Boneh-Durfee attack is an extension of Wiener's attack. That is, it also attacks on low private component with a further relaxed condition. If satisfies:
Then we can use Boneh-Durfee attack to retrive
Consider for first, see that
and if we decide to consider and , we will have:
At this point, finding is equivalent to find the 2 small solutions and to the congruence
now let and this will preserve the scomposed subtraction
consider (with any ), we deduct that must be really closed to because is in the same order of the length of (so ), we will get