Tags: coppersmith rsa-crt oaep
Rating: 4.5
tl;dr:
qInv
RSA-CRT parameter (named cf
) is not removed from public keyd
using polynomial cf*x -1 == 0 mod q**2
Full writeup: https://github.com/p4-team/ctf/tree/master/2019-09-02-tokyowesterns/happy