<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Aleksandra V. Markelova</string-name>
          <email>markelova_bmstu@mail.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>74</fpage>
      <lpage>78</lpage>
      <abstract>
        <p>-This paper is dedicated to ROCA-vulnerability that was detected by scientists from Masaryk University, Czech. Their investigation offers low-cost algorithm of factorization of RSA module for special type of keys generated by some widely used cryptographic library. They proposed a practical factorization method for various key lengths including 1024 and 2048 bits. This attack requires no additional information except for the value of the public key and does not depend on a weak or a faulty random number generator. We examine the possibility of modification of type of keys to embed the trapdoor with universal protection into key generator. In some cases we can design Secretly Embedded Trapdoor with Universal Protection in the generator of RSA key. This problem is serious and relevant for all closed (so-called black-box) implementations of cryptographic algorithm in user's library or device. The first section of this article (“Introduction”) is devoted to the history of the issue. It also describes the damage caused by vulnerability ROCA. The second section (“Fingerprint of weak keys”) describes the criterion that the key pair is vulnerable to ROCA. The third section (“Factorization”) is dedicated to the attack ROCA. It also estimates the running time of the algorithm. In the fourth section (“The trapdoor with universal protection”) we will consider the possibility of using SETUP mechanism in the implementation of RSA.</p>
      </abstract>
      <kwd-group>
        <kwd>information security</kwd>
        <kwd>cryptanalysis</kwd>
        <kwd>vulnerability</kwd>
        <kwd>ROCA</kwd>
        <kwd>RSA</kwd>
        <kwd>Coppersmith's algorithm</kwd>
        <kwd>factorization</kwd>
        <kwd>weak keys</kwd>
        <kwd>kleptography</kwd>
        <kwd>trapdoor with protection</kwd>
        <kwd>backdoor</kwd>
        <kwd>SETUP</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>
        On November, 2017 Estonian government made a
statement about blocking 760 000 certificate of ID cards issued
after October 16, 2014. The reason for this statement was the
vulnerability ROCA (Return of Coppersmith's Attack)
discovered by scientists from Masaryk University, Czech [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>Toomas Ilves, the former president of Estonia, said that he
believed millions of people in countries had been affected by
the ROCA flaw, but their authorities were remaining "silent".
In particular, according to the researchers of the Enigma
Bridge, similar problems are possible with ID card of Spain.</p>
      <p>There is a fast detection algorithm to verify whether a
particular key is vulnerable to attack. This verification is based
on the properties of the public moduli.</p>
      <p>Vulnerable keys were also found in some authentication
tokens, in the TPM (Trusted Platform Modules), in PGP.</p>
      <p>Google, HP, Lenovo and Fujitsu released updates for their
software products susceptible to this attack.</p>
      <p>Recall that the public key of the RSA algorithm is a pair
(n, e), where n is the product of two large primes and gcd(e,
(n))=1. Private key is number d such that ed=1(mod (n)).
Some implementations also store prime divisors of n as part of
the private key.</p>
      <p>Thus, RSA requires two large random primes p and q, that
can be obtained by generating a random candidate number
(usually with half of the bits of n) and then testing it for
primality. If the candidate is found to be composite, the
process is repeated with a different candidate.</p>
      <p>
        Since the RSA algorithm is very popular, many researches
are devoted to its reliability [
        <xref ref-type="bibr" rid="ref2 ref3 ref4 ref5 ref6 ref7">2, 3, 4, 5, 6, 7</xref>
        ].
      </p>
      <p>RSA security is based on the integer factorization problem.</p>
      <p>
        The most effective modern factorization algorithms (such
as quadratic sieve [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], number field sieve [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], special number
field sieve [
        <xref ref-type="bibr" rid="ref10 ref11">10, 11</xref>
        ]) have subexponential complexity [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] and
in the general case do not allow hacking RSA with large key
lengths.
      </p>
      <p>However, if the numbers p and q are a special type, then the
time of factorization of the number n = pq can be reduced.</p>
      <p>II.</p>
    </sec>
    <sec id="sec-2">
      <title>FINGERPRINT OF WEAK KEYS</title>
      <p>
        There is no common practice for developers of
cryptographic library how to generate RSA key pair. But there
are many recommendations regarding how to select suitable
primes p and q [
        <xref ref-type="bibr" rid="ref13 ref14 ref15 ref16">13, 14, 15, 16</xref>
        ] to be later used to compute the
private key and public moduli.
