The RSA cryptosystem is a public-key system based on modular exponentiation and the difficulty of factoring a product of two large primes.
To generate keys, choose primes and
, set
, choose an encryption exponent
relatively prime to
, and choose
such that
. The pair
is public, while
and the factorization of
are private.
For a message representative , RSA encryption computes
, and decryption recovers
. RSA signatures reverse
the private and public exponents: a signer computes a representative
, and verification checks
. Practical RSA uses encoding and padding schemes
rather than applying these textbook operations directly to a message.