use the 3-fork variant of the forking lemma to yield a couple of relations involving the unknown key s: #s + # = 0 mod #(n) and # # s + # # = 0 mod #(n) such that for some polynomial B, which only depends on the machine which presumably performs the exist (0)

by finally
Venue:GCD(#,# # ) # B; from