      </p>
      <p>
        In 2016, scientists from Masaryk University analyzed
implementations of RSA algorithm and key pairs from 22
open- and closed- source libraries and from 16 different smart
cards [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. In particular, the library RSALib used in Estonian
ID cards was investigated. This library utilizes an acceleration
algorithm called “Fast Prime”.
      </p>
      <p>The foundations of “Fast Prime” date back to the year
2000. According to its developers, its use started around ten
years later after thorough reviews. As a sub-part of one
cryptographic software library which is supplied to customers
as a basis for their own development, this software function
was certified by the BSI (Federal Office for Information
Security) in Germany.</p>
      <p>When compared to other implementations and theoretical
expectations on distribution of prime numbers, the keys from
RSALib exhibited a non-uniform distribution of (p mod x) and
(n mod x) for small primes x.</p>
      <p>
        Further studies have shown that all RSA primes generated
by the RSALib have the following form [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]:
      </p>
      <p>p=k*M + (65537a mod M)</p>
      <p>The integers k and a are unknown, and RSA primes differ
only in their values of a and k for keys of the same size. The
integer M is fixed for each key size (table I) and equal to the
product of the first successive primes:</p>
      <p>M = Pm =  pi = 2*3*5*7*…*pm</p>
      <p>
        The existence of the discrete logarithm c = log65537n mod
M is used as the fingerprint of weakness of the key pair. In
general, verification of solvability of the comparison (3) can
be difficult [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. But if M is of the form (2) then the problem
is easily solved.
      </p>
      <p>The number of residues modulo M for which there exists a
logarithm at base 65537 is equal to ordM65537. For randomly
generated prime numbers, the remainders from dividing their
product by M are distributed uniformly in the multiplicative
group of residues modulo M. Therefore, the probability for the
number n to satisfy the comparison (3) is ordM65537/(M).</p>
      <p>For the M used, the value of ordM65537 is much less than
(M). For example, ordM65537=262,09, (M)=2215,98 for
RSA512. Thus, the probability of the false positive result does not
exceed 262–216=2–154. This probability is even smaller for larger
keys (table II).</p>
      <p>So the existence of the discrete logarithm is the strong
fingerprint of the weak keys.</p>
      <p>
        Coppersmith’s attack was repeatedly modified. Now there
are various attacks on RSA based on Coppersmith’s algorithm.
For example, factorization algorithms have been developed for
cases when the lowest bits of the number p are known or when
primes p and q share bits in the middle ([
        <xref ref-type="bibr" rid="ref20 ref21 ref22 ref23">20, 21, 22, 23</xref>
        ]).
      </p>
      <p>In attacks of this class, we choose a polynomial f(x)
having a small root x0 in the residue field:
(1)
(2)
(3)
262,09
2134,73</p>
      <p>Online and offline versions of this test are already
developed. They are freely available on the Internet.</p>
    </sec>
    <sec id="sec-3">
      <title>FACTORIZATION</title>
      <p>
        Algorithm ROCA iterates over values of a in (1) and use
Coppersmith’s algorithm [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] to attempt to find k. To reduce
the search, the modulus M is replaced by its divisor M', for
which ordM'65537 is small and log2M'&gt;log2n/4. The number M'
is selected once for each RSA key size (table III).
      </p>
      <p>Then we construct a polynomial g(x) satisfying the
following conditions:
(7)
(8)
512
1024
2048
3072
4096
will take about 17 days to find the 2048-bit key. At the same
time the cost of the attack will not increase, because it is
calculated based on the price of one processor hour.</p>
      <p>fi(x) and f(x) have the same roots modulo p,</p>
      <p>
        The coefficients ai are chosen by the LLL-lattice method
[
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. It follows from (6) and (7) that g(x) has the same roots
modulo p as f(x). Well then g(x0)=0 mod p. Taking into
account (8), we see that g(x0)=0. Thus x0 can be found by
standard methods for finding the roots of a polynomial (e.g.,
the Berlekamp-Zassenhaus algorithm [
        <xref ref-type="bibr" rid="ref25 ref26">25, 26</xref>
        ]).
