English

Small primitive roots and malleability of RSA moduli

Number Theory 2008-01-03 v1

Abstract

In a paper of P. Paillier and J. Villar a conjecture is made about the malleability of an RSA modulus. In this paper we present an explicit algorithm refuting the conjecture. Concretely we can factorize an RSA modulus n using very little information on the factorization of a concrete n' coprime to n. However, we believe the conjecture might be true, when imposing some extra conditions on the auxiliary n' allowed to be used. In particular, the paper shows how subtle the notion of malleability is.

Cite

@article{arxiv.0801.0030,
  title  = {Small primitive roots and malleability of RSA moduli},
  author = {Luis Dieulefait and Jorge Jimenez Urroz},
  journal= {arXiv preprint arXiv:0801.0030},
  year   = {2008}
}
R2 v1 2026-06-21T09:58:13.200Z