Author_Institution :
RSA Labs., Redwood City, CA, USA
Abstract :
Recently R. Anderson (see ibid., vol.29, no.11, p.995, 1993) proposed a ´trapdoor´ in the RSA public-key cryptosystem whereby a hardware device generates RSA primes p and p´ in such a way that the hardware manufacturer can easily factor the RSA modulus n=pp´. The author shows how this RSA trapdoor can be broken and suggests ways of preventing factorisation attacks.