Paillier???s Cryptosystem Revisited
| Author(s) : | Nick Howgrave-graham Rosario Gennaro Dario Catalano Phong Q. Nguyen, |
| Publisher : | N/A |
| Publication Date : | 2001 |
| ISSN : | N/A |
| Abstract : | We re-examine Paillier's cryptosystem, and show that by choosing a particular discrete log base g, and by introducing an alternative decryption procedure, we can extend the scheme to allow an arbitrary exponent e instead of N. The use of low exponents substantially increases the eciency of the scheme. The semantic security is now based on a new decisional assumption, namely the hardness of deciding whether an element is a \small " e-th residue modulo N, |
