Home

Paillier???s Cryptosystem Revisited


Author(s) : Nick Howgrave-graham Rosario Gennaro Dario Catalano Phong Q. Nguyen, 
Publisher : N/A
Publication Date : 2001
ISSN : N/A
Abstract : We re-examine Paillier's cryptosystem, and show that by choosing a particular discrete log base g, and by introducing an alternative decryption procedure, we can extend the scheme to allow an arbitrary exponent e instead of N. The use of low exponents substantially increases the eciency of the scheme. The semantic security is now based on a new decisional assumption, namely the hardness of deciding whether an element is a \small " e-th residue modulo N,