<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet href="paper.xsl" type="text/xsl"?>

<paper xmlns="http://www.cse.ucsd.edu/daniele/XML"
       xmlns:paper="http://www.cse.ucsd.edu/daniele/XML"
       xmlns:xhtml="http://www.w3.org/1999/xhtml">

  <filename>PseudoFree</filename>

  <title>The RSA Group is Pseudo-Free</title>

  <author>Daniele Micciancio</author>


  <reference>
    <link>http://www.springerlink.com/content/100359/</link>
    <journal>Journal of Cryptology</journal>
    <year>2009?</year>
    <volume>??</volume>
    <number>?</number>
    <pages>??-??</pages>
    <doi></doi>
    <note>Preliminary version in Eurocrypt 2005</note>
  </reference>
  
  <abstract>
    <p xmlns="http://www.w3.org/1999/xhtml">
      We prove, under the strong RSA assumption, that the group 
      of invertible integers modulo the product of two safe primes 
      is pseudo-free.
      More specifically, no polynomial time algorithm can output 
      (with non negligible probability) an unsatisfiable system of 
      equations over 
      the free abelian group generated by the symbols 
      <em>g<sub>1</sub>,...,g<sub>n</sub></em>, 
      together with a solution modulo the product 
      of two randomly chosen safe primes when 
      <em>g<sub>1</sub>,...,g<sub>n</sub></em> are
      instantiated to randomly chosen quadratic residues.
      Ours is the first provably secure construction of pseudo-free 
      abelian groups under a standard cryptographic assumption, 
      and resolves a conjecture of Rivest 
      (Theory of Cryptography Conference - Proceedings of TCC 2004).
    </p>
  </abstract>

  <note>
    Preliminary versions in 
    <link doi="10.1007/11426639_23">Eurocrypt 2005</link>
  </note>
</paper>



