International Conference on the Theory and Applications of Cryptographic Techniques

EUROCRYPT 1998: Advances in Cryptology — EUROCRYPT'98 pp 59-71

Breaking RSA may not be equivalent to factoring

Extended abstract
  • Dan Boneh
  • Ramarathnam Venkatesan
Conference paper

DOI: 10.1007/BFb0054117

Volume 1403 of the book series Lecture Notes in Computer Science (LNCS)


We provide evidence that breaking low-exponent RSA cannot be equivalent to factoring integers. We show that an algebraic reduction from factoring to breaking low-exponent RSA can be converted into an efficient factoring algorithm. Thus, in effect an oracle for breaking RSA does not help in factoring integers. Our result suggests an explanation for the lack of progress in proving that breaking rsa is equivalent to factoring. We emphasize that our results do not expose any specific weakness in the rsa system.


RSAFactoringStraight line programsAlgebraic circuits
Download to read the full conference paper text

Copyright information

© Springer-Verlag 1998

Authors and Affiliations

  • Dan Boneh
    • 1
  • Ramarathnam Venkatesan
    • 2
  1. 1.Computer Science Dept.Stanford UniversityUSA
  2. 2.Microsoft ResearchUSA