You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RSA加密不同公钥生成相同密文问题排查求助

Troubleshooting Identical RSA Ciphertexts with Different Public Keys

Hey there! Let's dig into this odd RSA behavior you're seeing—getting the same ciphertext for the same message across different public keys is definitely not how RSA is supposed to work. Let's break down the most likely culprits based on your setup (C + GNU MP on Linux) and walk through how to debug them.

Common Root Causes & Fixes

1. Missing RSA Padding (The #1 Culprit for New Implementations)

RSA requires padding for both security and correct operation (standards like PKCS#1 v1.5 or OAEP are mandatory here). If you're encrypting raw, short messages directly—where m^e is smaller than both public key moduli (n1 and n2)—the ciphertext will just be m^e with no modulus operation applied. That means it'll be identical across all keys, since there's no per-key modular reduction happening.

  • Check: Look at your encryption code—are you adding any random or structured padding to the message before converting it to a big integer?
  • Fix: Implement a standard padding scheme. Even a simple random prefix added to your message before encryption will ensure different ciphertexts across keys, since the input to the modular exponentiation will no longer be identical.

2. GNU MP Function Misuse

GMP's mpz_powm (modular exponentiation) is the core of RSA encryption, and a tiny parameter mix-up can cause huge issues:

  • Verify your mpz_powm call: The correct syntax for RSA encryption is:
    mpz_powm(ciphertext, message, public_exponent, modulus);
    
    If you swapped parameters (like using the modulus as the exponent, or vice versa), you'll get incorrect or identical results across different keys.
  • Check variable initialization: Make sure you're properly loading and resetting the modulus and public_exponent variables for each public key. It's easy to accidentally reuse a hardcoded value instead of pulling in the new key's parameters.

3. Message Conversion Errors

If your code converts the input message to a big integer incorrectly, you might be encrypting the same numerical value every time—regardless of the key used:

  • Print the raw message integer: Before encryption, convert your message to an mpz_t and print it with mpz_out_str(stdout, 10, message). If this value is identical across all encryption attempts, the problem lies in how you're translating your input (like a string) to a big integer.
  • Watch for hardcoded test values: Did you accidentally leave a fixed test message in your code instead of using the actual input? That would obviously produce the same ciphertext every time.

4. Invalid Public Key Parameters

Double-check that your two public keys actually have distinct (n, e) pairs:

  • Print out the modulus (n) and public exponent (e) for both keys. If either value is identical between the keys, that could explain identical ciphertexts (though even with the same e, padding should prevent duplicates if n is different).

Next Debugging Steps

  1. Print all key parameters (n1, e1 and n2, e2) to confirm they're truly distinct.
  2. Print the numerical value of the message right before encryption to ensure it's being loaded correctly.
  3. Add debug prints for the input and output of mpz_powm to see exactly where the identical result is coming from.
  4. If you're not using padding, implement a basic scheme (even a random 16-byte prefix) and test again.

内容的提问来源于stack exchange,提问作者Gambon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:58:47