The hidden number problem with non-prime modulus
نویسنده
چکیده
Abstract We consider a generalization of the Hidden Number Problem for general moduli N , and prove that it can be solved with high probability if roughly 2(logN) aproximations of quality at least (logN) are given, and the multipliers are chosen uniformly at random from ZZ/NZZ. We prove a similar result in the case that the multipliers are chosen uniformly at random from (ZZ/NZZ) and N is the product of two distinct primes. The last result holds in the more general case when N is squarefree and a technical condition related to the prime factors of N holds. The condition is related to the distribution of the solutions of a linear equation modulo N . The Hidden Number Problem modulo the product of two primes, with multipliers chosen from (ZZ/NZZ), is related to the bit security of the most significant bits of the RSA and Rabin functions. Our solution of the Hidden Number Problem implies that computing roughly (log(N)) bits of the RSA and Rabin functions is equivalent to computing the entire values.
منابع مشابه
Attacks on the Search-RLWE problem with small errors
The Ring Learning-With-Errors (RLWE) problem shows great promise for post-quantum cryptography and homomorphic encryption. We describe a new attack on the non-dual search RLWE problem with small error widths, using ring homomorphisms to finite fields and the chi-square statistical test. In particular, we identify a “subfield vulnerability” (Section 5.2) and give a new attack which finds this vu...
متن کاملNormal edge-transitive Cayley graphs on the non-abelian groups of order $4p^2$, where $p$ is a prime number
In this paper, we determine all of connected normal edge-transitive Cayley graphs on non-abelian groups with order $4p^2$, where $p$ is a prime number.
متن کاملRecognition by prime graph of the almost simple group PGL(2, 25)
Throughout this paper, every groups are finite. The prime graph of a group $G$ is denoted by $Gamma(G)$. Also $G$ is called recognizable by prime graph if for every finite group $H$ with $Gamma(H) = Gamma(G)$, we conclude that $Gcong H$. Until now, it is proved that if $k$ is an odd number and $p$ is an odd prime number, then $PGL(2,p^k)$ is recognizable by prime graph. So if $k$ is even, the r...
متن کاملSome Notes On Multiplicative Congruential Random Number Generators With Mersenne Prime Modulus 261-1
Multiplicative congruential random number generators of the form sn = a*Sn_i mod m using the Mersenne prime modulus 2-1 are examined. Results show that they can provide sufficiently long pseudo-random sequences that can be implemented efficiently using 64 bit accumulators without the need of a costly division operation. INTRODUCTION Random number generators are widely used in computer simulatio...
متن کاملFactoring RSA Moduli with Weak Prime Factors
In this paper, we study the problem of factoring an RSA modulus N = pq in polynomial time, when p is a weak prime, that is, p can be expressed as ap = u0 + M1u1 + . . . + Mkuk for some k integers M1, . . . ,Mk and k+2 suitably small parameters a, u0, . . . uk. We further compute a lower bound for the set of weak moduli, that is, moduli made of at least one weak prime, in the interval [2, 2] and...
متن کامل