A newly revealed practical attack can impersonate a hardware security module (HSM) and forge arbitrary 1024-bit RSA signatures without extracting or factoring the device’s private key. The research, titled "Forging 1024-bit RSA Signatures in Nearly SNFS Time," implements a two-decade-old cryptanalytic technique against raw RSA signing and decryption oracles. The method allows an attacker with temporary access to an HSM’s unpadded RSA signing function to perform a large precomputation and query-collection operation.
They tested the technique against Thales Luna K6 and Luna S750 HSMs, showing that the attack relies solely on black-box API access and does not require physical compromise, side-channel leakage, firmware modification, or key extraction.
The method employs the "eth-root number field sieve," or √e NFS, as described by Antoine Joux, David Naccache, and Emmanuel Thomé in 2007. This approach exhibits asymptotic complexity akin to the Special Number Field Sieve, rendering it notably more efficient than the General Number Field Sieve for generic RSA modulus factoring in this specific oracle-assisted context. However, researchers warn that this condition can occur in HSM deployments that enable raw RSA for custom padding, legacy cryptographic formats, or application-side processing.
This reinforces the necessity of disabling raw RSA mechanisms when not required, strictly limiting HSM API permissions, rotating blind-signature keys, and transitioning to modern post-quantum cryptography. Explore for your team.










