New research has uncovered a method that uses traditional, classical computing to significantly weaken the security of the RSA cryptosystem, a widely used encryption standard. This method reduces the level of security to a point that is considered unacceptably low, although the practical threat it poses is currently minimal for most users. The technique would only be feasible for a few edge cases, and even then, it would require more computational power than most individuals or organizations can afford—though it might be achievable by large governments or corporations with vast resources.
The research is notable because it introduces a new way to break RSA keys without factoring them, a process that has long been considered the only way to compromise RSA encryption. This method, known as signature forgery, allows attackers to create valid digital signatures without needing to determine the private key first. This approach drastically reduces the computational resources required to attack RSA encryption, making it more efficient than previously believed.
Karsten Nohl, a cryptography expert and head of innovation at Allurity, emphasized the significance of the findings. He stated that if the research holds up under peer review, it would represent a conceptual breakthrough. "RSA is as difficult to break as it is to factor large integers, at least so we thought," Nohl said. The researcher behind the study suggests that it's now possible to practically break RSA without cracking its key, challenging long-held assumptions about the system's security.
Nadia Heninger, a professor at the University of California at San Diego and lead author of the study, explained that cryptographers previously believed the only way to generate valid RSA digital signatures was to first factor the key, which is computationally expensive. For 1024-bit RSA keys, this was thought to be possible for entities with substantial resources, such as large tech companies or the NSA. However, the new method significantly lowers the computational barrier, making the attack on 1024-bit RSA more feasible than previously estimated. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to levels that are considered unacceptable by standards set by agencies like the National Security Agency and the National Institute of Standards and Technology, which require a minimum of 128 bits of security.
New Research Challenges RSA Cryptosystem's Security Assumptions
AI-rewritten from original reportingHow it works
rsacryptographysecuritycomputingresearchencryption



