Shared Generation of Shared Rsa Keys 1

The paper considers the problem of distributed key generation for shared-control RSA schemes. In particular: how can two parties generate a shared RSA key in such a way that neither party can cheat? The answer to this question would have signi cant applications to, for example, key escrow systems. Cocks has recently proposed protocols to solve this problem in the case when both parties act honestly. However, we show that the Cocks protocols [6] are insecure if a dishonest party actively deviates from the protocol. A new protocol which resists these active attacks is proposed.