Multi-party RSA with Small e
Assuming e is constant between the messages and the message m is sent to at least e people, we can use the Chinese Remainder Theorem to retrieve m.
In single-party RSA, we calculate c=memodN. Let's pretend this is extrapolated to 3 people:
me=c1modN1me=c2modN2me=c3modN3
The Chinese Remainder Theorem allows us to solve this congruence modN1N2N3. Since m<minN1,N2,N3, we know that me<N1N2N3. Once we use the Chinese Remainder Theorem to compute memodN1N2N3, we just take the eth root to retrieve m.
Last updated
Was this helpful?