TO implement the idea described in the previous section, we needa public-key scheme with two additional properties: (a) When the seedk is known, secret keys can be easily computed for a non-negligiblefraction of the possible public keys.seed k from specific public/secret key pairs generated with this k isintractable.(b) The problem of computing theUnfortunately, the FGA scheme cannot be used in a way that satisfiesthese conditions simultaneously: (a) If the modulus n is a pseudorandomfunction of the user's identity, even the key generation centercannot factor this n and cannot compute the decryption exponent d fromthe encryption exponent e. (b) If the modulus n is universal and theseed is its secret factorization, then anyone who knows an encryptionexponent e and its corresponding decryption exponent d can compute theseed
đang được dịch, vui lòng đợi..
