out of these three schemes based on Coppersmith's lattice technique for finding small roots to trivariate modular polynomial equations. The bounds of private key for the first and third schemes were much improved, but the bound of the second scheme was not good enough. Our result improves Durfee and Nguyen's bound of the private exponent d from N0.483 to N0.486 for the second scheme. This implies the system is insecure if the private exponent d<N0.486.

Original languageEnglish
Pages (from-to)351-362
Number of pages12
JournalApplied Mathematics and Computation
Issue number2-3
StatePublished - 15 Jul 2003


  • Coppersmith's technique
  • Geometrically progressive matrices
  • Lattice reduction
  • Multivariate modular equations
  • RSA attack


