Advances in Cryptology — EUROCRYPT ’96

Volume 1070 of the series Lecture Notes in Computer Science pp 1-9


Low-Exponent RSA with Related Messages

  • Don CoppersmithAffiliated withIBM Research
  • , Matthew FranklinAffiliated withAT&T Research
  • , Jacques PatarinAffiliated withCP8 Transac
  • , Michael ReiterAffiliated withAT&T Research


In this paper we present a new class of attacks against RSA with low encrypting exponent. The attacks enable the recovery of plain- text messages from their ciphertexts and a known polynomial relationship among the messages, provided that the ciphertexts were created using the same RSA public key with low encrypting exponent.