{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T16:45:38Z","timestamp":1779900338851,"version":"3.53.1"},"publisher-location":"Cham","reference-count":48,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031910944","type":"print"},{"value":"9783031910951","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-91095-1_13","type":"book-chapter","created":{"date-parts":[[2025,4,27]],"date-time":"2025-04-27T05:15:14Z","timestamp":1745730914000},"page":"355-384","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Solving Multivariate Coppersmith Problems with\u00a0Known Moduli"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5846-2046","authenticated-orcid":false,"given":"Keegan","family":"Ryan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,28]]},"reference":[{"key":"13_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-3-642-00468-1_3","volume-title":"Public Key Cryptography \u2013 PKC 2009","author":"Y Aono","year":"2009","unstructured":"Aono, Y.: A new lattice construction for partial key exposure attack for RSA. In: Jarecki, S., Tsudik, G. (eds.) PKC 2009. LNCS, vol. 5443, pp. 34\u201353. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-00468-1_3"},{"key":"13_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1007\/978-3-642-31448-3_28","volume-title":"Information Security and Privacy","author":"Y Aono","year":"2012","unstructured":"Aono, Y., Agrawal, M., Satoh, T., Watanabe, O.: On the optimality of lattices for the coppersmith technique. In: Susilo, W., Mu, Y., Seberry, J. (eds.) ACISP 2012. LNCS, vol. 7372, pp. 376\u2013389. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-31448-3_28"},{"key":"13_CR3","doi-asserted-by":"publisher","unstructured":"Becker, T., Weispfenning, V.: Variations on Gr\u00f6bner bases, pp. 453\u2013509. Springer, New York (1993). https:\/\/doi.org\/10.1007\/978-1-4612-0913-3_11","DOI":"10.1007\/978-1-4612-0913-3_11"},{"key":"13_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11745853_1","volume-title":"Public Key Cryptography - PKC 2006","author":"D Bleichenbacher","year":"2006","unstructured":"Bleichenbacher, D., May, A.: New attacks on RSA with small secret CRT-exponents. In: Yung, M., Dodis, Y., Kiayias, A., Malkin, T. (eds.) PKC 2006. LNCS, vol. 3958, pp. 1\u201313. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11745853_1"},{"key":"13_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/978-3-540-45146-4_2","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"J Bl\u00f6mer","year":"2003","unstructured":"Bl\u00f6mer, J., May, A.: New partial key exposure attacks on RSA. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 27\u201343. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_2"},{"key":"13_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/11426639_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"J Bl\u00f6mer","year":"2005","unstructured":"Bl\u00f6mer, J., May, A.: A tool kit for finding small roots of bivariate polynomials over the integers. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 251\u2013267. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_15"},{"key":"13_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-48910-X_1","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201999","author":"D Boneh","year":"1999","unstructured":"Boneh, D., Durfee, G.: Cryptanalysis of RSA with private key $$d$$ less than $$N^{0.292}$$. In: Stern, J. (ed.) EUROCRYPT 1999. LNCS, vol. 1592, pp. 1\u201311. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48910-X_1"},{"key":"13_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/3-540-45682-1_3","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2001","author":"D Boneh","year":"2001","unstructured":"Boneh, D., Halevi, S., Howgrave-Graham, N.: The modular inversion hidden number problem. In: Boyd, C. (ed.) ASIACRYPT 2001. LNCS, vol. 2248, pp. 36\u201351. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45682-1_3"},{"key":"13_CR9","doi-asserted-by":"crossref","unstructured":"Brion, M., Vergne, M.: Lattice points in simple polytopes. J. Am. Math. Soc. 10(2), 371\u2013392 (1997). http:\/\/www.jstor.org\/stable\/2152855","DOI":"10.1090\/S0894-0347-97-00229-4"},{"key":"13_CR10","doi-asserted-by":"publisher","unstructured":"Chen, B.: Ehrhart polynomials of lattice polyhedral functions (2005). https:\/\/doi.org\/10.1090\/conm\/374\/06898","DOI":"10.1090\/conm\/374\/06898"},{"key":"13_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"759","DOI":"10.1007\/978-3-662-53887-6_28","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"T Chinburg","year":"2016","unstructured":"Chinburg, T., Hemenway, B., Heninger, N., Scherr, Z.: Cryptographic applications of capacity theory: on the optimality of coppersmith\u2019s method for univariate polynomials. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016, Part I. LNCS, vol. 10031, pp. 759\u2013788. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_28"},{"key":"13_CR12","doi-asserted-by":"publisher","unstructured":"Cohn, H., Heninger, N.: Approximate common divisors via lattices. ANTS X, p.