Key points are not available for this paper at this time.
In this paper, we present attacks on three types of RSA modulus when the least significant bits of the prime factors of RSA modulus satisfy some conditions. Let p, and q be primes of the form p=a^m₁+rₚ and q=b^m₂+rq respectively, where a, b, m₁, m₂ Z^+ rₚ, and rq are known. The first attack is when the RSA modulus is N=pq where m₁ or m₂ is an even number. If (rrₐ) ¹2 is sufficiently small, then N can be factored in polynomial time. The second attack is when N=p^sq, where q>p and s divides m₂. If rₚrq is sufficiently small, then N can be factored in polynomial time. The third attack is when N=p^s+lq^s, where p>q, s, l Z^+, l qa^m₁l{s}, and lr³ₚ is sufficiently small, then N can be factored in polynomial time.
Anwar et al. (Sun,) studied this question.