Abstract:
It is proved that the generalized Wiener attack on the RSA cryptosystem permits to find not only small, but also some large secret exponents $d$, and the fraction of exponents $d$, which are weak with respect to this attack is heuristically estimated as $O(N^{-1/2})$.
Keywords:RSA cryptosystem, continued fractions, small secret exponent, Weiner attack.