Pandorex
Security

RSA Forgery Without Factoring Still Needs a Raw Signing Oracle

Published Pandorex Redaktion·5 min read
—
Illustration: a sealed HSM releases signature queries through a gate while a separate computer subsequently produces more forged signatures.
Editorial illustration · Pandorex

In brief: A research team forged arbitrary RSA-1024 signatures without factoring the public modulus or extracting the private key. The record substantially lowers the assumed security of specific RSA applications. Ordinary TLS and Web PKI signatures are unaffected because the attack requires temporary access to a raw, unpadded RSA oracle.

Confirmed: 1,380 core-years and 232 oracle queries

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented a 2007 attack using the special number field sieve. Over five months it consumed 1,380 CPU core-years: roughly 1,200 for public-modulus precomputation and 180 for the later forgery. The researchers made 232 raw RSA requests to HSMs between those stages, then created further signatures offline while the private key remained inside.

The paper estimates factoring RSA-1024 with current software at 500,000 to one million CPU core-years. The figures are not equivalent: the new attack was executed, whereas the factoring cost is estimated. The team also disabled the tested Luna K6 HSM's FIPS 140-2 mode to enable raw RSA.

Blind signatures are the relevant exception

The model matches blind RSA, where a client obtains a signature on a value the signer cannot inspect. RFC 9474 standardises it as RSABSSA; Privacy Pass and Apple Private Access Tokens are deployments examined in the paper. For RSA-2048, the authors estimate 290 work and 243 oracle queries. That is below the usual 112-bit rating, yet remains an enormous barrier.

For 4096-bit keys, the extrapolation reaches 2119 operations rather than 144–152 security bits inferred from factoring. These are not demonstrated attacks. Hidden constants, parameter improvements and extrapolation from the 1024-bit run add uncertainty.

Pandorex Analysis: “RSA is broken” would go too far

PKCS#1 v1.5 and RSA-PSS signatures used by TLS, certificates and many tokens do not expose the raw oracle. The paper finds no comparable speed-up over factoring for these padded schemes. Ars Technica explains this limit correctly, but its headline about a new way to break RSA is broader without that context.

Blind-RSA operators should compare key rotation and query limits with the 243-query scale. The paper proposes larger keys, zero-knowledge proofs of well-formed requests and eventually moving away from RSA. Conventional RSA signatures need no emergency migration, but the result supports existing post-quantum transition plans.

Sources and references

Sources used for the facts and context in this article.

  1. Shea, Haller, Suhl, Heninger, Thomé, 20.09.2026: Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.org
  2. UC San Diego HACC: NSNFSSSFSFN — Implementierung und FAQgithub.com
  3. IETF RFC 9474, Oktober 2023: RSA Blind Signaturesrfc-editor.org
  4. Ars Technica, 24.09.2026: There’s a new way to break RSA that’s faster than anything we’ve seen beforearstechnica.com

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

GitLab Fixes Two CVSS 9.9 Flaws in Regular-Expression Processing

Security