RSA加密不同公钥生成相同密文问题排查求助
Hey there! Let's dig into this odd RSA behavior you're seeing—getting the same ciphertext for the same message across different public keys is definitely not how RSA is supposed to work. Let's break down the most likely culprits based on your setup (C + GNU MP on Linux) and walk through how to debug them.
Common Root Causes & Fixes
1. Missing RSA Padding (The #1 Culprit for New Implementations)
RSA requires padding for both security and correct operation (standards like PKCS#1 v1.5 or OAEP are mandatory here). If you're encrypting raw, short messages directly—where m^e is smaller than both public key moduli (n1 and n2)—the ciphertext will just be m^e with no modulus operation applied. That means it'll be identical across all keys, since there's no per-key modular reduction happening.
- Check: Look at your encryption code—are you adding any random or structured padding to the message before converting it to a big integer?
- Fix: Implement a standard padding scheme. Even a simple random prefix added to your message before encryption will ensure different ciphertexts across keys, since the input to the modular exponentiation will no longer be identical.
2. GNU MP Function Misuse
GMP's mpz_powm (modular exponentiation) is the core of RSA encryption, and a tiny parameter mix-up can cause huge issues:
- Verify your
mpz_powmcall: The correct syntax for RSA encryption is:
If you swapped parameters (like using the modulus as the exponent, or vice versa), you'll get incorrect or identical results across different keys.mpz_powm(ciphertext, message, public_exponent, modulus); - Check variable initialization: Make sure you're properly loading and resetting the
modulusandpublic_exponentvariables for each public key. It's easy to accidentally reuse a hardcoded value instead of pulling in the new key's parameters.
3. Message Conversion Errors
If your code converts the input message to a big integer incorrectly, you might be encrypting the same numerical value every time—regardless of the key used:
- Print the raw message integer: Before encryption, convert your message to an
mpz_tand print it withmpz_out_str(stdout, 10, message). If this value is identical across all encryption attempts, the problem lies in how you're translating your input (like a string) to a big integer. - Watch for hardcoded test values: Did you accidentally leave a fixed test message in your code instead of using the actual input? That would obviously produce the same ciphertext every time.
4. Invalid Public Key Parameters
Double-check that your two public keys actually have distinct (n, e) pairs:
- Print out the modulus (
n) and public exponent (e) for both keys. If either value is identical between the keys, that could explain identical ciphertexts (though even with the samee, padding should prevent duplicates ifnis different).
Next Debugging Steps
- Print all key parameters (
n1, e1andn2, e2) to confirm they're truly distinct. - Print the numerical value of the message right before encryption to ensure it's being loaded correctly.
- Add debug prints for the input and output of
mpz_powmto see exactly where the identical result is coming from. - If you're not using padding, implement a basic scheme (even a random 16-byte prefix) and test again.
内容的提问来源于stack exchange,提问作者Gambon

