Cryptanalysis of RSA Factorization - Library(ISI Kolkata) - Indian ...
Cryptanalysis of RSA Factorization - Library(ISI Kolkata) - Indian ...
Cryptanalysis of RSA Factorization - Library(ISI Kolkata) - Indian ...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Chapter 7: Approximate Integer Common Divisor Problem 132<br />
Then<br />
P 2 = X m3 τ 2 +m 3 τ+ m3 τ 3 +o(m 3) 3 , and<br />
ω = m2<br />
2 +m2 τ + m2 τ 2<br />
+o(m 2 ).<br />
2<br />
Neglecting the o(m 3 ) terms, the required condition det(L) < p mω<br />
1 implies<br />
( 1<br />
3 +τ2 +τ +<br />
)(α+β)+ τ3 1 ( ) 1<br />
3 6 < (1−α) τ2<br />
+τ +<br />
2 2<br />
which simplifies to the following<br />
(<br />
− τ3 3α<br />
3 (α+β)−τ2 2 +β − 1 )<br />
−τ(2α+β −1)− 5α 2 6 − β β + 1 3<br />
> 0. (7.19)<br />
To maximize β for a fixed α, the optimal value <strong>of</strong> τ is 1−2α−β . Putting this optimal<br />
α+β<br />
value<strong>of</strong>τ in(7.19), wegettherequiredconditionas−α 3 +2α 2 −2αβ−β 2 −3α+1 ><br />
0, i.e.,<br />
β < √ 1−3α+3α 2 −α 3 −α.<br />
As τ ≥ 0, we also need the constraint 2α+β ≤ 1. Then under Assumption 1 (as<br />
the polynomials are <strong>of</strong> two variables), we can collect the roots successfully.<br />
In Theorem 6.9 <strong>of</strong> Chapter 6, it has been explained that factorization <strong>of</strong><br />
N 1 ,N 2 ,N 3 will be successful when β < 0.8 − 2α. In our case, the upper bound<br />
<strong>of</strong> β is √ 1−3α+3α 2 −α 3 −α. Now, 0.8−2α < √ 1−3α+3α 2 −α 3 −α when<br />
α < 0.55. Hence, our upper bound on β will be greater than that <strong>of</strong> Theorem 6.9.<br />
7.5 Sublattice and Generalized Bound<br />
In this section, we study a sublattice L ′ <strong>of</strong> the lattice L explained in the previous<br />
section. This helps in two ways as follows.<br />
• The dimension <strong>of</strong> the sublattice L ′ is less than that <strong>of</strong> L and this helps in<br />
actual experiments.<br />
• The theoretical analysis helps us to get a generalized bound for β.