started · updated
RSA encryption vulnerability discovered via signature forgery without factoring
Researchers from the University of California San Diego and INRIA Nancy have demonstrated a new method to forge RSA digital signatures without the need to factor the underlying large integers. By implementing a 2007 algorithm at scale, the team successfully forged a 1024-bit RSA signature using approximately 1,380 CPU core-years of computation over five months.
This approach bypasses the traditional requirement of calculating the private key through factorization. While widely used padding schemes like PKCS or PSS remain largely secure, the vulnerability is significant for blind-signature protocols and systems using raw RSA signatures. The research indicates that the security levels for 1024-bit, 2048-bit, and 4096-bit RSA keys are 15 to 30 bits lower than previously estimated under this specific attack model.
Experts note that while the attack requires substantial resources—likely only available to nation-states or major cloud providers—it represents a conceptual breakthrough. The findings suggest that RSA security assumptions may need urgent re-evaluation as the industry transitions toward post-quantum cryptography.
Entities
Apple · Cloudflare · Inria Nancy · NIST · Nadia Heninger · National Institute of Standards and Technology · RSA · University of California San Diego