      </p>
      <p>We denote the process of finding x0 as Coppersmith(f(x), n,
, m, t, X), where n is RSA-modulus,  is the upper bound for
the ratio of log2p and log2n, m and t are optimization
parameters of Coppersmith algorithm, X is from (5).</p>
      <p>Algorithm ROCA works as follows:
1. c'= log65537n mod M'
2. =0.5, X=2*n /M'
3. For all a' in [c'/2; (c'+ ordM'65537)/2]:
3.1 f(x) = x + (M'–1 mod n)*(65537a' mod M')(mod n)
3.2. k' = Coppersmith(f(x), n, , m, t, X)
3.3. p=k'*M' + (65537a' mod M')</p>
    </sec>
    <sec id="sec-4">
      <title>3.4 If p is a nontrivial divisor of n, then finish.</title>
      <p>The running time of this algorithm is shown in tables IV
and V. Two time values were explicitly checked by the
scientists from Masaryk University on the university cluster.</p>
      <p>The algorithm is well suited for parallel computations,
since the approbation of different values of a' can pass
independently of each other.</p>
      <p>For example, you can rent 1000 cores on Amazon AWS.
In this case it will take 45 minutes to find the 1024-bit key. It</p>
      <p>Note that 4096-bit RSA key is not practically factorizable
now, but may become so, if the attack is improved.</p>
      <p>
        This is very possible, since the Coppersmith’s algorithm
and the lattice-based method are constantly improving [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ]
IV. THE
PROTECTION
      </p>
      <p>TRAPDOOR</p>
      <p>WITH</p>
      <p>UNIVERSAL</p>
      <p>Did the developers of the RSALib library know about the
vulnerability of their key generator? If they knew, then such
an implementation could be considered as an implementation
with a trapdoor (or a backdoor). But in this case the special
form (2) of the number M makes it possible for any observer to
restore the prime numbers (1). Because of this, an access to the
backdoor is provided not only for developers or authorized
special agency, but also for attacker.</p>
      <p>
        The difference between a trapdoor and a backdoor is the
degree of protection from a third-party offender [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ]. The
science of trapdoors is called "kleptography" [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ]. It was
shown that a cryptosystem, when implemented as a black-box
(i.e., when the user has only input/output access to the
hardware or software cryptographic facility), can be designed
such that it gives a unique advantage to the attacker. This is
accomplished using SETUP (Secretly Embedded Trapdoor
with Universal Protection) mechanisms. SETUP is a system,
hacking which will be available only to the developer.
      </p>
      <p>
        This topic was examined in detail by Young A. and Yung
M. [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. In particular, they considered a number of
kleptographic attacks on the RSA algorithm [
        <xref ref-type="bibr" rid="ref30 ref31 ref32">30, 31, 32</xref>
        ].
      </p>
      <p>
        Issues of the implementation of SETUP-mechanisms are
an actual direction of modern cryptography. Bellare, Paterson,
and Rogaway initiated a formal study of such attacks on
symmetric key encryption algorithms, demonstrating that
kleptographic attacks can be mounted in broad generality
against randomized components of cryptographic systems
[
        <xref ref-type="bibr" rid="ref33">33</xref>
        ]. Russell, Tang, Yung and Zhou enlarged the scope of
work on the problem by permitting adversarial subversion of
(randomized) key generation; in particular, they initiated the
study of cryptography in the complete subversion model,
where all relevant cryptographic primitives are subject to
kleptographic attacks [
        <xref ref-type="bibr" rid="ref34">34</xref>
        ].
      </p>
      <p>
        Obviously, the most effective attack for the intruder and
the greatest danger to the user are backdoors and trapdoors
into the key pair generator. The simplest attack on RSA key
generator is using a fixed prime number p [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. But this attack
is detectable and it is breakable without reverse engineering.
      </p>
      <p>The problem of detectability in the attack can be avoided
by using pseudorandom values instead of random values and
having the initial seed known only to the device and the
attacker. This type of the backdoor is similar to the
implementation of the key generator in the RSALib library.</p>
      <p>
        The fundamental weakness in the pseudorandom number
generator backdoor attack is that once an intermediate seed is
exposed, the future operation of the device is compromised
[
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. Modern methods of protection against backdoor in
pseudorandom generators assume randomness checking at any
time without any notification, so the device is forced to behave
honest [
        <xref ref-type="bibr" rid="ref35">35</xref>
        ].
      </p>
      <p>
        Degabriele, Paterson, Schuldt and Woodage conducted a
full-scale study of pseudorandom number generators [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ] and
give efficient constructions of BPRGs (backdoored
pseudorandom number generators) for which, given a single
generator output, Big Brother can recover the initial state and,
therefore, all outputs of the BPRG. They give an impossibility
result: they provide a bound on the number of previous phases
that Big Brother can compromise as a function of the state-size
of the generator: smaller states provide more limited
backdooring opportunities for Big Brother.
