E-Ink News Daily

← Back to list

Forging 1024-bit RSA signatures in nearly SNFS time

Researchers demonstrate a practical attack on 1024-bit RSA signatures using the Joux-Naccache-Thomé algorithm, forging signatures in nearly SNFS time without factoring the modulus. The attack used an HSM as a signing oracle, requiring 1380 CPU core-years over five months for precomputation and 232 oracle queries, after which any signature could be forged offline in 180 core-years. The findings suggest RSA security with a signing oracle is 15-30 bits lower than traditional factoring-based estimates, and even 4096-bit RSA fails to achieve 128-bit security in this model.

Background

The Joux-Naccache-Thomé algorithm (2007) was a theoretical cryptanalytic technique allowing RSA signature forgery via signing oracle access, but had never been practically demonstrated at scale. This work bridges the gap between theory and practice by implementing the attack against a real HSM.

Source
Lobsters
Published
Sep 24, 2026 at 11:13 PM
Score
7.0 / 10