The RSA group is pseudo-free

10Citations
Citations of this article
44Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

We prove, under the strong RSA assumption, that the group of invertible integers modulo the product of two safe primes is pseudo-free. More specifically, no polynomial-time algorithm can output (with non negligible probability) an unsatisfiable system of equations over the free Abelian group generated by the symbols g 1,⋯,g n, together with a solution modulo the product of two randomly chosen safe primes when g 1,⋯,g n are instantiated to randomly chosen quadratic residues. Ours is the first provably secure construction of pseudo-free Abelian groups under a standard cryptographic assumption and resolves a conjecture of Rivest (Theory of Cryptography Conference-Proceedings of TCC 2004, LNCS, vol. 2951, pp. 505-521, 2004).

Cite

CITATION STYLE

APA

Micciancio, D. (2010). The RSA group is pseudo-free. Journal of Cryptology, 23(2), 169–186. https://doi.org/10.1007/s00145-009-9042-5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free