Sun,Yang和Laih利用素因子p,q间的不平衡性提出了三类RSA变体以抵抗Wiener给出的连分式攻击和Boneh-Durfee的小解密指数攻击.本文通过构造一个新的双变元模方程及系数格,利用格基约化求小根的方法得到解密指数的界与加密指数和较小素因子之间的渐进关系,有效攻击了其中的两类RSA变体.
Sun, Yang and Laih proposed three RSA variants to resist all attacks including Wiener's continued fraction attack and Boneh-Durfee's short secret exponent attack using the unbalanced primes p and q. In this paper, we construct a new bivariate modular equation and coefficient lattice to obtain the asymptotic relationship between the bound of secret exponent and the prime. The research implies two out of the three variants could be attacked efficiently.