      </p>
      <p>Leaving aside the moral and legal aspects of the issue, we
will consider whether it is possible to construct a trapdoor
with universal protection based on the same idea as the
vulnerability of ROCA.</p>
      <p>Let’s choose numbers M and w satisfying the following
conditions:</p>
      <p>1) the decomposition of the number M into prime factors is
known</p>
      <p>2) (M) is decomposed into small primes:



3) value ordMw is small:
pi | (M): pi &lt; C</p>
      <p>ordMw</p>
    </sec>
    <sec id="sec-5">
      <title>5) there are many primes of the form</title>
      <p>l = log2M ~ log2n / 4
p=k*M + (wa mod M)
4) the size of M approximately equal to
Coppersmith’s algorithm parameters:
optimal</p>
      <p>The last condition ensures that the generator will construct
many different prime numbers.</p>
      <p>

(11)
(12)</p>
      <p>The set (C, , l) specifies the parameters for selecting the
numbers M and w. If you know this set, M and w then you can
restore the user’s private key from the public key applying the
ROCA analog.</p>
      <p>If M has a large prime divisor, then it is not possible to
estimate the distribution (p mod x) and (n mod x) for all
numbers x of this size. Then an attacker will not receive any
additional information about the key.</p>
      <p>The vulnerability of ROCA once again recalled the
importance of analyzing the used cryptographic libraries. In
some cases, problems can be identified by evaluating the
specificity of the generated keys.</p>
      <p>However, the RSA algorithm allows you to build in the
key generator secretly embedded trapdoor with universal
protection. The feature of this trapdoor is that it is not
detectable for the analyst (it is impossible even to prove its
presence in the implementation), but it allows the developer to
calculate the user's private keys.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Nemec</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sys</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Svenda</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Klinec</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matyas</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA Moduli</article-title>
          .
          <year>2017</year>
          .
          <source>CCS'17 Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security</source>
          , p.
          <fpage>1631</fpage>
          -
          <lpage>1648</lpage>
          . DOI:
          <volume>10</volume>
          .1145/3133956.3133969.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Nitaj</surname>
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2012</year>
          )
          <article-title>A New Attack on RSA and CRT-RSA</article-title>
          . In: Mitrokotsa A.,
          <string-name>
            <surname>Vaudenay</surname>
            <given-names>S</given-names>
          </string-name>
          . (eds) Progress in Cryptology - AFRICACRYPT
          <year>2012</year>
          .
          <source>AFRICACRYPT 2012. Lecture Notes in Computer Science</source>
          , vol
          <volume>7374</volume>
          , p.
          <fpage>221</fpage>
          -
          <lpage>233</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -31410- 0_
          <fpage>14</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Nitaj</surname>
            <given-names>A.</given-names>
          </string-name>
          <article-title>A new attack on RSA with two or three decryption exponents</article-title>
          .
          <source>Journal of Applied Mathematics and Computing</source>
          (
          <year>2013</year>
          ) Vol.
          <volume>42</volume>
          ,
          <string-name>
            <surname>Issue</surname>
          </string-name>
          1-
          <issue>2</issue>
          , p.
          <fpage>309</fpage>
          -
          <lpage>319</lpage>
          . DOI:
          <volume>10</volume>
          .1007/s12190-012-0618-0.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Peng</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hu</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lu</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Xu</surname>
            <given-names>J.</given-names>
          </string-name>
          , Huang Z..
          <source>Cryptanalysis of Dual RSA Designs, Codes and Cryptography</source>
          . (
          <year>2017</year>
          ) Vol.
          <volume>83</volume>
          ,
          <string-name>
            <surname>Issue</surname>
            <given-names>1</given-names>
          </string-name>
          , p.
          <fpage>1</fpage>
          -
          <lpage>21</lpage>
          . DOI:
          <volume>10</volume>
          .1007/s10623-016-0196-5.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Barbu</surname>
            <given-names>G.</given-names>
          </string-name>
          et al. (
          <year>2013</year>
          )
          <article-title>Combined Attack on CRT-RSA</article-title>
          . In:
          <string-name>
            <surname>Kurosawa</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hanaoka</surname>
            <given-names>G</given-names>
          </string-name>
          . (eds)
          <string-name>
            <surname>Public-Key</surname>
          </string-name>
          Cryptography - PKC
          <source>2013. Lecture Notes in Computer Science</source>
          , vol
          <volume>7778</volume>
          , p.
          <fpage>198</fpage>
          -
          <lpage>215</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -36362-7_
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Bunder</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nitaj</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Susilo</surname>
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tonien</surname>
            <given-names>J</given-names>
          </string-name>
          . (
          <year>2016</year>
          )
          <article-title>A New Attack on Three Variants of the RSA Cryptosystem</article-title>
          . In: Liu J.,
          <string-name>
            <surname>Steinfeld</surname>
            <given-names>R</given-names>
          </string-name>
          . (eds)
          <article-title>Information Security and Privacy</article-title>
          .
