• Tidak ada hasil yang ditemukan

Index of /rsasecurity

N/A
N/A
Protected

Academic year: 2017

Membagikan "Index of /rsasecurity"

Copied!
1
0
0

Teks penuh

(1)

Errata to "High-Speed RSA Implementation"

November 14, 2005

This note updates RSA Laboratories’ Technical Note TR-201, “High-Speed RSA Implementation,” by Çetin Kaya Koç, Version 2.0, November 1994.

Issue: On page 4, the proof that Cd = (Me)d (mod n) when gcd(M, n) > 1 is

incorrect. In particular, the claim that Mλ(n) = 1 (mod n) in this case is incorrect.

Resolution: Replace the text from “The exception …” through the end of the paragraph with the following:

The exception gcd(M, n) > 1 can be dealt with as follows. Let g = gcd(M,

n) and let h = n/g. Since n is a product of distinct primes, g and h will be relatively prime. Now consider the values

C1 = (Me)d mod g ,

C2 = (Me)d mod h .

Since M is divisible by g, we have C1 ≡ 0 mod g.

Since M is relatively prime to h, we can apply the general case recursively to show that C2 ≡ M mod h.

Referensi

Dokumen terkait

The timing attacks potentially affect the imple mentations of the RSA and DSA algorithms in BSAFE and RSAREF, which, like many other imple- mentations, are optimized for

In particular, the algorithm consists of three parts: (1) a gathering of data stage, (2) a solu- tion of a matrix to find dependencies among the data, and (3) the use of

In reality there would be a large additional cost for the fast interconnection network needed for the tightly coupled parallel machine used to solve the matrix, but we ignore

The design and properties of HMAC are such that Dobbertin’s current techniques that might find collisions for either the compression function or the full hash function of MD5 seem

The Rank 6x8 matrix test uses six random 32-bit integers from the test sequence, a specified 8-bit byte is chosen, and the resulting six bytes form a 6x8 bi- nary matrix whose rank

However, there are also adaptive algorithms which partition the exponent into a series of zero and nonzero words in order to decrease the number multiplications required in Step 4b

All shift register based schemes try to exploit the good characteristics of sequences generated using linear feedback shift registers in such a way that the new sequences are

In addition to Keon Certificate Server , the suite includes Keon Security Server for centralized security administration, user management and access control; Keon Desktop