# RSASSS

In [4]:
import gmpy2
from Crypto.Util.number import long_to_bytes

In [134]:
def modular_sqrt(a, p):
    """ Find a quadratic residue (mod p) of 'a'. p
        must be an odd prime.

        Solve the congruence of the form:
            x^2 = a (mod p)
        And returns x. Note that p - x is also a root.

        0 is returned is no square root exists for
        these a and p.

        The Tonelli-Shanks algorithm is used (except
        for some simple cases in which the solution
        is known from an identity). This algorithm
        runs in polynomial time (unless the
        generalized Riemann hypothesis is false).
    """
    # Simple cases
    #
    if gmpy2.legendre(a, p) != 1:
        return 0
    elif a == 0:
        return 0
    elif p == 2:
        return 0
    elif p % 4 == 3:
        return pow(a, (p + 1) / 4, p)

    # Partition p-1 to s * 2^e for an odd s (i.e.
    # reduce all the powers of 2 from p-1)
    #
    s = p - 1
    e = 0
    while s % 2 == 0:
        s /= 2
        e += 1

    # Find some 'n' with a legendre symbol n|p = -1.
    # Shouldn't take long.
    #
    n = 2
    while gmpy2.legendre(n, p) != -1:
        n += 1

    # Here be dragons!
    # Read the paper "Square roots from 1; 24, 51,
    # 10 to Dan Shanks" by Ezra Brown for more
    # information
    #

    # x is a guess of the square root that gets better
    # with each iteration.
    # b is the "fudge factor" - by how much we're off
    # with the guess. The invariant x^2 = ab (mod p)
    # is maintained throughout the loop.
    # g is used for successive powers of n to update
    # both a and b
    # r is the exponent - decreases with each update
    #
    x = pow(a, (s + 1) / 2, p)
    b = pow(a, s, p)
    g = pow(n, s, p)
    r = e

    while True:
        t = b
        m = 0
        for m in xrange(r):
            if t == 1:
                break
            t = pow(t, 2, p)

        if m == 0:
            return x

        gs = pow(g, 2 ** (r - m - 1), p)
        g = (gs * gs) % p
        x = (x * gs) % p
        b = (b * g) % p
        r = m


def legendre_symbol(a, p):
    """ Compute the Legendre symbol a|p using
        Euler's criterion. p is a prime, a is
        relatively prime to p (if p divides
        a, then a|p = 0)

        Returns 1 if a has a square root modulo
        p, -1 otherwise.
    """
    ls = pow(a, (p - 1) / 2, p)
    return -1 if ls == p - 1 else ls

In [136]:
def legendre_symbol(a, p):
    """
    Legendre symbol
    Define if a is a quadratic residue modulo odd prime
    http://en.wikipedia.org/wiki/Legendre_symbol
    """
    ls = pow(a, (p - 1)//2, p)
    if ls == p - 1:
        return -1
    return ls

def prime_mod_sqrt(a, p):
    """
    Square root modulo prime number
    Solve the equation
        x^2 = a mod p
    and return list of x solution
    http://en.wikipedia.org/wiki/Tonelli-Shanks_algorithm
    """
    a %= p

    # Simple case
    if a == 0:
        return [0]
    if p == 2:
        return [a]

    # Check solution existence on odd prime
    if legendre_symbol(a, p) != 1:
        return []

    # Simple case
    if p % 4 == 3:
        x = pow(a, (p + 1)//4, p)
        return [x, p-x]

    # Factor p-1 on the form q * 2^s (with Q odd)
    q, s = p - 1, 0
    while q % 2 == 0:
        s += 1
        q //= 2

    # Select a z which is a quadratic non resudue modulo p
    z = 1
    while legendre_symbol(z, p) != -1:
        z += 1
    c = pow(z, q, p)

    # Search for a solution
    x = pow(a, (q + 1)//2, p)
    t = pow(a, q, p)
    m = s
    while t != 1:
        # Find the lowest i such that t^(2^i) = 1
        i, e = 0, 2
        for i in range(1, m):
            if pow(t, e, p) == 1:
                break
            e *= 2

        # Update next value to iterate
        b = pow(c, 2**(m - i - 1), p)
        x = (x * b) % p
        t = (t * b * b) % p
        c = (b * b) % p
        m = i

    return [x, p-x]

In [209]:
S1

b'(1, 132156498146518935546534654)'

The history saving thread hit an unexpected error (OperationalError('database is locked')).History will not be written to the database.


