International Association for Cryptologic Research (IACR)
Abstract
During the design of a new primitive inspired by Squash we accidentally stumbled on the observation described in this note.
Let n be a k-bit Mersenne number whose factors are unknown. Consider an β-bit secret number x=2k/2a+b. We observe that there are parameter configurations where a chunk of the value b2 is leaked even if k<2β.
This observation does not endanger any known scheme and in particular not Squash