## CryptoDB

### Paper: Small CRT-Exponent RSA Revisited

Authors: Atsushi Takayasu Yao Lu Liqiang Peng DOI: 10.1007/s00145-018-9282-3 Search ePrint Search Google Since May (Crypto’02) revealed the vulnerability of the small CRT-exponent RSA using Coppersmith’s lattice-based method, several papers have studied the problem and two major improvements have been made. (1) Bleichenbacher and May (PKC’06) proposed an attack for small $d_q$ d q when the prime factor p is significantly smaller than the other prime factor q ; the attack works for p
