摘要 |
A method for generating a compressed RSA modulus, allowing up to two thirds of the bits of a modulus N to be fixed. N has a predetermined portion N H , which comprises two parts N h and N m . A candidate RSA modulus that shares the N h part is generated, and the candidate is then modified using Euclidian-type computations until it shares both N h and N m . Also provided is an apparatus (30) for calculating compressed RSA moduli according to the method and a computer program product (35). |