          <source>ACISP 2016. Lecture Notes in Computer Science</source>
          , vol
          <volume>9723</volume>
          , p.
          <fpage>258</fpage>
          -
          <lpage>268</lpage>
          . Springer, Cham. DOI: 978-3-
          <fpage>319</fpage>
          -40367-0_
          <fpage>16</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Bauer</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jaulmes</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lomné</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Prouff</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Roche</surname>
            <given-names>T.</given-names>
          </string-name>
          (
          <year>2014</year>
          )
          <article-title>SideChannel Attack against RSA Key Generation Algorithms</article-title>
          . In: Batina L.,
          <string-name>
            <surname>Robshaw</surname>
            <given-names>M</given-names>
          </string-name>
          . (eds) Cryptographic
          <source>Hardware and Embedded Systems - CHES 2014. CHES 2014. Lecture Notes in Computer Science</source>
          , vol
          <volume>8731</volume>
          , p.
          <fpage>223</fpage>
          -
          <lpage>241</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          - 44709-3_
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Pomerance</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <article-title>Analysis and Comparison of Some Integer Factoring Algorithms</article-title>
          , in Computational Methods in Number Theory,
          <string-name>
            <surname>Part</surname>
            <given-names>I</given-names>
          </string-name>
          , H.W. Lenstra, Jr. and R. Tijdeman, eds.,
          <source>Math. Centre Tract</source>
          <volume>154</volume>
          , Amsterdam,
          <year>1982</year>
          , p.
          <fpage>89</fpage>
          -
          <lpage>139</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Lenstra</surname>
            <given-names>A.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lenstra</surname>
            <given-names>H.W.</given-names>
          </string-name>
          , Jr.,
          <string-name>
            <surname>Manasse</surname>
            <given-names>M.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pollard</surname>
            <given-names>J.M.</given-names>
          </string-name>
          (
          <year>1990</year>
          ).
          <article-title>The number field sieve</article-title>
          .
          <source>STOC '90 Proceedings of the twenty-second annual ACM symposium on Theory of computing</source>
          , p.
          <fpage>564</fpage>
          -
          <lpage>572</lpage>
          , ISBN 0-89791- 361-
          <fpage>2</fpage>
          . DOI:
          <volume>10</volume>
          .1145/100216.100295.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Lenstra</surname>
            <given-names>A.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lenstra</surname>
            <given-names>H.W.</given-names>
          </string-name>
          , Jr.,
          <string-name>
            <surname>Manasse</surname>
            <given-names>M.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pollard</surname>
            <given-names>J.M.</given-names>
          </string-name>
          (
          <year>1993</year>
          ).
          <article-title>The Factorization of the Ninth Fermat Number</article-title>
          .
          <source>Mathematics of Computation Т</source>
          .
          <volume>61</volume>
          (
          <year>1993</year>
          ): p.
          <fpage>319</fpage>
          -
          <lpage>349</lpage>
          , DOI: 10.1090/S0025-5718- 1993-1182953-4.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Buhler</surname>
            <given-names>J.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lenstra</surname>
            <given-names>H.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pomerance</surname>
            <given-names>C.</given-names>
          </string-name>
          (
          <year>1993</year>
          )
          <article-title>Factoring integers with the number field sieve</article-title>
          . In:
          <string-name>
            <surname>Lenstra</surname>
            <given-names>A.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lenstra H</surname>
          </string-name>
          .W. (eds)
          <article-title>The development of the number field sieve</article-title>
          .
          <source>Lecture Notes in Mathematics,</source>
          vol
          <volume>1554</volume>
          , p.
          <fpage>50</fpage>
          -
          <lpage>94</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/BFb0091539.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Pomerance</surname>
            <given-names>C.</given-names>
          </string-name>
          <article-title>A tale of two sieves</article-title>
          .
          <source>Notices Amer. Math. Soc</source>
          .
          <volume>43</volume>
          (
          <year>1996</year>
          ), p.
          <fpage>1473</fpage>
          -
          <lpage>1485</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Gordon</surname>
            <given-names>J.</given-names>
          </string-name>
          (
          <year>1985</year>
          )
          <article-title>Strong Primes are Easy to Find</article-title>
          . In: Beth T.,
          <string-name>
            <surname>Cot</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ingemarsson</surname>
            <given-names>I</given-names>
          </string-name>
          . (eds) Advances in Cryptology.
