USENIX Security2026Top-tier venue
Secure Distributed RSA Modulus Generation Revisited: A Faster and More Communication-Efficient Construction
Shaojing Zhang, Chengliang Tian, Ruixue Wang, Hequn Xian, Guangwu Xu
Abstract
Securely generating an RSA modulus N = pq in a distributed n-party setting while keeping its factors private is a core challenge in threshold cryptography. This paper revisits this problem and improves the state-of-the-art distributed Miller-Rabin primality test by replacing its core component-the divisibility test-with a novel zero-testing protocol.
Our key innovation is an elegant distributed design of Montgomery reduction, which transforms checking δ mod f = 0 (given shares of δ and f ) into testing whether a product equals zero. This approach enables efficient distributed evaluation and offers: (1) Perfect correctness. Unlike prior approaches that are probabilistic or require impractically large shares, our zero test decides δ mod f = 0 deterministically. (2) Improved efficiency. Our zero test runs in only 7 rounds and uses 5 secure multiplications, improving over previous divisibility tests that require either 3 + log 2 n rounds with n + 3 multiplications or 8 rounds with 5n -1 multiplications. Extensive experiments under honest-majority settings show increasing speedups for n ≥ 9, with the efficiency advantage growing as the number of parties increases. Moreover, our semi-honest protocol supports both honest-and dishonest-majority settings via appropriate secure multiplication primitives, and can be upgraded to malicious security with standard compilers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Diogenes: Lightweight Scalable RSA Modulus Generation with a Dishonest MajorityMegan Chen, Carmit Hazay, Yuval Ishai, Yuriy Kashnikov et al.S&P 2021 · 52 citations
- Multiparty Generation of an RSA ModulusMegan Chen, Ran Cohen, Jack Doerner, Yashvanth Kondi et al.CRYPTO 2020 · 24 citations
- Improved Distributed RSA Key Generation Using the Miller-Rabin TestJakob Burkhardt, Ivan Damgård, Tore Kasper Frederiksen, Satrajit Ghosh et al.CCS 2023 · 10 citations
- The Return of Eratosthenes: Secure Generation of RSA Moduli using Distributed SievingCyprien Delpech de Saint Guilhem, Eleftheria Makri, Dragos Rotaru, Titouan TanguyCCS 2021 · 1 citation
Related papers
- VROOM: Accelerating (Almost All) Number-Theoretic Cryptography Using Vectorization and the Residue Number SystemSimon Langowski, Kaiwen He, Srinivas DevadasUSENIX Security 2026
- Accelerating Multi-Scalar Multiplication for Efficient Zero Knowledge Proofs with Multi-GPU SystemsZhuoran Ji, Zhiyuan Zhang, Jiming Xu, Lei JuASPLOS 2024 · 17 citations
- Powers of Tau in AsynchronySourav Das, Zhuolun Xiang, Ling RenNDSS 2024
- Integer Reasoning Modulo Different Constants in SMTElizaveta Pertseva, Alex Ozdemir, Shankara Pailoor, Alp Bassa et al.CAV 2025 · 1 citation
- Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPCAlexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou et al.USENIX Security 2026 · 1 citation
