RSA/Rabin Bits are 1/2 + 1 / Poly (Log N) Secure

Werner Alexi, Benny Chor, Oded Goldreich, Claus Peter Schnorr · 1984

We prove that RSA least significant bit is 1/2 + (1/[logcN]) secure, for any constant c (where N is the RSA modulus). This means that an adversary, given the ciphertext, cannot guess the least sigiiilicatnt bit of the plaintext with probability better than 1/2 + (1/[logcN]), unless he can break RSA.

Read the paper · More papers on PaperTik