          <source>EUROCRYPT 1984. Lecture Notes in Computer Science</source>
          , vol
          <volume>209</volume>
          , p.
          <fpage>216</fpage>
          -
          <lpage>223</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/3-540-39757-4_
          <fpage>19</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Loebenberger</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nusken</surname>
            <given-names>M..</given-names>
          </string-name>
          <article-title>Notions for RSA Integers</article-title>
          . In
          <source>International Journal of Applied Cryptography</source>
          , Vol.
          <volume>3</volume>
          , No.
          <volume>2</volume>
          (
          <issue>2014</issue>
          ), p.
          <fpage>116</fpage>
          -
          <lpage>138</lpage>
          . DOI:
          <volume>10</volume>
          .1504/IJACT.
          <year>2014</year>
          .
          <volume>062723</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Maurer</surname>
            <given-names>U.M..</given-names>
          </string-name>
          <article-title>Fast generation of prime numbers and secure public-key cryptographic parameters</article-title>
          .
          <source>Journal of Cryptology</source>
          , Vol.
          <volume>8</volume>
          , Issue 3 (
          <year>1995</year>
          ), p.
          <fpage>123</fpage>
          -
          <lpage>155</lpage>
          . DOI:
          <volume>10</volume>
          .1007/BF00202269.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Benhamouda</surname>
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ferradi</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Géraud</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Naccache</surname>
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2017</year>
          )
          <article-title>Noninteractive Provably Secure Attestations for Arbitrary RSA Prime Generation Algorithms</article-title>
          . In: Foley S.,
          <string-name>
            <surname>Gollmann</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Snekkenes</surname>
            <given-names>E</given-names>
          </string-name>
          . (eds) Computer Security - ESORICS
          <year>2017</year>
          .
          <source>ESORICS 2017. Lecture Notes in Computer Science</source>
          , vol
          <volume>10492</volume>
          , p.
          <fpage>206</fpage>
          -
          <lpage>223</lpage>
          . Springer, Cham. DOI: 978-3-
          <fpage>319</fpage>
          -66402-6_
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Svenda</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nemec</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sekan</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kvasnovskyy</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Formanek</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Komarek</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matyas</surname>
            <given-names>V..</given-names>
          </string-name>
          <year>2016</year>
          .
          <article-title>The Million-Key Question - Investigating the Origins of RSA Public Keys</article-title>
          .
          <source>In The 25th USENIX Security Symposium (USENIX Security'16)</source>
          . USENIX, p.
          <fpage>893</fpage>
          -
          <lpage>910</lpage>
          . DOI:
          <volume>10</volume>
          .13140/rg.2.1.3759.3848.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Markelova</surname>
            <given-names>A.V.</given-names>
          </string-name>
          <article-title>Solvability of the problem of taking the discrete logarithm</article-title>
          . Moscow University Mathematics Bulletin, Vol.
          <volume>63</volume>
          ,
          <issue>Issue 6</issue>
          (
          <year>2008</year>
          ), p.
          <fpage>225</fpage>
          -
          <lpage>228</lpage>
          . DOI:
          <volume>10</volume>
          .3103/S0027132208060016.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Coppersmith</surname>
            <given-names>D.</given-names>
          </string-name>
          (
          <year>1996</year>
          )
          <article-title>Finding a Small Root of a Bivariate Integer Equation; Factoring with High Bits Known</article-title>
          . In: Maurer U. (eds) Advances in Cryptology -
          <source>EUROCRYPT '96. EUROCRYPT 1996. Lecture Notes in Computer Science</source>
          , vol
          <volume>1070</volume>
          , p.
          <fpage>178</fpage>
          -
          <lpage>189</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/3-540-68339-9_
          <fpage>16</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Lu</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhang</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lin</surname>
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2013</year>
          )
          <article-title>Factoring RSA Modulus with Known Bits from Both p and q: A Lattice Method</article-title>
          . In: Lopez J.,
          <string-name>
            <surname>Huang</surname>
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sandhu</surname>
            <given-names>R</given-names>
          </string-name>
          . (eds)
          <article-title>Network and System Security</article-title>
          .
          <source>NSS 2013. Lecture Notes in Computer Science</source>
          , vol
          <volume>7873</volume>
          , p.
          <fpage>393</fpage>
          -
          <lpage>404</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -38631-2_
          <fpage>29</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Akchiche</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Khadir</surname>
            <given-names>O.. Factoring</given-names>
          </string-name>
          <article-title>RSA moduli with primes sharing bits in the middle</article-title>
          .
