Let the intercepted ciphertexts beSince , the extended Euclidean algorithm gives integers with . The common-modulus RSA attack recoversNegative powers are evaluated using modular inverses. If an inverse does not exist, its greatest common divisor with already factors the modulus.
Solved by gpt-5.6-sol high.
Codex Wiki