In [110]:
# Son 1
N1 = 97047969232146954924046774696075865737213640317155598548487427318856539382020276352271195838803309131457220036648459752540841036128924236048549721616504194211254524734004891263525843844420125276708561088067354907535207032583787127753999797298443939923156682493665024043791390402297820623248479854569162947726288476231132227245848115115422145148336574070067423431126845531640957633685686645225126825334581913963565723039133863796718136412375397839670960352036239720850084055826265202851425314018360795995897013762969921609482109602561498180630710515820313694959690818241359973185843521836735260581693346819233041430373151
e1 = 3
c1 = 6008114574778435343952018711942729034975412246009252210018599456513617537698072592002032569492841831205939130493750693989597182551192638274353912519544475581613764788829782577570885595737170709653047941339954488766683093231757625

m1 = gmpy2.iroot(c1,3)[0]
print(len(long_to_bytes(m1)), long_to_bytes(m1))
print(long_to_bytes(m1).hex())

S1 = b'(1, 132156498146518935546534654)'

32 b'(1, 132156498146518935546534654)'
28312c2031333231353634393831343635313839333535343635333436353429


In [149]:
# Son 2
p2 = 7237005577332262213973186563042994240829374041602535252466099000494570602917
q2 = 88653318322320212121171535397276679450159832009631056842709712756058489880609
e2 = 16
c2 = 128067909105216284348808993695734979917384615977985008857494038384160720721127262500602107681721675827823420594821881043967947295783995842628815275429540
N2 = 641584559147643806522585180578209433834461841024440698738725108146842224132878080954869712051951546360407690947466432537234140877105707375769336477136453
f2 = (p2-1)*(q2-1)
d2 = gmpy2.invert(e2//16,f2)

prime = p2
m16 = pow(c2, d2, N2)
m8 = prime_mod_sqrt(m16,prime)
m4 = [item for sublist in [prime_mod_sqrt(i,prime) for i in m8] for item in sublist]
m2 = [item for sublist in [prime_mod_sqrt(i,prime) for i in m4] for item in sublist]
m1 = [item for sublist in [prime_mod_sqrt(i,prime) for i in m2] for item in sublist]

for m in m1:
    print(long_to_bytes(m))

b'\x0b\xc6\xc9\xce\xcd\xcc\xc7\xc9\xcb\xce\xeeu\xf7\xdd\x90\xd9\xbab4\x82\xc8\xe9`\xac\xee)\xb8\x93\x9f\xe3\xe7\xfb'
b'\x04961238641\x11\x8a\x08"o&E\x9d\xcb}7\x16\x9fS\x11\xd6Gl`\x1c\x19\xaa'
b'\x08`H5f0_e\x82\xf6\xbe\x98\xf2\xee\x07\xa7\x0e\xdbp\x86\x84L\x92\x8d\xe0\x82\x9b\x0b)\xd4u '
b'\x07\x9f\xb7\xca\x99\xcf\xa0\x9a}\tAg\r\x11\xf8X\xf1$\x8fy{\xb3mr\x1f}d\xf4\xd6+\x8c\x85'


In [152]:
qm

[mpz(38297688785245425942315470195203368228917701025365630206640911325936938424081),
 mpz(50355629537074786178856065202073311221242130984265426636068801430121551456528),
 mpz(14991434533997167602900450207826414892791918008257559906785817035918095055937),
 mpz(73661883788323044518271085189450264557367914001373496935923895720140394824672),
 mpz(63825686663518936188124045803129940209355472505493513065376022650672390288294),
 mpz(24827631658801275933047489594146739240804359504137543777333690105386099592315),
 mpz(65976794851029334311604807496441880931188870664677745946719553145804980762306),
 mpz(22676523471290877809566727900834798518970961344953310895990159610253509118303),
 mpz(5555628510504491012094665941460002231027535769363266461787671386055926834204),
 mpz(83097689811815721109076869455816677219132296240267790380922041370002563046405),
 mpz(28545725259483356344817474381552442111873386390261071738789425798044283754772),
 mpz(6010759306283685577635406101572423733828644561936998510392028

In [151]:
pm

[mpz(5326669879680030277560357503186915499085285713538416134067345893682994997243),
 mpz(1910335697652231936412829059856078741744088328064119118398753106811575605674),
 mpz(3788618472260751383396585810107767470073035349261013075305220094291497743648),
 mpz(3448387105071510830576600752935226770756338692341522177160878906203072859269)]

In [153]:
qinv = gmpy2.invert(q2, p2)

for qmi in qm:
    
    for pmi in pm:
        
        h = (qinv * (pmi - qmi)) % p2
        
        mfinal = qmi + h*q2
        print(long_to_bytes(mfinal))

