RSA password decomposition method and system based on factor search

By performing densification transformation of the integer interval [1,N-1], a set of integers on two-dimensional rectangular grid points is formed, and local search is performed using the upper right and lower left search directions, the problem of inefficiency of the existing RSA cryptographic decomposition method is solved, and the rapid decomposition of large integers is achieved.

CN120238307APending Publication Date: 2025-07-01FOSHAN UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510374585.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing RSA cipher decomposition method is still very low for large integer decomposition efficiency, and it is impossible to quickly search the factor of RSA modulus.

Method used

A RSA cryptographic decomposition method based on factor search is proposed. By performing densification transformation of integer intervals [1,N-1], a set of integers corresponding to the two-dimensional rectangular grid points is obtained. Each row and each column of the collection contain integers with p and q as factors, forming a distribution line. Using the search direction of the upper right and lower left, a local search area is built to search the collection, calculate the maximum common factor of the searched elements and N, and realize the decomposition of N.

Benefits of technology

Through this method, the factor of the RSA modulus N can be quickly obtained, and the factor of an RSA number can be effectively searched, which improves the efficiency of large integer decomposition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238307A_ABST
    Figure CN120238307A_ABST
Patent Text Reader

Abstract

The invention discloses an RSA password decomposition method and system based on factor search. The method comprises the steps that parameters are defined; generating a rectangular area according to a preset rule and calculating the center of the rectangular area; selecting a search starting point near the center of the rectangular area; according to the parameter calculation, determining a search direction; calculating the side length and the number of small squares to be searched, constructing small square areas with the side length in batches in combination with the search starting point and the search direction, circularly and randomly selecting the small squares by using an LCG sampling method, searching an element h of the small squares, and calculating res = gcd (h, N) until resgt; 1, completing the task; the system comprises a memory and a processor used for executing the RSA password decomposition method based on the factor search. By using the method and the device, the factor of one RSA number can be effectively searched, and the development of an RSA password system is facilitated. The method can be widely applied to the technical field of cryptography.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cryptography, and in particular to an RSA cryptography decomposition method and system based on factor search. Background Art

[0002] The RSA cryptosystem is a widely used public-key encryption algorithm, and its security is based on the difficulty of the prime factorization problem of large integers. The RSA public-key cryptography algorithm is one of the globally famous public-key cryptography algorithm standards, which includes a digital signature algorithm and a public-key encryption algorithm. At present, the RSA public-key cryptography algorithm has been widely used in fields such as Internet communication, e-commerce, and identity authentication.

[0003] The essence of RSA cryptography decomposition is a kind of integer decomposition. Given a standard RSA modulus N, N = pq, where both p and q are odd prime numbers satisfying p < q < 2p. The trial division method is the simplest decomposition method, but for large integers (such as N with 1024 bits or 2048 bits), the computational amount is too large and completely unrealistic. Currently, the commonly used decomposition methods still have very low decomposition efficiency for large integers. Summary of the Invention

[0004] In view of this, in order to solve the technical problem that a factor of an RSA modulus cannot be quickly searched in the existing cryptography decomposition methods, in a first aspect, the present invention proposes an RSA cryptography decomposition method based on factor search, and the method includes the following steps:

[0005] S1. Define the modulus N, the encryption repetition degree g, and the efficiency index η;

[0006] S2. Calculate and the main search direction

[0007] S3. Generate a rectangular area according to a preset rule and calculate the center of the rectangular area:

[0008] S4. Calculate the side length and the number of small square areas:

[0009] S5. Represent n in the form of 2 M K + R;

[0010] S6. Randomly select a search starting point near the center of the rectangular area;

[0011] S7. Randomly select a specific search direction d in the main search direction: upper right or lower left;

[0012] S8. Construct a small square with side length e and centered at the search starting point, and search for its element h, and calculate res = gcd(h, N);

[0013] S9. If res > 1, the task is completed;

[0014] S10. Otherwise, continue to construct R small squares in the direction of d and sequentially search for element h, and calculate res = gcd(h, N); if res > 1, the task is completed;

[0015] S11. If not found, loop K times: continuously construct 2 M small squares in the direction of d; randomly select a small square using the LCG sampling method; search for element h of the selected small square, and calculate res = gcd(h, N); if res > 1, the task is completed; otherwise, continue to loop.

