论文部分内容阅读
In this paper,we re-examine the bit security of Paillier’s trapdoor function.We show that given a random w=gcyN mod N2 ∈ZN2* the most significant bit of its class c is a hard-core predicate,under a standard assumption that is computing composite residuosity class is hard.For the simultaneous security,we prove that n number of the class c’s bits are simultaneously hard-core under the standard assumption,where n is the length of c.
In this paper, we re-examine the bit security of Paillier’s trapdoor function. We show that given a random w = gcyN mod N2 ∈ZN2 * the most significant bit of its class c is a hard-core predicate, under a standard assumption that is computing composite residuosity class is hard. For the simultaneous security, we prove that n number of the class c’s bits are simultaneously hard-core under the standard assumption, where n is the length of c.