\u00a0271 (2012). https:\/\/doi.org\/10.2140\/obs.2013.1.271","DOI":"10.2140\/obs.2013.1.271"},{"key":"13_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/3-540-68339-9_14","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201996","author":"D Coppersmith","year":"1996","unstructured":"Coppersmith, D.: Finding a small root of a univariate modular equation. In: Maurer, U. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 155\u2013165. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_14"},{"key":"13_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/3-540-44670-2_3","volume-title":"Cryptography and Lattices","author":"D Coppersmith","year":"2001","unstructured":"Coppersmith, D.: Finding small solutions to small degree polynomials. In: Silverman, J.H. (ed.) CaLC 2001. LNCS, vol. 2146, pp. 20\u201331. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44670-2_3"},{"key":"13_CR15","first-page":"616","volume":"254","author":"E Ehrhart","year":"1962","unstructured":"Ehrhart, E.: Sur les poly\u00e8dres rationnels homoth\u00e9tiques \u00e0 n dimensions. CR Acad. Sci. Paris 254, 616 (1962)","journal-title":"CR Acad. Sci. Paris"},{"key":"13_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/11426639_22","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"M Ernst","year":"2005","unstructured":"Ernst, M., Jochemsz, E., May, A., de Weger, B.: Partial key exposure attacks on RSA up to full size exponents. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 371\u2013386. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_22"},{"key":"13_CR17","unstructured":"Feng, Y., Luo, H., Chen, Q., Nitaj, A., Pan, Y.: Computing asymptotic bounds for small roots in Coppersmith\u2019s method via sumset theory. Cryptology ePrint Archive, Paper 2024\/1330 (2024). https:\/\/eprint.iacr.org\/2024\/1330"},{"key":"13_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"403","DOI":"10.1007\/3-540-39799-X_29","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201985 Proceedings","author":"J Hastad","year":"1986","unstructured":"Hastad, J.: N using RSA with low exponent in a public key network. In: Williams, H.C. (ed.) CRYPTO 1985. LNCS, vol. 218, pp. 403\u2013408. Springer, Heidelberg (1986). https:\/\/doi.org\/10.1007\/3-540-39799-X_29"},{"key":"13_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1007\/978-3-642-10366-7_29","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2009","author":"M Herrmann","year":"2009","unstructured":"Herrmann, M., May, A.: Attacking power generators using unravelled linearization: when do we output too much? In: Matsui, M. (ed.) ASIACRYPT 2009. LNCS, vol. 5912, pp. 487\u2013504. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-10366-7_29"},{"key":"13_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/978-3-642-13013-7_4","volume-title":"Public Key Cryptography \u2013 PKC 2010","author":"M Herrmann","year":"2010","unstructured":"Herrmann, M., May, A.: Maximizing small root bounds by linearization and applications to small secret exponent RSA. In: Nguyen, P.Q., Pointcheval, D. (eds.) PKC 2010. LNCS, vol. 6056, pp. 53\u201369. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13013-7_4"},{"key":"13_CR21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/bfb0024458","volume-title":"6th IMA International Conference on Cryptography and Coding","author":"N Howgrave-Graham","year":"1997","unstructured":"Howgrave-Graham, N.: Finding small roots of univariate modular equations revisited. In: Darnell, M. (ed.) 6th IMA International Conference on Cryptography and Coding. LNCS, vol. 1355, pp. 131\u2013142. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/bfb0024458"},{"key":"13_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/11935230_18","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2006","author":"E Jochemsz","year":"2006","unstructured":"Jochemsz, E., May, A.: A strategy for finding roots of multivariate polynomials with new applications in attacking RSA variants. In: Lai, X., Chen, K. (eds.) ASIACRYPT 2006. LNCS, vol. 4284, pp. 267\u2013282. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11935230_18"},{"key":"13_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-540-74143-5_22","volume-title":"Advances in Cryptology - CRYPTO 2007","author":"E Jochemsz","year":"2007","unstructured":"Jochemsz, E., May, A.: A polynomial time attack on RSA with private CRT-exponents smaller than $$N^{0.073}$$. In: Menezes, A. (ed.) CRYPTO 2007. LNCS, vol. 4622, pp. 395\u2013411. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74143-5_22"},{"issue":"4","key":"13_CR24","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1007\/BF01457454","volume":"261","author":"AK Lenstra","year":"1982","unstructured":"Lenstra, A.K., Lenstra, H.W., Lov\u00e1sz, L.: Factoring polynomials with rational coefficients. Math. Ann. 261(4), 515\u2013534 (1982). https:\/\/doi.org\/10.1007\/BF01457454","journal-title":"Math. Ann."