[0016] In some embodiments, the preset rule in step S2 is specifically:

[0017] According to Calculate integers inside a rectangle with a width of (N - p u ) and a length of (g(2p u - p b - N - 1) + 1);

[0018] X and Y in the above calculation formula correspond to the row and column changes of the rectangle, where X changes N - p u rows and Y changes g(2p u - p b - N - 1) + 1 columns, forming a rectangular area.

[0019] The present invention also proposes an RSA cryptography decomposition system based on factor search, including:

[0020] At least one processor;

[0021] At least one memory for storing at least one program;

[0022] When the at least one program is executed by the at least one processor, the at least one processor implements the above - mentioned RSA cryptography decomposition method based on factor search.

[0023] Based on the above solution, the present invention provides an RSA cryptographic decomposition method and system based on factor search. Through a densification transformation of the integer interval [1, N - 1], an integer set (aggregate) corresponding to the two-dimensional rectangular lattice points is obtained; each row and each column of this aggregate contains integers with p and q as factors, and is densely distributed in multiple positions from the upper left to the lower right, forming distribution lines. Search the aggregate by constructing a local search small area in the direction from the upper right to the lower left, and calculate the greatest common divisor of the searched elements and N, then p or q can be obtained relatively quickly to achieve the decomposition of N. The aggregate and the search method thereon invented by the present invention can effectively search for the factors of an RSA number. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 is the N - S flowchart of an RSA cryptographic decomposition method based on factor search according to the present invention;

[0025] Figure 2 is a schematic diagram of the rectangular area Π and the coordinate system obtained in the specific embodiment of the present invention with N = 35 and g = 2;

[0026] Figure 3 is a schematic diagram of the distribution of host numbers and non - host numbers in Π obtained in the specific embodiment of the present invention with N = 35 and g = 2;

[0027] Figure 4 is a schematic diagram of the distribution of host numbers and non - host numbers in Π obtained in the specific embodiment of the present invention with N = 35 and g = 4;

[0028] Figure 5 is a schematic diagram of the small area on Π and the host numbers therein in the specific embodiment of the present invention;

[0029] Figure 6 is a schematic diagram of a complete partition on Π in the specific embodiment of the present invention;

[0030] Figure 7 is a schematic diagram of the distribution direction of host numbers in Π and the proposed search direction in the specific embodiment of the present invention;

[0031] Figure 8 is a schematic diagram that the search path in the specific embodiment does not exceed any right - angled side of a right - angled triangle;

[0032] Figure 9 is a schematic diagram of the left - hand part of Π obtained in the specific embodiment of the present invention with N = 77 and g = 2;

[0033] Figure 10 is a schematic diagram of the host number distribution and search direction in the specific embodiment of the present invention with N = 77 and g = 2. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0035] It should be noted that for the convenience of description, only the parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0036] It should be understood that the "system", "unit" and / or "module" used in the present application is a method for distinguishing different components, elements, parts, portions or assemblies at different levels. However, if other words can achieve the same purpose, the word can be replaced by other expressions.

[0037] As shown in the present application and the claims, unless the context clearly indicates an exception, words such as "a", "an", "one" and / or "the" are not specifically singular and may also include the plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of the clearly identified steps and elements, and these steps and elements do not constitute an exclusive list. The method or device may also include other steps or elements. An element defined by the statement "comprising one..." does not exclude the existence of another identical element in the process, method, commodity or device including the element.

[0038] In the description of the embodiments of the present application, "a plurality" means two or more than two. The following terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.