          <source>AAECC</source>
          (
          <year>2017</year>
          ), p.
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
          . DOI:
          <volume>10</volume>
          .1007/s00200-017- 0340-0.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Nitaj</surname>
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2013</year>
          )
          <article-title>An Attack on RSA Using LSBs of Multiples of the Prime Factors</article-title>
          . In: Youssef A.,
          <string-name>
            <surname>Nitaj</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hassanien</surname>
            <given-names>A</given-names>
          </string-name>
          .E. (eds) Progress in Cryptology - AFRICACRYPT
          <year>2013</year>
          .
          <source>AFRICACRYPT 2013. Lecture Notes in Computer Science</source>
          , vol
          <volume>7918</volume>
          , p.
          <fpage>297</fpage>
          -
          <lpage>310</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -38553-7_
          <fpage>17</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>May</surname>
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2009</year>
          )
          <article-title>Using LLL-Reduction for Solving RSA and Factorization Problems</article-title>
          . In: Nguyen P.,
          <string-name>
            <surname>Vallée</surname>
            <given-names>B</given-names>
          </string-name>
          . (
          <article-title>eds) The LLL Algorithm</article-title>
          .
          <source>Information Security and Cryptography</source>
          , p.
          <fpage>315</fpage>
          -
          <lpage>348</lpage>
          . Springer, Berlin, Heidelberg. DOI: 0.1007/978-3-
          <fpage>642</fpage>
          -02295-1_
          <fpage>10</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Lenstra</surname>
            <given-names>A.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lenstra</surname>
            <given-names>H.W.</given-names>
          </string-name>
          , Lovász L.
          <article-title>Factoring polynomials with rational coefficients</article-title>
          . Math. Ann.
          <volume>261</volume>
          ,
          <issue>4</issue>
          (
          <year>1982</year>
          ), p.
          <fpage>515</fpage>
          -
          <lpage>534</lpage>
          . DOI:
          <volume>10</volume>
          .1007/BF01457454.
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>Berlekamp</surname>
            <given-names>E.R.</given-names>
          </string-name>
          <string-name>
            <surname>Factoring</surname>
          </string-name>
          <article-title>Polynomials Over Large Finite Fields</article-title>
          . Math. Comp.
          <volume>24</volume>
          (
          <year>1970</year>
          ), p.
          <fpage>713</fpage>
          -
          <lpage>735</lpage>
          . DOI:
          <volume>10</volume>
          .1090/S0025-5718-1970- 0276200-X.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Cantor</surname>
            <given-names>D.G.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Zassenhaus H</surname>
          </string-name>
          .
          <article-title>A New Algorithm for Factoring Polynomials Over Finite Fields</article-title>
          . Math. Comp.
          <volume>36</volume>
          ,
          <issue>154</issue>
          (
          <year>1981</year>
          ), p.
          <fpage>587</fpage>
          -
          <lpage>592</lpage>
          . DOI:
          <volume>10</volume>
          .2307/2007663.
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Lu</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Peng</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kunihiro</surname>
            <given-names>N.</given-names>
          </string-name>
          (
          <year>2018</year>
          )
          <article-title>Recent Progress on Coppersmith's Lattice-Based Method: A Survey</article-title>
          . In: Takagi T.,
          <string-name>
            <surname>Wakayama</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tanaka</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kunihiro</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kimoto</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Duong</surname>
            <given-names>D</given-names>
          </string-name>
          . (eds)
          <article-title>Mathematical Modelling for Next-Generation Cryptography</article-title>
          .
          <source>Mathematics for Industry</source>
          , vol
          <volume>29</volume>
          , p.
          <fpage>297</fpage>
          -
          <lpage>312</lpage>
          . Springer, Singapore. DOI:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          -981-10-5065-7_
          <fpage>16</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Zhukov</surname>
            <given-names>A.E.</given-names>
          </string-name>
          <article-title>Cryptosystems with embedded trapdoors</article-title>
          .
          <source>BYTE Russia</source>
          ,
          <year>2007</year>
          (№101), p.
          <fpage>45</fpage>
          -
          <lpage>51</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <surname>Young</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yung</surname>
            <given-names>M.</given-names>
          </string-name>
          (
          <year>1997</year>
          )
          <article-title>Kleptography: Using Cryptography Against Cryptography</article-title>
          . In: Fumy W. (eds) Advances in Cryptology -
          <source>EUROCRYPT '97. EUROCRYPT 1997. Lecture Notes in Computer Science</source>
          , vol
          <volume>1233</volume>
          , p.
