181

Small solutions to polynomial equations, and low exponent RSA vulnerabilities
– D Coppersmith
 1997

116

Cryptanalysis of RSA with Private Key d Less Than N^0.292
– Dan Boneh, Glenn Durfee
 2000

706

Factoring polynomials with rational coefficients
– A. K. Lenstra, H. W. Lenstra
 1982

67

Finding a small root of a bivariate integer equation; factoring with high bits known
– D Coppersmith
 1996

66

Finding small roots of univariate modular equations revisited
– N HowgraveGraham
 1997

30

Finding small solutions to small degree polynomials
– D Coppersmith

2895

A Method for Obtaining Digital Signatures and PublicKey Cryptosystems
– R.L. Rivest, A. Shamir, L. Adleman
 1978

12

New Partial Key Exposure Attacks on
– J Blömer, A May
 2003

8

NTL: A Library for doing Number Theory, online available at http:// www.shoup.net/ntl/index.html
– V Shoup

40

Factoring N = p r q for large r
– Dan Boneh, Glenn Durfee, Nick HowgraveGraham
 1999

87

Finding a small root of a univariate modular equation
– D Coppersmith
 1996

227

On Lovász’ lattice reduction and the nearest lattice point problem
– László Babai
 1986

22

Exposing an RSA Private Key Given a Small Fraction of its Bits
– Dan Boneh, Glenn Durfee, Yair Frankel
 1998

16

Partial key exposure attacks on RSA up to full size exponents
– Matthias Ernst, Ellen Jochemsz, Er May
 2005

10

Number Theory C++ Library (NTL) version 5.4.1. Available at http://www.shoup.net/ntl
– V Shoup

14

Computing the RSA Secret Key is Deterministic Polynomial Time Equivalent to Factoring
– Alexander May
 2004

16

A strategy for finding roots of multivariate polynomials with new applications in attacking rsa variants
– Ellen Jochemsz, Alexander May
 2006

207

Riemann’s hypothesis and tests for primality
– Gary L Miller
 1976

42

An attack on RSA given a small fraction of the private key bits
– D Boneh, G Durfee, Y Frankel
 1998