b'\xac\xec\x04\x9c\xe7\xea?\x1a\xe6lT\x83\xcd\x0e|\xf0\nO\xd8g\x98\xf436y\xda\x9b\xfa\xf6C\x8c\xb1\xc9\x03/d\x10d=\x9a\xd1^A\xfbj\xc8E\xc9\xb7"\xa8\xb1\x82\xe46Tq\xe0\xcf\x0f\xb3y!'
b'\x05|\xb1\x16/\xce\x0e8[bS\x0bXa\xa9\x12\xc7D\xd8\x86\x94\x99,k\xde\x13\xacQ&*\x86\xcae,\xcd\xfb\x10\tc\x1a\xbfZ,\x0f\x91\xd3-A\x89\x1f \xa35wu\x96w|^\xa8\x9f\x07\xef\xca'
b'\x027\xc9n\xecc1\t\xa8\x7f\x1f[\x80\xfa\x0b\xb2\x95./\x94\xc3m\xaa\x99\xf1o?u\xe1H=\xae4D~\xe1X*\xad\x87\x13\xdf\xd6J\xa6A\xd2\x9c^\x1fj\xdc\xb9\xe5\x85.\x9f\xb8h\xc2\xe6\xa5lq'
b'\x03\xf1\xd3\xab\xe0R\xc7m\xcd\xc9\xa0\x04[4\xab\xdd" \xf8\xca8\xc4v\x05#\x1eGw?\xd8\x8c\xa8\xe2\xb1RI\x1b\xef\x19\xd1FK\xb4\x06\xe6\xfc"\xea\xf4\xb6\xd8o-\x14\xd4\x9e,5\xd6\xb4\xc8\x15\xfcz'
b"\x06\xc3N\xe9\xd01\xf1\xc7\xa4\x9d\xac\xf4\xa7\x9eV\xed8\xbb'ykf\xd3\x94!\xecS\xae\xd9\xd5zy\xfe\xd32\x04\xef\xf6\x9c\xe5@\xa5\xd3\xf0n,\xd2\xbev\xe0\xdf\\\xca\x88\x8ai\x88\x83\xa1W`\xf8F{"
b"\x0b\x93\x13\xfbc\x18\x15\xc0\xe5\x19\x93\xab|2\xf1\x83\x0f\xf5\xb0'\x98g\x0

In [155]:
S2 = b'(2, 861352498496153254961238645321268413658613864351)'

In [205]:
import random
from math import ceil
from decimal import Decimal, getcontext

getcontext().prec = 500
 
def reconstruct_secret(shares):
    """
    Combines individual shares (points on graph)
    using Lagranges interpolation.
 
    `shares` is a list of points (x, y) belonging to a
    polynomial with a constant of our key.
    """
    sums = 0
    prod_arr = []
 
    for j, share_j in enumerate(shares):
        xj, yj = share_j
        prod = Decimal(1)
 
        for i, share_i in enumerate(shares):
            xi, _ = share_i
            if i != j:
                prod *= Decimal(Decimal(xi)/(xi-xj))
 
        prod *= yj
        sums += Decimal(prod)
 
    return round(sums)

long_to_bytes(reconstruct_secret(lest))

In [206]:
SSS = [[int(i) for i in S1.decode()[1:-1].split(', ')], 
       [int(i) for i in S2.decode()[1:-1].split(', ')], 
       [int(i) for i in S3.decode()[1:-1].split(', ')]]

In [208]:
getcontext().prec = 500
long_to_bytes(reconstruct_secret(SSS))

b'bctf{Mr._Ad1_5ham1r}'

In [98]:
2031333231353634393831343635313839333535343635333436353429

2031333231353634393831343635313839333535343635333436353429

In [128]:
# Get all 16*16 = 256 possible roots
entry = [pow(c2,gmpy2.invert(e2//16,phi),N2)]
roots1 = [entry[0]]
roots2 = []
for i in range(4):
    for e in roots1:
        r1 = prime_mod_sqrt(e,p2)
        r2 = p2 - r1
        r3 = prime_mod_sqrt(e,q2)
        r4 = q2 - r3
        [roots2.append(r) for r in [r1,r2,r3,r4]]
    print(str(2**(i+1))+'-th root', len(roots2))
    roots1 = roots2[::1]
    roots2 = []
    
print()
# Let's check em out
for r in roots1:
    if r != 0:
        if '20' == str(r)[:2]:
            b = long_to_bytes(r)
            print(r)

TypeError: pow() 3rd argument not allowed unless all arguments are integers

In [210]:
# Son 3
N3 = 3213876088517980551083924185487283336189331657515992206038949
e3 = 65537
c3 = 2941293819923490843589362205798232424837846370982721175905966
p3 = 2**100+277
q3 = 2**101+81

phi3 = (p3-1)*(q3-1)
d3 = pow(e3, -1, phi3)

m3 = pow(c3, d3, N3)
print(long_to_bytes(m3))
m3

b'd@\x9b\xd7\xd2\xf1\xea\x9a\x17*u\x97\\H3\xcf\x15\xfe\x93\xa3K&\x93\x19\xcd'


629294375772413445978559434482906561379546104217158827579853

In [109]:
S3 = b'(3, 3145756504701717246281836139538967176547517737056)'

In [117]:
long_to_bytes(541893472927304311696017462663852715895951883676838007787557872016428*N3+629294375772413445978559434482906561379546104217158827579853)

b'(3, 3145756504701717246281836139538967176547517737056)'

In [211]:
541893472927304311696017462663852715895951883676838007787557872016428*N3+629294375772413445978559434482906561379546104217158827579853

1741578475165028969394795886739067133341415965726853757727627095462005631428847640037247055134536266102909953307040160676163434025

In [213]:
long_to_bytes(1741578475165028969394795886739067133341415965726853757727627095462005631428847640037247055134536266102909953307040160676163434025)

b'(3, 3145756504701717246281836139538967176547517737056)'