Project Sekai
🔒 CrewCTF 2023 / ✅-crypto-nec_easy
Sutx
BOT
07/07/2023 10:02 PM
nec_easy - 1000 points
Category:
Crypto
Description:
Can we factor N which is related to EC ? Author : kiona
nc nec-easy.chal.crewc.tf 20006
Files:
https://crewc.tf/files/5d6a5a5cdaa47e40f3d4f0b8ee1b4108/dist.rar?token=eyJ1c2VyX2lkIjoyMSwidGVhbV9pZCI6MTYsImZpbGVfaWQiOjE1fQ.ZKjt1w.yWgnKi3TANtN2LCp-MHo4fZ_trk
Tags:
No tags.
Sutx
pinned
a message
to this channel.
07/07/2023 10:02 PM
Sutx
BOT
07/07/2023 10:26 PM
@Utaha
wants to collaborate
Sutx
BOT
07/08/2023 12:28 AM
@kanon
wants to collaborate
Sutx
BOT
07/08/2023 2:31 AM
@Violin
wants to collaborate
Sutx
BOT
07/08/2023 6:17 AM
@Aptx
wants to collaborate
06:22
@layka_
wants to collaborate
layka_
07/08/2023 7:55 AM
anyone good with lattices here ?
07:56
(sig2_j - sig2_i) * nonce - (sig1_j - sig1_i) * d = 0 mod r
07:56
we have 7 equations of that
07:56
with unknown modulus
Utaha
07/08/2023 8:07 AM
what is known?
layka_
07/08/2023 8:07 AM
sig2 sig1
(edited)
08:08
message.txt
2.07 KB
08:08
thinking of this form
Utaha
07/08/2023 8:08 AM
so I guess it's a * nonce = b * d mod r, where a, b is known?
layka_
07/08/2023 8:08 AM
yep
Utaha
07/08/2023 8:08 AM
let's say you can have a1, b1, a2, b2,
(edited)
08:09
then a1b2-a2b1 is a multiple of r
08:09
so you can take gcd of all a1b2-a2b1 and get r
08:09
nonce and d is trivial afterward
08:09
tho you only get the ratio
(edited)
Utaha
then a1b2-a2b1 is a multiple of r
layka_
07/08/2023 8:09 AM
i always forget abt this trick
Utaha
07/08/2023 8:09 AM
lmao
layka_
07/08/2023 8:10 AM
i'll go for that
layka_
07/08/2023 8:31 AM
solved
layka_
used /ctf solve
Sutx
BOT
07/08/2023 8:31 AM
✅ Challenge solved.
Exported 27 message(s)