[0039] In addition, flowcharts are used in the present application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the previous or subsequent operations do not necessarily need to be executed precisely in sequence. On the contrary, the operations can be executed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several steps of operations can be removed from these processes.

[0040] Refer to Figure 1 , which is a schematic flowchart of an optional example of the RSA cryptography decomposition method based on factor search proposed by the present invention. This method can be applied to computer devices. The decomposition method proposed in this embodiment may include but is not limited to the following steps:

[0041] S1. Define the modulus N, the densification repetition degree g, and the efficiency index η;

[0042] Among them, the densification repetition degree g: The integer x appears continuously and adjacent to each other g times in an integer set. For example, in the set {1, 2, 3, 3, 3, 3, 4, 5, 6}, the densification repetition degrees of 1, 2, 4, 5, and 6 are 1, while the densification repetition degree of 3 is 4. The efficiency index η: An index reflecting the decomposition efficiency of the RSA modulus N, quantified by and is usually an even number. For example, etc.

[0043] S2. Calculate and the main search direction

[0044] Among them, the floor function is a function that rounds x downwards, that is: the largest integer not exceeding x, mathematically expressed as For example: if x = 3.12345, then

[0045] S3. Generate a rectangular area according to a preset rule and calculate the center of the rectangular area:

[0046] S4. Calculate the side length and number of the first batch of small square areas:

[0047] S5. Represent n in the form of 2 M K + R;

[0048] S6. Randomly select a search starting point near the center of the rectangular area;

[0049] S7. Randomly select a specific search direction d in the main search direction: upper right or lower left;

[0050] S8. Construct a small square with side length e and centered at the search starting point, and perform a small search for its element h, and calculate res = gcd(h, N);

[0051] Among them, the element h is equivalent to ω calculated according to the coordinates X and Y subsequently x,y .

[0052] Among them, small search: A search method for a small-scale finite set using the classical brute-force search, random walk search, or other mature search methods. The use of this term is intended to distinguish the large-scale search method (big search) described in the present invention. In the following text, unless the word "small search" is specified, it refers to the big search described in the present invention.

[0053] S9. If res > 1, the task is completed;

[0054] S10. Otherwise, continue to construct R small squares along the direction of d to obtain the first batch of small square regions, and search for the element h among them. Calculate res = gcd(h, N); if res > 1, the task is completed;

[0055] S11. If not found, loop K times: Continuously construct 2 M small squares along the direction of d (there are K groups in total); randomly select a small square using the LCG sampling method; search for the element h of the selected small square, and calculate res = gcd(h, N); if res > 1, the task is completed; otherwise, continue to loop.

[0056] In some feasible embodiments, the rectangular region in step S3 specifically includes:

[0057] For a given RSA modulus N = pq, where p and q are both odd prime numbers satisfying p < q < 2q. Take and the densification repetition degree g; restrict the integer variables X and Y within the following ranges:

[0058]

[0059] Let

[0060]

[0061] Then calculate (N - p u )(g(2p u - p b - N - 1)+1) integers. If X is regarded as the row coordinate changing from top to bottom and Y as the column coordinate changing from left to right, then these integers are arranged in rows and columns and distributed on a rectangular region corresponding to the X and Y change ranges with N - p u rows and g(2p u - p b - N - 1)+1 columns. Denote this region as Π.

[0062] Since g can be calculated or set in advance (the specific calculation method does not belong to the content of the present invention), and p b and p u are both calculated in advance, the Π mentioned above is an existing aggregate.

[0063] The region Π has the characteristic of dense host numbers: each column contains at least one host number of p or q; each host number appears with a repetition degree of g inside Π.

[0064] Host number: Another name for multiple. If an integer x is a multiple of an integer y, then x is called a host number of y. For example, 35 is a host number of 5 and 7, and 10 is a host number of 5 and 2.

[0065] Taking N = 35 and g = 2 as an example, calculate p b = 5, p u = 29, and obtain Π as Figure 2 shown.

