
Cryptographers have identified a new attack against RSA encryption that operates through signature forgery rather than the traditional factoring method. The novel approach uses a variant of the number field sieve algorithm, a technique initially developed in 2007, combined with properties of certain cryptographic protocols to gather sufficient information for deciphering ciphertext.
When applied to 1024-bit RSA keys, the attack required approximately 265 operations and 1,380 core-years of computation on an academic CPU cluster over a span of months. This represents a dramatic reduction compared to traditional factoring estimates, which would necessitate around 280 operations and 500,000 to 1 million CPU core-years. The security levels for 1024-bit, 2048-bit, and 4096-bit keys drop to 265, 290, and 2119 respectively under this method, all falling below the 128-bit minimum threshold established by security agencies including the NSA and NIST.
The practical threat remains limited since the attack functions only against blind-signature RSA implementations rather than the PKCS or PSS padded formats used in most deployed systems. However, some real-world protocols including Privacy Pass, which is used by Apple and Cloudflare, employ the vulnerable textbook RSA approach. An attack on Privacy Pass would require approximately 243 token requests, a volume comparable to daily network traffic levels that major platforms handle routinely. Regular key rotation at implementation sites provides additional protection, though it does not entirely eliminate attack risks.
Researchers emphasized that the findings, pending peer review, represent a conceptual breakthrough in cryptanalysis. The discovery that RSA security can be undermined through methods beyond factorization has intensified focus on transitioning to post-quantum cryptographic alternatives. The attack’s efficiency could potentially improve further since the research team performed all computations manually without utilizing artificial intelligence or GPU acceleration.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI