Embed presentation
Download to read offline




This document discusses using the Coppersmith method to decrypt an RSA ciphertext with a small exponent of 5. It constructs a polynomial based on the ciphertext equation and uses lattice reduction to find a short vector with a root modulo n that reveals plaintext bits. However, the method is unable to recover enough unknown plaintext bits from the given ciphertext due to the lattice dimensions being too large. Multiple polynomial constructions are attempted but none achieve the necessary root size bound to reveal 96 unknown plaintext bits.


