filename : KMOV title : On the Security of the KMOV Public Key Cryptosystem author : Daniel Bleichenbacher type : inproceedings organization : Lucent Technologies booktitle : Advances in Cryptology -- CRYPTO' 97 series : Lecture Notes in Computer Science publisher : Springer-Verlag, Berlin editor : B.S. Kaliski volume : 1294 pages : 235-248 abstract : This paper analyzes the KMOV public key cryptosystem, which is an elliptic curve based analogue to RSA. It was believed that this cryptosystem is more secure against attacks without factoring such as the H\aa{}stad-attack in broadcast application. Some new attacks on KMOV are presented in this paper that show the converse. In particular, it is shown that some attacks on RSA which work only when a small public exponent $e$ is used can be extended to KMOV, but with no restriction on $e$. The implication of these attacks on related cryptosystems are also discussed.