English

Decomposition of RSA modulus applying even order elliptic curves

Cryptography and Security 2025-03-04 v1 Number Theory

Abstract

An efficient integer factorization algorithm would reduce the security of all variants of the RSA cryptographic scheme to zero. Despite the passage of years, no method for efficiently factoring large semiprime numbers in a classical computational model has been discovered. In this paper, we demonstrate how a natural extension of the generalized approach to smoothness, combined with the separation of 22-adic point orders, leads us to propose a factoring algorithm that finds (conjecturally) the prime decomposition N=pqN = pq in subexponential time L(2+o(1),min(p,q))L(\sqrt 2+o(1), \min(p,q)). This approach motivated by the papers \cite{Len}, \cite{MMV} and \cite{PoZo} is based on a more careful investigation of pairs (E,Q)(E,Q), where QQ is a point on an elliptic curve EE over ZN\Z _N. Specifically, in contrast to the familiar condition that the largest prime divisor P+(\ordQp)P^+(\ord Q_p) of the reduced order \ordQp\ord Q_p does not divide #E(\Fq)\#E(\F_q) we focus on the relation between P+(\ordQr)P^+(\ord Q_r) and the smallest prime number lmin(E,Q)l_{\min}(E,Q) separating the orders \ordQp\ord Q_p and \ordQq\ord Q_q. We focus on the \calE2{\calE}_2 family of even order elliptic curves over ZN\Z_N since then the condition lmin(E,Q)2l_{\min}(E,Q)\le 2 holds true for large fraction of points (x,y)E(ZN)(x,y)\in E(\Z_N). Moreover if we know the pair (E,Q)(E,Q) such that P+(\ordQr)t<lmin(E,Q)P^+(\ord Q_r)\le t<l_{\min}(E,Q) and d=maxr{p,q}(\ordQr)d=\max_{r\in \{p,q\}}(\ord Q_r) is large in comparison to minr{p,q}ar(E)0\min_{r\in \{p,q\}}|a_r(E)|\neq 0 then we can decompose NN in deterministic time t1+o(1)t^{1+o(1)} by representing NN in base dd.

Keywords

Cite

@article{arxiv.2503.00950,
  title  = {Decomposition of RSA modulus applying even order elliptic curves},
  author = {Jacek Pomykała and Mariusz Jurkiewicz},
  journal= {arXiv preprint arXiv:2503.00950},
  year   = {2025}
}
R2 v1 2026-06-28T22:03:44.624Z