Researchers forge 1024-bit RSA signatures without extracting private keys
2026-09-29 12:57:49
CoinMeta data: A research team from the University of California, San Diego, demonstrated how it is possible to forge a 1024-bit RSA signature by sending multiple queries to a hardware security module ( HSM ), without the need to extract the private key. This result indicates that, despite keeping the key in tamper-proof hardware, there is still a risk if an attacker gains access to the system authorized to use that key. The researchers described in IACR Eprint 2026/2131 how by temporarily accessing the original RSA signature Oracle, attackers can ultimately forge signatures offline. The attack process involved 2^32 basic signature requests and took approximately 1380 CPU core years. In contrast, factoring the same 1024-bit RSA modulus would require about 500,000 to 1,000,000 core years. The study shows that the security of RSA signature Oracle is 15-30 bits lower than estimated based on factorization methods.
Bullish 0
Bearish 0
Source:Cryptopolitan
This content is for market information only and does not constitute investment advice.