[0066] If Figure 2 the host numbers of 5 and 7 in Π are represented by small circles o, and the non - host numbers are represented by dots., obtain Figure 3 , indicating the distribution of host numbers and non - host numbers.

[0067] If g = 4 is taken, then the distribution of host numbers and non - host numbers as shown in Figure 4 is obtained.

[0068] The properties of the above - mentioned region Π can be proved mathematically. In fact, the following conclusions can be proved separately.

[0069] 1) There is at least one host number in each column.

[0070] 2) Inside a row (i.e., the non - boundary part), if a host number appears, it appears continuously g times.

[0071] 3) There are several host numbers in each row.

[0072] 4) Inside Π (non - boundary part), if there is a host number h of p or q at the X - th row and Y - th column, then the number at the (X + 1) - th row and (Y + g) - th column is also h. This property can be called the "lower - right tilt property".

[0073] 5) The host numbers of p or q are centrosymmetrically distributed inside Π.

[0074] Proof: First, prove conclusion 1). Fix Y and let X vary continuously. The formula (2) calculates N - p consecutive integers in one column. Since u Therefore So According to the properties of integers, among any consecutive p integers, there must be a multiple of p (i.e., a host number). Therefore, there is at least one host number of p in each column of Π.

[0075] Next, prove conclusion 2). In formula (2), the change of Y affects the elements of each column in the X - th row. Arbitrarily take a Y and consider the value of the integer , where the integer k≥0. Since According to the properties of the floor function:

[0076]

[0077] Or

[0078]

[0079] When k < g Therefore, when k varies from 0 to g - 1, there are g values of k such that take the same value. This indicates that without boundary constraints, ω calculated according to equation (2) X,Y will necessarily have g consecutive repeated values in the Y direction each time; however, on the boundary, there may be a situation where there are less than g repeated values due to boundary limitations.

[0080] The following proves conclusion 3). Fix X and calculate a row according to equation (2), and there are a total of numbers. Notice a special case: when g = 1, that is, the repetition degree is 1, a total of consecutive integers distributed in the interval Since this interval exactly contains integers, the numbers calculated for each row will cover every integer in the interval without omission. When g > 1, according to conclusion 2), the n integers calculated for each row will repeat in the middle; only take 1 from each repeated number, which is the case of g = 1. Therefore, each row contains consecutive non-repeating integers. Denote these numbers as m. According to the definition of the floor function,[[]] Thus

[0081]

[0082] From this, it can be seen that for any N not less than 15, m > 0. On the other hand, from q > p and N = pq, we get

[0083]

[0084] It can be known that when p ≥ 3, m > q, and thus m > p. Therefore, the interval contains both the host numbers of p and the host numbers of q.

[0085] Next, prove conclusion 4). If h is the host number that appears in the X-th row and Y-th column, then according to equation (2), we have

[0086]

[0087] According to equation (2) again, the number in the X1-th and Y1-th columns is

[0088]

[0089] Substitute X1 = X + 1 and Y1 = Y + g into the above formula to get

[0090]

[0091] Therefore, conclusion 5) holds.

[0092] Finally, we prove conclusion 5). First, we prove that when g = 1, the number of hosts on Π is centrally symmetrically distributed. In fact, from equation (1), we know that the central coordinate of Π is:

[0093]

[0094] From this we get:

[0095]

[0096] thereby

[0097]

[0098] Take (Cx, Cy) as the reference and take increments ΔX and ΔY respectively, and calculate according to formula (2):

[0099] ω Cx+ΔX,Cy+ΔY =p u +Cx+ΔX-Cy-ΔY=p u +Cx-Cy+(ΔX-ΔY),

[0100] ω Cx-ΔX,Cy-ΔY =p u +Cx-ΔX-Cy+ΔY=p u +Cx-Cy-(ΔX-ΔY).

