Researchers demonstrate RSA signature forgery without factoring keys
publishers 6articles 6first reported 24 Sep, 11:15 UTCdeveloping since 24 Sep · 3 editions
Researchers have demonstrated a classical-computing technique that can forge RSA digital signatures without first factoring the public key’s modulus, challenging the long-held assumption that defeating RSA requires solving the underlying factoring problem.
According to Ars Technica, the researchers completed an attack against a deprecated 1,024-bit RSA key in several months using an academic CPU cluster. Estimates for factoring a key of that size have typically involved computing resources available only to large technology companies or national intelligence agencies, potentially costing tens of millions of dollars for a single key.
Nadia Heninger, a University of California, San Diego professor and co-author of the research, said the forgery method is practical for 1,024-bit RSA. The researchers also found that it lowers the security offered by 2,048- and 4,096-bit keys.
The immediate risk is limited: 1,024-bit RSA has been deprecated, and widely used RSA implementations are reported to be safe from the demonstrated attack. However, the method reduces the computing resources needed to attack affected RSA signatures by orders of magnitude.
Cryptography expert Karsten Nohl said the result would represent a conceptual breakthrough if it withstands peer review, because it provides a route to producing valid signatures without recovering the private key.
HOW THIS STORY WAS MADE
Written from 6 articles, 1 with the publisher's own text; 6 independent newsrooms once syndicated copies count as one; this version written 20 h after the record first saw the story; the editor revised it.
- Publishers
- 6
- Source articles
- 6
- Given to the writer
- 6, 1 with the article's own text
- Independent newsrooms
- 6
- This version written
- 20 h after the record first saw the story
- Second model (editor)
- revised
- Publication gate
- passed
- Human review
- none
Written by a language model from the sources above, then checked by a second model that may only cut, attribute or correct. How it works →