},{"key":"13_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-662-48797-6_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"Y Lu","year":"2015","unstructured":"Lu, Y., Zhang, R., Peng, L., Lin, D.: Solving linear equations modulo unknown divisors: revisited. In: Iwata, T., Cheon, J.H. (eds.) ASIACRYPT 2015, Part I. LNCS, vol. 9452, pp. 189\u2013213. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48797-6_9"},{"key":"13_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"242","DOI":"10.1007\/3-540-45708-9_16","volume-title":"Advances in Cryptology \u2014 CRYPTO 2002","author":"A May","year":"2002","unstructured":"May, A.: Cryptanalysis of unbalanced RSA with small CRT-exponent. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol. 2442, pp. 242\u2013256. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45708-9_16"},{"key":"13_CR27","unstructured":"May, A.: New RSA vulnerabilities using lattice reduction methods. Ph.D. thesis, University of Paderborn (2003)"},{"key":"13_CR28","doi-asserted-by":"publisher","unstructured":"May, A.: Using LLL-Reduction for Solving RSA and Factorization Problems, pp. 315\u2013348. ISC, Springer (2010). https:\/\/doi.org\/10.1007\/978-3-642-02295-1","DOI":"10.1007\/978-3-642-02295-1"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"May, A.: Lattice-based integer factorisation: an introduction to Coppersmith\u2019s method. Computational Cryptography: Algorithmic Aspects of Cryptology, pp. 78\u2013105 (2021)","DOI":"10.1017\/9781108854207.006"},{"key":"13_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-030-92062-3_4","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"A May","year":"2021","unstructured":"May, A., Nowakowski, J., Sarkar, S.: Partial key exposure attack on\u00a0short secret exponent CRT-RSA. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021, Part I. LNCS, vol. 13090, pp. 99\u2013129. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_4"},{"key":"13_CR31","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-031-07082-2_6","volume-title":"EUROCRYPT 2022, Part III","author":"A May","year":"2022","unstructured":"May, A., Nowakowski, J., Sarkar, S.: Approximate divisor multiples - factoring with only a third of the secret CRT-exponents. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT 2022, Part III. LNCS, vol. 13277, pp. 147\u2013167. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_6"},{"key":"13_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-540-78440-1_3","volume-title":"Public Key Cryptography \u2013 PKC 2008","author":"A May","year":"2008","unstructured":"May, A., Ritzenhofen, M.: Solving systems of modular equations in one variable: how many RSA-encrypted messages does eve need to know? In: Cramer, R. (ed.) PKC 2008. LNCS, vol. 4939, pp. 37\u201346. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78440-1_3"},{"key":"13_CR33","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-981-99-8730-6_2","volume-title":"ASIACRYPT 2023, Part IV","author":"J Meers","year":"2023","unstructured":"Meers, J., Nowakowski, J.: Solving the hidden number problem for CSIDH and CSURF via automated Coppersmith. In: Guo, J., Steinfeld, R. (eds.) ASIACRYPT 2023, Part IV. LNCS, vol. 14441, pp. 39\u201371. Springer, Singapore (2023). https:\/\/doi.org\/10.1007\/978-981-99-8730-6_2"},{"key":"13_CR34","doi-asserted-by":"publisher","unstructured":"Micheli, G.D., Heninger, N.: Survey: recovering cryptographic keys from partial information, by example. CiC 1(1), 28 (2024). https:\/\/doi.org\/10.62056\/ahjbksdja","DOI":"10.62056\/ahjbksdja"},{"key":"13_CR35","doi-asserted-by":"publisher","unstructured":"Nguyen, P.Q.: Hermite\u2019s constant and lattice algorithms, pp. 19\u201369. ISC, Springer (2010). https:\/\/doi.org\/10.1007\/978-3-642-02295-1","DOI":"10.1007\/978-3-642-02295-1"},{"key":"13_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-319-06734-6_11","volume-title":"Progress in Cryptology \u2013 AFRICACRYPT 2014","author":"L Peng","year":"2014","unstructured":"Peng, L., Hu, L., Xu, J., Huang, Z., Xie, Y.: Further improvement of factoring RSA moduli with implicit hint. In: Pointcheval, D., Vergnaud, D. (eds.) AFRICACRYPT 2014. LNCS, vol. 8469, pp. 165\u2013177. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-06734-6_11"},{"key":"13_CR37","doi-asserted-by":"publisher","unstructured":"Picard, J.C.: Maximal closure of a graph and applications to combinatorial problems. Manag. Sci. 22(11), 1268\u20131272 (1976). https:\/\/doi.org\/10.1287\/mnsc.22.11.1268","DOI":"10.1287\/mnsc.22.11.1268"},{"key":"13_CR38","unstructured":"Ryan, K.: Solving multivariate Coppersmith problems with known moduli. Cryptology ePrint Archive, Paper 2024\/1577 (2024). https:\/\/eprint.iacr.org\/2024\/1577"},{"key":"13_CR39","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-38548-3_1","volume-title":"CRYPTO 2023, Part III","author":"K Ryan","year":"2023","unstructured":"Ryan, K., Heninger, N.: Fast practical lattice reduction through iterated compression. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part III. LNCS, vol. 14083, pp. 3\u201336. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_1"},{"key":"13_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"473","DOI":"10.1007\/978-3-642-01957-9_29","volume-title":"Applied Cryptography and Network Security","author":"S Sarkar","year":"2009","unstructured":"Sarkar, S., Maitra, S.: Partial key exposure attack on CRT-RSA. In: Abdalla, M., Pointcheval, D., Fouque, P.-A., Vergnaud, D. (eds.) ACNS 2009. LNCS, vol. 5536, pp. 473\u2013484. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-01957-9_29"},{"key":"13_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/978-3-319-13051-4_21","volume-title":"Selected Areas in Cryptography \u2013 SAC 2014","author":"A Takayasu","year":"2014","unstructured":"Takayasu, A., Kunihiro, N.: Partial key exposure attacks on RSA: achieving the Boneh-Durfee bound. In: Joux, A., Youssef, A. (eds.) SAC 2014. LNCS, vol. 8781, pp. 345\u2013362. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13051-4_21"},{"key":"13_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1007\/978-3-319-56614-6_5","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"A Takayasu","year":"2017","unstructured":"Takayasu, A., Lu, Y., Peng, L.: Small CRT-exponent RSA revisited. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017, Part II. LNCS, vol. 10211, pp. 130\u2013159. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56614-6_5"},{"key":"13_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/978-3-319-06320-1_39","volume-title":"Information Security Practice and Experience","author":"J Xu","year":"2014","unstructured":"Xu, J., Hu, L., Huang, Z., Peng, L.: Modular inversion hidden number problem revisited. In: Huang, X., Zhou, J. (eds.) ISPEC 2014. LNCS, vol. 8434, pp. 537\u2013551. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-06320-1_39"},{"issue":"2","key":"13_CR44","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/s10623-019-00685-y","volume":"88","author":"J Xu","year":"2019","unstructured":"Xu, J., Hu, L., Sarkar, S.: Cryptanalysis of elliptic curve hidden number problem from PKC 2017. Des. Codes Crypt. 88(2), 341\u2013361 (2019). https:\/\/doi.org\/10.1007\/s10623-019-00685-y","journal-title":"Des. Codes Crypt."},{"issue":"9","key":"13_CR45","doi-asserted-by":"publisher","first-page":"1997","DOI":"10.1007\/s10623-017-0435-4","volume":"86","author":"J Xu","year":"2017","unstructured":"Xu, J., Sarkar, S., Hu, L., Huang, Z., Peng, L.: Solving a class of modular polynomial equations and its relation to modular inversion hidden number problem and inversive congruential generator. Des. Codes Crypt. 86(9), 1997\u20132033 (2017). https:\/\/doi.org\/10.1007\/s10623-017-0435-4","journal-title":"Des. Codes Crypt."},{"key":"13_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1007\/978-3-030-26948-7_11","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"J Xu","year":"2019","unstructured":"Xu, J., Sarkar, S., Hu, L., Wang, H., Pan, Y.: New results on modular inversion hidden number problem and inversive congruential generator. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019, Part I. LNCS, vol. 11692, pp. 297\u2013321. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26948-7_11"},{"issue":"8","key":"13_CR47","doi-asserted-by":"publisher","first-page":"5337","DOI":"10.1109\/TIT.2023.3263485","volume":"69","author":"J Xu","year":"2023","unstructured":"Xu, J., Sarkar, S., Hu, L., Wang, H., Pan, Y.: Revisiting modular inversion hidden number problem and its applications. IEEE Trans. Inf. Theory 69(8), 5337\u20135356 (2023). https:\/\/doi.org\/10.1109\/TIT.2023.3263485","journal-title":"IEEE Trans. Inf. Theory"},{"key":"13_CR48","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"771","DOI":"10.1007\/978-3-031-22969-5_26","volume-title":"ASIACRYPT 2022, Part III","author":"J Xu","year":"2022","unstructured":"Xu, J., Sarkar, S., Wang, H., Hu, L.: Improving bounds on elliptic curve hidden number problem for ECDH key exchange. In: Agrawal, S., Lin, D. (eds.) ASIACRYPT 2022, Part III. LNCS, vol. 13793, pp. 771\u2013799. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22969-5_26"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-91095-1_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,27]],"date-time":"2025-04-27T05:15:17Z","timestamp":1745730917000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-91095-1_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031910944","9783031910951"],"references-count":48,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-91095-1_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"28 April 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that\u00a0are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Madrid","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 May 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 May 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}