          <fpage>62</fpage>
          -
          <lpage>74</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/3-540-69053-
          <issue>0</issue>
          _
          <fpage>6</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <surname>Young</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yung</surname>
            <given-names>M. Malicious</given-names>
          </string-name>
          <string-name>
            <surname>Cryptography</surname>
          </string-name>
          . Exposing Cryptovirology. Wiley Publishing, Inc.
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Young</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yung</surname>
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2006</year>
          )
          <article-title>A Space Efficient Backdoor in RSA and Its Applications</article-title>
          . In: Preneel B.,
          <string-name>
            <surname>Tavares</surname>
            <given-names>S</given-names>
          </string-name>
          . (eds) Selected Areas in Cryptography.
          <source>SAC 2005. Lecture Notes in Computer Science</source>
          , vol
          <volume>3897</volume>
          , p .
          <fpage>128</fpage>
          -
          <lpage>143</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/11693383_9.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Young</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yung</surname>
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2016</year>
          )
          <article-title>Cryptography as an Attack Technology: Proving the RSA/Factoring Kleptographic Attack</article-title>
          . In: Ryan P.,
          <string-name>
            <surname>Naccache</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quisquater</surname>
            <given-names>JJ</given-names>
          </string-name>
          .
          <source>(eds) The New Codebreakers. Lecture Notes in Computer Science</source>
          , vol
          <volume>9100</volume>
          , p.
          <fpage>243</fpage>
          -
          <lpage>255</lpage>
          . Springer, Berlin, Heidelberg. DOI: 978-3-
          <fpage>662</fpage>
          -49301-4_
          <fpage>16</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Bellare</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paterson</surname>
            <given-names>K.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rogaway</surname>
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2014</year>
          )
          <article-title>Security of Symmetric Encryption against Mass Surveillance</article-title>
          . In:
          <string-name>
            <surname>Garay</surname>
            <given-names>J.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gennaro</surname>
            <given-names>R</given-names>
          </string-name>
          . (eds) Advances in Cryptology - CRYPTO
          <source>2014. Lecture Notes in Computer Science</source>
          , vol
          <volume>8616</volume>
          , p.
          <fpage>1</fpage>
          -
          <lpage>19</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -44371-
          <issue>2</issue>
          _
          <fpage>1</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <surname>Russell</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tang</surname>
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yung</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhou</surname>
            <given-names>HS</given-names>
          </string-name>
          . (
          <year>2016</year>
          )
          <article-title>Cliptography: Clipping the Power of Kleptographic Attacks</article-title>
          . In: Cheon J.,
          <string-name>
            <surname>Takagi</surname>
            <given-names>T</given-names>
          </string-name>
          . (eds) Advances in Cryptology - ASIACRYPT
          <source>2016. Lecture Notes in Computer Science</source>
          , vol
          <volume>10032</volume>
          , p.
          <fpage>34</fpage>
          -
          <lpage>64</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -53890-
          <issue>6</issue>
          _
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <surname>Hanzlik</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kluczniak</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kutyłowski</surname>
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2017</year>
          )
          <article-title>Controlled Randomness - A Defense Against Backdoors in Cryptographic Devices</article-title>
          . In: Phan RW.,
          <string-name>
            <surname>Yung</surname>
            <given-names>M</given-names>
          </string-name>
          . (eds) Paradigms in Cryptology - Mycrypt
          <year>2016</year>
          .
          <article-title>Malicious and Exploratory Cryptology</article-title>
          .
          <source>Mycrypt 2016. Lecture Notes in Computer Science</source>
          , vol
          <volume>10311</volume>
          , p
          <fpage>215</fpage>
          -
          <lpage>232</lpage>
          . Springer, Cham. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -61273-7_
          <fpage>11</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <surname>Degabriele</surname>
            <given-names>J.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paterson</surname>
            <given-names>K.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schuldt</surname>
            <given-names>J.C.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Woodage</surname>
            <given-names>J</given-names>
          </string-name>
          . (
          <year>2016</year>
          )
          <article-title>Backdoors in Pseudorandom Number Generators: Possibility and Impossibility Results</article-title>
          . In:
          <string-name>
            <surname>Robshaw</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katz</surname>
            <given-names>J</given-names>
          </string-name>
          . (eds) Advances in Cryptology - CRYPTO
          <source>2016. Lecture Notes in Computer Science</source>
          , vol
          <volume>9814</volume>
          , p.
          <fpage>403</fpage>
          -
          <lpage>432</lpage>
          . Springer, Berlin, Heidelberg. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -53018-4_
          <fpage>15</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>