Skip to main navigation Skip to search Skip to main content

RSA/Rabin least significant bits are (Fomula presented.) secure (Extended Abstract)

  • Massachusetts Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

8 Scopus citations

Abstract

We prove that RSA least significant bit is (Fomula presented.) secure, for any constant c (where N is the RSA modulus). This means that an adversary, given the ciphertext, cannot guess the least significant bit of the plaintext with probability better than (Fomula presented.), unless he can break RSA. Our proof technique is strong enough to give, with slight modifications, the following related results:(1)The loglog N least significant bits are simultaneously (Fomula presented.) secure.(2)The above also holds for Rabin’s encryption function. Our results imply that Rabin/RSA encryption can be directly used for pseudo random bits generation, provided that factoring/inverting RSA is hard.

Original languageEnglish
Title of host publicationAdvances in Cryptology - Proceedings of CRYPTO 84
EditorsDavid Chaum, George Robert Blakley
PublisherSpringer Verlag
Pages303-313
Number of pages11
ISBN (Print)9783540156581
DOIs
StatePublished - 1985
Externally publishedYes
EventAnnual International Cryptology Conference, CRYPTO 1984 - Santa Barbara, United States
Duration: 19 Aug 198422 Aug 1984

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume196 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceAnnual International Cryptology Conference, CRYPTO 1984
Country/TerritoryUnited States
CitySanta Barbara
Period19/08/8422/08/84

Fingerprint

Dive into the research topics of 'RSA/Rabin least significant bits are (Fomula presented.) secure (Extended Abstract)'. Together they form a unique fingerprint.

Cite this