Ir para o conteúdo principal
UC San Diego researchers expose new RSA security risk
Image for illustrative purposes only. Not a real photo.

UC San Diego researchers expose new RSA security risk

Share
  • UC San Diego researchers demonstrated a way to forge 1024-bit RSA signatures without stealing the private key.
  • The attack required 1,380 CPU core-years and 2³² signing-oracle queries.
  • The findings challenge factoring-based RSA security estimates and support migration towards post-quantum cryptography.

UC San Diego and France’s INRIA researchers have demonstrated an RSA attack that can forge signatures without recovering the private key.

The attack targets systems exposing a raw RSA signing or decryption oracle.

The researchers completed the 1024-bit attack using 1,380 CPU core-years over five months.

The operation also required 2³² oracle queries before signatures could be forged offline.

The team used a hardware security module as the signing oracle during the experiment.

Most standard RSA implementations remain outside the attack’s practical scope because they use padding.

The researchers estimate RSA security could be 15 to 30 bits lower than factoring-based estimates.

The findings strengthen the case for moving from RSA towards post-quantum cryptographic systems.


Perguntas frequentes