29 ms·
Do the standards require strong primes for RSA? I think FIPS doesn't ... it gives you that option, either for the legacy reasons or to get a proof with Pocklin
by less_less 1y ago
Do the standards require strong primes for RSA? I think FIPS doesn't ... it gives you that option, either for the legacy reasons or to get a proof with Pocklington's theorem that (p,q) really are prime, but just choosing a random (p,q) and running enough rounds of Miller-Rabin on them is considered acceptable IIRC.
- AnotherGoodName 1y agoYeah see https://en.wikipedia.org/wiki/Strong_prime#Factoring-based_cryptosystems https://en.wikipedia.org/wiki/Strong_prime#Factoring-based_c... There is probably a newer standard superseeding that but it is there in the ansi standards