{"rewrite":{"id":"r_c8abcc5d95629555aecf4777","clusterId":"c_ce0210b1e45f087a3e0530aa","slug":"researchers-forge-1024-bit-rsa-signatures-without-factoring-the-key","model":"deepseek-v4-1-flash","headline":"Researchers Forge 1024-Bit RSA Signatures Without Factoring the Key","summary":"A University of California, San Diego and Inria team ran a large-scale experiment using an algorithm called sqrt-e NFS, a Number Field Sieve variant proposed in 2007 and implemented publicly here. Targetting 1024-bit RSA, the attack never factors the public key. It needs an oracle that returns raw RSA operations. Precomputation took about 1,200 CPU core-years, plus 2^32 oracle queries; total cost was roughly 1,380 CPU core-years over about five months.","whyItMatters":"The result says RSA's security can sit below the cost estimates drawn from general number field sieving when an attacker has raw signing access, which puts hardware security modules that return unpadded signatures inside the threat model rather than outside it.","webCardHtml":"\u003cp\u003eThe attack does not recover the private key. It acquires the ability to produce arbitrary signatures offline and keeps it after oracle access ends. That is the part worth sitting with: the private key stays inside the hardware security module the whole time, and the signatures still come out forged. What the method exploits is the module\u0026#39;s willingness to hand back raw, unpadded RSA results on request. The algorithm is still sub-exponential, so key size still buys real distance. It is just a shorter distance than a general number field sieve estimate implies.\u003c/p\u003e","blueskyPost":"The UCSD and Inria attack needs an oracle that returns raw RSA operations, so the 1,380 CPU core-years buy a signature forgery only where such an oracle already exists.","twitterPost":"The forgery works because an oracle hands back raw RSA operations. Where no such oracle exists, the 1,380 CPU core-years buy nothing.","threadsPost":"The UCSD and Inria experiment succeeds because an oracle returns raw RSA operations on demand. Without that access, the 1,200 CPU core-years of precomputation and 2^32 queries do not produce the forged 1024-bit RSA signature.","newsletterBlurb":"A UC San Diego and Inria team demonstrated signature forgery against 1024-bit RSA without factoring the public key, using an algorithm called sqrt-e NFS. The method is faster than the general number field sieve RSA estimates rest on, though it remains sub-exponential. It requires temporary access to an oracle returning raw, unpadded RSA results, which the experiment obtained from a hardware security module.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260925-rsa-nsnfsssfsfn/\",\"title\":\"Attack that breaks RSA without factoring demonstrated at scale, succeeds in forging 1024-bit RSA signatures\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4657,"outputTokens":612,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1791216430,"createdAt":"2026-10-05T16:03:18.000Z","publishedAt":"2026-10-05T16:06:07.000Z","updatedAt":"2026-10-05T16:06:07.000Z"},"cluster":{"id":"c_ce0210b1e45f087a3e0530aa","canonicalTitle":"RSAを素因数分解せずに破る攻撃を大規模実証、1024ビットRSAの署名偽造に成功","representativeArticleId":"a_155da13cde47f01798e0c331","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-09-25T02:10:00.000Z","lastSeenAt":"2026-09-25T02:10:00.000Z","updatedAt":"2026-10-05T16:06:06.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260925-rsa-nsnfsssfsfn/","title":"RSAを素因数分解せずに破る攻撃を大規模実証、1024ビットRSAの署名偽造に成功"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
