Academia.eduAcademia.edu

Continued fractions and RSA with small secret exponent

2004, arXiv (Cornell University)

Abstract

Extending the classical Legendre's result, we describe all solutions of the inequality |α -a/b| < c/b 2 in terms of convergents of continued fraction expansion of α. Namely, we show that a/b = (rpm+1 ± spm)/(rqm+1 ± sqm) for some nonnegative integers m, r, s such that rs < 2c. As an application of this result, we describe a modification of Verheul and van Tilborg variant of Wiener's attack on RSA cryptosystem with small secret exponent.