Multiparty Generation of an RSA Modulus
Megan Chen, Ran Cohen, Jack Doerner, Yashvanth Kondi, Eysa Lee, Schuyler Rosefield, Abhi Shelat
Abstract
We present a new multiparty protocol for the distributed generation of biprime RSA moduli, with security against any subset of maliciously colluding parties assuming oblivious transfer and the hardness of factoring.
Our protocol is highly modular, and its uppermost layer can be viewed as a template that generalizes the structure of prior works and leads to a simpler security proof. We introduce a combined sampling-and-sieving technique that eliminates both the inherent leakage in the approach of Frederiksen et al. (Crypto'18), and the dependence upon additively homomorphic encryption in the approach of Hazay et al. (JCrypt'19). We combine this technique with an efficient, privacy-free check to detect malicious behavior retroactively when a sampled candidate is not a biprime, and thereby overcome covert rejection-sampling attacks and achieve both asymptotic and concrete efficiency improvements over the previous state of the art.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bc67a882-a91a-4080-817b-063232f1441aCited by top-tier papers8
- Threshold Schnorr with Stateless Deterministic Signing from Standard AssumptionsFrançois Garillot, Yashvanth Kondi, Payman Mohassel, Valeria NikolaenkoCRYPTO 2021 · 39 citations
- Practical Statistically-Sound Proofs of Exponentiation in Any GroupCharlotte Hoffmann, Pavel Hubácek, Chethan Kamath, Karen Klein et al.CRYPTO 2022 · 14 citations
- Pixel+ and Pixel++: Compact and Efficient Forward-Secure Multi-Signatures for PoS Blockchain ConsensusJianghong Wei, Guohua Tian, Ding Wang, Fuchun Guo et al.USENIX Security 2024 · 9 citations
- Cryptanalysis of Algebraic Verifiable Delay FunctionsAlex Biryukov, Ben Fisch, Gottfried Herold, Dmitry Khovratovich et al.CRYPTO 2024 · 7 citations
- Efficient CCA Timed Commitments in Class GroupsSri Aravinda Krishnan Thyagarajan, Guilhem Castagnos, Fabien Laguillaumie, Giulio MalavoltaCCS 2021 · 2 citations
Related papers
- The Return of Eratosthenes: Secure Generation of RSA Moduli using Distributed SievingCyprien Delpech de Saint Guilhem, Eleftheria Makri, Dragos Rotaru, Titouan TanguyCCS 2021 · 1 citation
- Diogenes: Lightweight Scalable RSA Modulus Generation with a Dishonest MajorityMegan Chen, Carmit Hazay, Yuval Ishai, Yuriy Kashnikov et al.S&P 2021 · 52 citations
- Secure Distributed RSA Modulus Generation Revisited: A Faster and More Communication-Efficient ConstructionShaojing Zhang, Chengliang Tian, Ruixue Wang, Hequn Xian et al.USENIX Security 2026
- Improved Distributed RSA Key Generation Using the Miller-Rabin TestJakob Burkhardt, Ivan Damgård, Tore Kasper Frederiksen, Satrajit Ghosh et al.CCS 2023 · 10 citations
- Reverse Firewalls for Oblivious Transfer Extension and Applications to Zero-KnowledgeSuvradip Chakraborty, Chaya Ganesh, Pratik SarkarEUROCRYPT 2023 · 11 citations