[0101] From the above two equations and (5), we can get:

[0102] ω Cx+ΔX,Cy+ΔY +ω Cx-ΔX,Cy-ΔY =N

[0103] It can be seen from this that if ω Cx+ΔX,Cy+ΔY is a host number, then ω Cx-ΔX,Cy-ΔY There must also be a host number. Note that ω Cx+ΔX,Cy+ΔY With ω Cx-ΔX,Cy-ΔY It is centrosymmetric. Therefore, conclusion 5) holds when g=1.

[0104] When g>1, geometrically, the repeated data can be regarded as the result of first pulling the entire graph a distance of g along the Y direction, and then shifting it 1 unit to the right for g times. Therefore, conclusion 5) also holds when g>1.

[0105] From the conclusion of the above proof, we can know that in the set Π defined by equation (1) and calculated by equation (2), each column contains at least one host number p, and each row contains host numbers p and q; each host number inside Π appears g times consecutively, showing an approximately centrally symmetrical and right-downward tilted distribution.

[0106] The existence of the host numbers p and q and their local aggregation within Π make their occurrence probabilities relatively high in some local areas and thus easy to be found through small-scale searches. For example, for Figure 3 in Π, select 4 small rectangles as shown in Figure 5 . Then the probability that the host number in the bottom-left small rectangle is calculated by randomly sampling one each time is 0.37255, which is higher than the overall probability of 0.333333. In addition, conducting small-scale searches within the range of the small rectangles also reduces the search volume.

[0107] In fact, there are indeed small areas on Π with relatively high host number distribution probabilities. The proof is as follows:

[0108] Suppose Π is completely partitioned into π1, π2,..., and π m , a total of m small intervals, as shown in Figure 6 .

[0109] If P i is the probability of selecting a host number on each small area π i , and each small area can be selected with equal probability; then the probability of each small area being selected is The total probability P Π of selecting a host number on Π is:

[0110]

[0111] The above formula (6) shows that: P Π is the arithmetic mean of P1, P2,..., and P m . Therefore, there must be one π b such that P b ≥P Π .

[0112] Therefore, the method of screening host numbers by selecting small areas on Π is superior to the method of single-point sampling screening.

[0113] In some feasible embodiments, in step S8, the search range and direction for searching for host numbers on it specifically include:

[0114] The method of screening host numbers by selecting small areas on it is superior to the method of single-point sampling screening.

[0115] The semi-Π principle. As previously analyzed and proven: The distribution of host numbers within Π is centrosymmetric. Therefore, by selecting half of Π in the Y direction as the search object, that is, the number of columns in the Y direction is reduced to gp u -(g(p b +N+1)-1) / 2, the search range can be reduced by half. The present invention uses the left half of Π as the search object. For convenience, it is still marked with Π.

[0116] Principle of starting point near the center. The starting point of the search is very important, and the present invention adopts random selection. In order to ensure that the selected point can produce the best search effect, the present invention selects near the center point of Π. This is because such selection can make the number of hosts relatively evenly distributed around the starting point. The reason is self-evident. The central coordinates after the aforementioned semi-Π processing are:

[0117]

[0118] Principle of search direction of upper right and lower left inclination. The search direction determines the search efficiency. If the densification repetition degree is g, the present invention adopts a search direction of inclination to the upper right (or lower left), and the slope of the best search direction is

[0119] The basis for adopting the above search direction is as follows:

[0120] If the upper left corner of Π is taken as the coordinate origin, according to property 4) of the number of hosts in Π (“lower right inclination property”), taking the lower left corner as the starting reference point for search, according to property 4 (“lower right inclination”) proved above, as Figure 7 shown, the slope of the distribution direction of the number of hosts in Π is g, and the distribution line is y = gx + b, where b is the intercept. Then taking the direction perpendicular to the distribution direction of the number of hosts and pointing to the distribution line as the search direction will obtain the shortest search distance, and this distance does not exceed (p - 2). In fact, according to the aforementioned mathematical theorem, the maximum distance between two host numbers p or q is p - 1, and the minimum distance is q - p - 1. Since there are 0 or 1 host numbers q between two adjacent host numbers p, and there are 1 or 2 host numbers p between two adjacent host numbers q. Assuming that the lower left corner of Π is not a host number, then the maximum distance between it and the first host number on its right is (p - 2)g; similarly, the maximum distance between it and the first host number above it is p - 2. The positions of this lower left corner point and the two host numbers above and to the right of it form a right triangle, as Figure 8 shown, the search direction is perpendicular to the hypotenuse, so the distance does not exceed p - 2.

