There's a new way to break RSA that's faster than anything we've seen before
摘要
研究人员提出一种利用经典计算攻击RSA的新方法,可将现有RSA安全强度降至不可接受的低水平。该发现短期内几乎不构成实际威胁,仅可能影响少数边缘场景;即便针对已弃用的1024位密钥,所需算力也极高,常见RSA实现仍安全。但该研究令密码学家意外,因为它引入了不依赖因子分解的签名伪造新途径,并将所需计算资源降低数个数量级。
The world has known for decades that the RSA cryptosystem’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold.
The finding poses little to no practical threat in the immediate term, except possibly in a few edge cases. Even applying the attack against the deprecated use of 1024-bit keys, the method requires more computation than just about anybody—short of nation-states or companies with massive resources—can achieve. Widely used RSA implementations are also safe.
Nonetheless, the research has taken cryptographers by surprise because it introduces signature forgery, a new way to break RSA keys without factoring. Equally important, this novel method reduces the required computing resources by orders of magnitude.
转载信息
评论 (0)
暂无评论,来留下第一条评论吧