Annual International Cryptology Conference

CRYPTO 2004: Advances in Cryptology – CRYPTO 2004 pp 213-219

Computing the RSA Secret Key Is Deterministic Polynomial Time Equivalent to Factoring

  • Alexander May
Conference paper

DOI: 10.1007/978-3-540-28628-8_13

Volume 3152 of the book series Lecture Notes in Computer Science (LNCS)


We address one of the most fundamental problems concerning the RSA cryptoscheme: Does the knowledge of the RSA public key/ secret key pair (e,d) yield the factorization of N=pq in polynomial time? It is well-known that there is a probabilistic polynomial time algorithm that on input (N,e,d) outputs the factors p and q. We present the first deterministic polynomial time algorithm that factors N provided that e,d < φ(N) and that the factors p, q are of the same bit-size. Our approach is an application of Coppersmith’s technique for finding small roots of bivariate integer polynomials.


RSACoppersmith’s method
Download to read the full conference paper text

Copyright information

© Springer-Verlag Berlin Heidelberg 2004

Authors and Affiliations

  • Alexander May
    • 1
  1. 1.Faculty of Computer Science, Electrical Engineering and MathematicsUniversity of PaderbornPaderbornGermany