[0121] According to the aforementioned properties 3) and 4), there are host numbers in each row on the distribution line. After selecting the search starting point inside Π, if the selected starting point does not correspond to a host number, then searching in the above upper right or lower left direction can reduce the length of the search path.

[0122] Example: Π obtained when N = 77 and g = 2 is as Figure 9 shown, and the distribution of its host numbers and non-host numbers is as Figure 10 shown.

[0123] As Figure 9As shown, connecting the host numbers 63 closest to the lower left corner in the X and Y directions gives a distribution line. According to the aforementioned search method, moving one grid per step, it only takes 3 steps to search for 63. If searching solely along the X direction, it takes 4 steps, while along the Y direction, it takes 8 steps. Arbitrarily select a starting point near the center of Π. For example, Figure 9 The small squares inside Π shown represent the selected points. When searching in the upper right - lower left direction as described, the search paths are shorter than those along the X or Y direction alone, unless the selected point itself is a host number.

[0124] The following points need to be noted:

[0125] Since p and q are unknown before N is factored. It is impossible to directly find the distribution line, but it does not affect the trend rule of the distribution line, that is, y = gx + b; naturally, it also does not affect the search in the described search direction.

[0126] A relatively large N will calculate a very large Π. Π can be completely partitioned. After partitioning, a finite number of small regions are obtained, and each small region is regarded as a lattice point. Similarly, according to the upper right - lower left direction principle, small regions are randomly sampled and small searches are also carried out within the small regions according to this principle. The present invention sets the size of the small region according to the efficiency index η: If the expected efficiency index is Then a square small region is selected with a side length of The small search can complete the search of the small region within steps. For the convenience of subsequent calculation of e.

[0127] Setting of the efficiency index η. The side length of the small square was determined using the efficiency index η as described above. Here, a method for determining η is given. Considering that when N≈10 mn At this time, Because any number can be expressed as b×10 k Here, b is a number less than 10. Therefore, a selection principle for η is obtained from this calculation rule as follows:

[0128] For N≈10 10 、10 20 、...、10 mn Here, mn is a multiple of 10; if it is desired to complete the search of the small square within 10 n search steps, then take η = m. Thus, If, according to this η, a smaller N gives a smaller e, then use e = 2g.

[0129] For example, when N≈10 20 At this time, And 10 5 is an acceptable number of search steps. Therefore, take η = 4 to obtain That is, the side length of the small square is 300.

[0130] Search range. According to the distribution characteristics of the number of hosts, the maximum search distance is Therefore, the upper limit of the number n of small areas that need to be searched theoretically is:

[0131]

[0132] For example, if N is an RSA modulus with a length of 20 bits, that is, N≈10 20 ; setting η = 10, then at most small areas are required.

[0133] For a relatively large N, the number of small areas may be very large. n can be expressed in the following form:

[0134] n = 2 M K + R (8)

[0135] where K is an integer in the form of 4x + 1.

[0136] In this way, the small areas can be divided into K + 1 groups, where K groups contain 2 M small areas, and the other group contains R small areas. After grouping, it is not only convenient to use the linear congruential random number generation method for random sampling in the small groups, but also convenient for parallel computing.

[0137] It is very easy to express n in the form of (8) by using binary representation. For example, if the binary representation of n is:

[0138] n = b s 2 s + b s-1 2 s-1 +... + b12 + b0

[0139] Then

[0140] n = 2 M (b s 2 s-M + b s-1 2 s-M-1 +... + b M ) + b M-1 2 M-1 ... + b12 + b0

[0141] Then: K = b s 2 s-M + b s-1 2 s-M-1 +... + b M and R = b M-1 2 M-1 ... + b12 + b0.

[0142] After determining the general search direction, there is still a choice between searching diagonally up to the right or diagonally down to the left. Since it is easy to go out of bounds when searching upward when the starting point is close to the top of Π, or it is easy to go out of bounds when searching downward when the starting point is close to the bottom of Π, the present invention stipulates to select the starting point near the center of Π, at which time neither searching diagonally up to the right nor diagonally down to the left will go out of bounds.

[0143] An RSA cryptographic decomposition system based on factor search:

[0144] At least one processor;

[0145] At least one memory for storing at least one program;

[0146] When the at least one program is executed by the at least one processor, the at least one processor implements an RSA cryptographic decomposition method based on factor search as described above.

[0147] The content in the above method embodiments is applicable to the present system embodiment. The functions specifically implemented by the present system embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0148] A storage medium storing instructions executable by a processor, where the instructions executable by the processor are used to implement an RSA cryptographic decomposition method based on factor search as described above when executed by the processor.

[0149] The content in the above method embodiments is applicable to the present storage medium embodiment. The functions specifically implemented by the present storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0150] The above has specifically described the preferred embodiments of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art can also make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of this application.

Claims

1. A RSA cipher decomposition method based on factor search, characterized in that: The following steps are involved: Define the modulus N, the densification repetition g and the efficiency index η; calculate and the main search direction Generate a rectangular area according to a preset rule and calculate the center of the rectangular area; Selecting a search starting point based on the center of the rectangular area, and constructing a square with a preset side length with the search starting point as the center; Search the elements in the square and calculate res=gcd(h,N), where h represents the elements therein; If res>1, the task is completed; If res=1, determine the specific search direction according to the main search direction; Combine the search starting point, the specific search direction and the preset number, construct a small square area and a small search element, and calculate res=gcd(h,N) until res>1, and the task is completed.

2. A RSA cryptographic decomposition method based on factor search according to claim 1, characterized in that: The step of generating a rectangular area according to a preset rule specifically includes: according to Calculate multiple integers, the number of integers is calculated as follows: u )(g(2p u -p b -N-1)+1), distributed in Np u row, g(2p u -p b -N-1)+1 columns form a rectangular area; With X and Y representing the row and column respectively, the integer is calculated.

3. A RSA password decomposition method based on factor search according to claim 2, characterized in that: The calculation formula for the center of the rectangular area is as follows:

4. The RSA cryptographic decomposition method based on factor search according to claim 1, characterized in that: The efficiency index η is defined, and the calculation formulas of the preset side length and the preset number are expressed as follows: Among them, e represents the side length and n represents the number.

5. A RSA password decomposition method based on factor search according to claim 4, characterized in that: Also includes: The number n is expressed as 2 M The K+R form, where M, K and R are all positive integers.

6. The RSA cryptographic decomposition method based on factor search according to claim 5, characterized in that: The step of combining the search starting point, the specific search direction and the preset number to construct a small square area and search for elements of the small square specifically includes: Continue to construct R small squares along the specific search direction to obtain the first batch of small square areas, and search their elements to calculate res = gcd(h, N); If res>1, the task is completed.

7. The RSA cipher decomposition method based on factor search according to claim 6, characterized in that: Also includes: If res=1, then loop K times according to the following steps: Construct 2 along the specific search direction M small squares, and obtain a new batch of small squares in sequence; Randomly select a small square and search the elements of the selected small square, and calculate res = gcd(h,N); Until res>1, the task is completed.

8. A RSA cryptographic decomposition system based on factor search, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the RSA cryptographic decomposition method based on factor search as described in any one of claims 1 to 7.